Sorry if I misunderstood the question, sounds like you are asking if there are some common tools that do auth outside of the application before passing traffic back.
Google IAP is a big one, and Cloudflare Access can let you do similar things (link an internal service to Cloudflare network and Cloudflare will deny someone ability to talk to that service until they've validated their identity to cloudflare and it matches your rules somehow.