Pomerium for MCP
What it is
Pomerium is an identity- and context-aware access proxy; its docs have a dedicated MCP section describing it as a secure gateway for MCP servers: authentication, authorization, TLS termination and audit in front of internal or third-party MCP servers (docs, read 2026-10-08).
Maker and licence
Pomerium, Inc. Repo pomerium/pomerium, Apache-2.0. 5,029 stars on 2026-10-08; latest release v0.33.4 (2026-10-02) per GitHub API. Website https://www.pomerium.com.
Position
Identity-aware proxy with MCP support (gateway for MCP servers, plus an MCP-aware OAuth bridge).
Core capabilities (docs)
- MCP gateway: put an internal MCP server behind Pomerium so clients (Claude, ChatGPT, VS Code and others) reach it with downstream OAuth 2.1 against your identity provider.
- MCP bridging: Pomerium manages upstream OAuth (acquire, cache, refresh tokens, RFC 9728 discovery) for third-party servers such as GitHub, Linear, Notion, Google and injects tokens so clients never see upstream credentials.
- Per-user upstream connection management through a routes portal and discovery API.
- Tool-level access control using Pomerium Policy Language (
mcp_toolcriterion: exact, prefix, suffix or list), composable with identity policies; every tool call is logged with method, tool name and parameters. - Delegation: service accounts for CI/agents, and client-app routes that pass a user token to an LLM API.
pom.runSSH tunnel for exposing a local MCP server during development.
MCP spec support
Downstream OAuth 2.1 and RFC 9728 are named; the specific MCP spec revision is not stated on the page read.
Maturity
Releases are in the 0.x line (v0.33.4); the MCP section is current in the docs on 2026-10-08. GA/preview label for MCP features not stated.
Fit and limits (opinion)
Strong fit when identity (SSO, groups) and zero-trust access are the main need and you want one proxy for web apps and MCP servers. It is not a tool catalogue or LLM gateway; combine with an LLM gateway such as LiteLLM if you need model routing.
Related notes
- agentgateway, Arcade MCP Gateway, Portkey, OmniRoute: other gateway notes in this folder
- MCP security with a gateway, Model Context Protocol, A2A protocol
- HyperTool MCP (tool-subset proxy) and Tool Platforms (managed tool/integration platforms) cover adjacent ground and are not repeated here
Self-learning
- MCP overview: https://www.pomerium.com/docs/capabilities/mcp
- The docs link a hands-on course, “Securing MCP Servers and MCP Apps with Pomerium” (hosted on iximiuz labs; free account required per the docs)
- Repo: https://github.com/pomerium/pomerium
Sources
- https://www.pomerium.com/docs/capabilities/mcp (fetched 2026-10-08)
- https://api.github.com/repos/pomerium/pomerium and /releases (fetched 2026-10-08)
Open items
- MCP spec revision supported: not stated.
- Enterprise / hosted editions and their MCP limits: not checked.
- The linked course was not opened.