Harden Access to OpenClaw with Pomerium
Put OpenClaw, a self-hosted AI assistant with shell and file access, behind a web route and an SSH route, both gated by the same identity and Pomerium's context-aware policy.
Practical talks, tutorials, videos, and writing about identity-aware access, OAuth, authorization, and policy enforcement for modern infrastructure, including AI agents and MCP servers.
Book me for a talk or guest appearanceHands-on material for putting identity and policy at the access boundary.
Put OpenClaw, a self-hosted AI assistant with shell and file access, behind a web route and an SSH route, both gated by the same identity and Pomerium's context-aware policy.
Use Pomerium's native SSH support to publish a local service through a standard reverse SSH tunnel, with OpenID Connect (OIDC) authentication and continuous authorization on every request.
Pomerium can be used as a native SSH reverse proxy, adding OAuth authentication and flexible Pomerium policy enforcement to standard SSH connections, without the need for tunnels, or custom clients or servers.
How proxy-enforced OAuth, token separation, auditing, and context-aware authorization close important gaps in production MCP deployments.
A practical explanation of how Zero Trust replaces perimeter assumptions with identity-aware, context-based access decisions.