Announcing upcoming changes to the AWS Security Token Service global endpoint
Security Blog
AWS is making changes to the AWS Security Token Service (STS) global endpoint to improve resiliency and performance:
- Starting in early 2025, STS global endpoint requests will be automatically served in the same Region as deployed workloads
- Applies to AWS Regions enabled by default, with gradual rollout beginning in Europe (Stockholm) Region
- CloudTrail logs will be updated with new fields to clarify endpoint and serving Region
- Requests to global endpoint will continue to have `us-east-1` as the `aws:RequestedRegion`
- Global endpoint requests will have a separate request quota from Regional endpoints
AWS recommends using Regional STS endpoints whenever possible, especially for workloads outside AWS or in opt-in Regions.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Nov 21
2025
2025
AWS Security Token Service Now Supports Internet Protocol version 6 (IPv6)
Jan 10
2025
2025
AWS End User Messaging expands self-service sender ID registration support in 19 new countries
Feb 11
2025
2025
Updating AWS SDK defaults – AWS STS service endpoint and Retry Strategy
Feb 14
2025
2025
Introducing the AWS Trust Center
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.