Pomerium logo

Pomerium

Identity-aware reverse proxy with OAuth2 SSO for securely exposing internal apps

4.9k Go Apache-2.0 today

Overview

Pomerium is an open-source identity-aware access proxy that adds authentication and authorization in front of any internal web application. It integrates with identity providers (Google, Okta, Azure AD, GitHub, etc.) via OAuth2/OIDC and enforces policy-based access control before traffic reaches upstream services. Originally a successor to the deprecated oauth2_proxy, it supports context-aware policies based on user identity, groups, and device state. Deploys as a single Go binary or via Docker/Kubernetes with official Helm charts.

Where it falls short of Heroku

  • No application deployment or hosting capabilities; purely an access proxy layer
  • Policy configuration via YAML can be complex; lacks a full-featured web UI in the open-source edition
  • Device posture checking and some enterprise features require the commercial Pomerium Zero/Enterprise tier
  • Setup complexity is significantly higher than simpler tools like Nginx Proxy Manager for basic use cases

We list the gaps honestly so you can decide if the trade-off is worth owning your data.

Tags

identity-aware-proxy
sso
oauth2
access-control
reverse-proxy
Maintain Pomerium?

Claim this listing to keep it accurate, add a deploy template, or feature it on relevant pages.

Show off your self-host difficulty score

Embed the Pomerium difficulty badge in your README — it links back here.

Self-host difficulty badge← add this to your README
[![Self-host difficulty](https://openreplace.com/api/badge/pomerium)](https://openreplace.com/pomerium)

Similar open-source projects

Other self-hostable tools in the same space worth comparing.

Automatic HTTPS web server and reverse proxy with zero config TLS

73k Go Apache-2.0 today
3/5
Pomerium vs Caddy

Cloud-native HTTP reverse proxy and load balancer for microservices

64k Go MIT today
3/5
Pomerium vs Traefik

Self-hostable Heroku/Netlify alternative for apps, databases, and services

57k PHP Apache-2.0 2 days ago
2/5
1-click
Pomerium vs Coolify

Modern Linux server and web-app management panel with app store deploys

36k Go GPL-3.0 today
2/5
Pomerium vs 1Panel