Amazon API Gateway now supports mutual TLS for backend integrations
News
Amazon API Gateway now supports mutual TLS (mTLS) for backend integrations, allowing REST APIs to present AWS Certificate Manager certificates during TLS handshakes with backend services.
- Present trusted CA-signed certificates instead of self-signed certificates to backend endpoints
- Import certificates from existing PKI or use AWS Private Certificate Authority for issuance
- Automatic certificate updates propagate without redeployment or downtime
- Combine with inbound mTLS for mutual authentication on both client-to-API and API-to-backend connections
- Available in all commercial AWS Regions and AWS GovCloud (US)
- Configure via API Gateway console, AWS CLI, or AWS CloudFormation
Enables zero-trust security and mutual authentication across API connections, meeting requirements for regulated industries like financial services and healthcare.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Nov 20
2025
2025
Amazon API Gateway now supports additional TLS security policies for REST APIs
Jan 23
2024
2024
Consuming private Amazon API Gateway APIs using mutual TLS
Sep 8
2026
2026
Bring your own client certificate for backend mTLS in Amazon API Gateway
Nov 21
2025
2025
Enhancing API security with Amazon API Gateway TLS security policies
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.