Pomerium for MCP

What it is

Pomerium is an identity- and context-aware access proxy; its docs have a dedicated MCP section describing it as a secure gateway for MCP servers: authentication, authorization, TLS termination and audit in front of internal or third-party MCP servers (docs, read 2026-10-08).

Maker and licence

Pomerium, Inc. Repo pomerium/pomerium, Apache-2.0. 5,029 stars on 2026-10-08; latest release v0.33.4 (2026-10-02) per GitHub API. Website https://www.pomerium.com.

Position

Identity-aware proxy with MCP support (gateway for MCP servers, plus an MCP-aware OAuth bridge).

Core capabilities (docs)

  • MCP gateway: put an internal MCP server behind Pomerium so clients (Claude, ChatGPT, VS Code and others) reach it with downstream OAuth 2.1 against your identity provider.
  • MCP bridging: Pomerium manages upstream OAuth (acquire, cache, refresh tokens, RFC 9728 discovery) for third-party servers such as GitHub, Linear, Notion, Google and injects tokens so clients never see upstream credentials.
  • Per-user upstream connection management through a routes portal and discovery API.
  • Tool-level access control using Pomerium Policy Language (mcp_tool criterion: exact, prefix, suffix or list), composable with identity policies; every tool call is logged with method, tool name and parameters.
  • Delegation: service accounts for CI/agents, and client-app routes that pass a user token to an LLM API.
  • pom.run SSH tunnel for exposing a local MCP server during development.

MCP spec support

Downstream OAuth 2.1 and RFC 9728 are named; the specific MCP spec revision is not stated on the page read.

Maturity

Releases are in the 0.x line (v0.33.4); the MCP section is current in the docs on 2026-10-08. GA/preview label for MCP features not stated.

Fit and limits (opinion)

Strong fit when identity (SSO, groups) and zero-trust access are the main need and you want one proxy for web apps and MCP servers. It is not a tool catalogue or LLM gateway; combine with an LLM gateway such as LiteLLM if you need model routing.

Self-learning

Sources

Open items

  • MCP spec revision supported: not stated.
  • Enterprise / hosted editions and their MCP limits: not checked.
  • The linked course was not opened.