Skip to content
PlainID
← Back to all integrations
Istio logo

Istio

Discover service traffic and enforce contextual API and agent access through Istio.

About PlainID + Istio

The transition from a monolithic application architecture to a cloud-native one as enterprises migrate and adopt modern cloud technology involves the use of hundreds of microservices interacting with each other through numerous API calls every millisecond of the day. The sheer complexity and volume of calls between microservices, also known as East-West traffic, can pose significant security challenges in terms of authorization.
Istio is a service mesh implementation developed by Google, Lyft, and IBM. It’s open source and the most popular service mesh implementation. Istio offers service components that can control the communication to and between services. More precisely, which pods running service A can reach pods running service B. This by itself is not enough, authorization policies should also consider the full context of the request taking into consideration the identities that are operating within those services and what they are trying to do (i.e. the pod's functionality).

Technical Information

The PlainID Istio Authorizer runs as a sidecar next to each instance of Istio. When a request hits the Istio proxy, it queries the PlainID sidecar directly for an authorization decision. PlainID delivers the Authorization decision based on the policies configured in the Policy Administration Point (PAP).
The PlainID Istio Authorizer can provide two types of responses:
1. Permit / Deny - allow to or block the request as-is
2. Token Exchange and Token Enrichment - Enrich access token by injecting authorization claims into the request header, or mint a new access token containing only relevant information for the transaction

Architectures

  1. The client sends its access/ID token in the request header.
  2. The request is intercepted by the Istio Proxy and passed to the PlainID Sidecar container. The PlainID sidecar container is automatically injected into the pods through configuration settings within Istio.
  3. The PlainID sidecar container requests an access decision from the PlainID PDP which responds with a dynamically calculated access decision based on the policies configured within the PlainID Authorization Platform. The decision can be on the request URL, request header, and request body.
  4. In case the authorization decision is Permit, the Istio proxy passes the request to the service container as-is or Enrich the request header with entitlements or additional information to provide specific access data to the service. Otherwise, If the authorization decision is denied, the request never reaches the actual service container and a 403 response is returned immediately.

Technology

  • Servicemesh

Capabilities

  • Discover
  • Manage
  • Enforce

Auth Patterns

  • API Authorization
  • MCP Authorizations
  • Agentic Authorizations (Guardrails)

Need help integrating?

Our experts can help you architect the perfect authorization strategy for your stack.

Contact Support

Better Together

Connect Context. Centralize Policy. Enforce Everywhere.