Home icon

Bring your own client certificate for backend mTLS in Amazon API Gateway

Compute Blog



This article announces the ability to bring your own client certificate for backend mutual TLS (mTLS) authentication in Amazon API Gateway, enabling secure connections to backends requiring specific certificate authorities.

  • Configure ACM client certificate ARN at API Gateway REST API stage for outbound mTLS handshake
  • Support for third-party certificates imported to ACM or certificates from AWS Private Certificate Authority
  • Solves legacy gateway migration and internal PKI mandate scenarios where backends reject self-signed certificates
  • Solution demonstrates outbound mTLS between API Gateway and ECS Fargate backend with NGINX sidecar
  • Automatic certificate renewal with no downtime when certificates change in ACM
  • Includes step-by-step deployment guide with negative and positive testing scenarios

Enterprises can now authenticate to backends enforcing specific corporate or partner certificate authorities without relying on self-signed certificates.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jan 23
2024
Consuming private Amazon API Gateway APIs using mutual TLS
Nov 21
2025
Enhancing API security with Amazon API Gateway TLS security policies
Nov 20
2025
Amazon API Gateway now supports additional TLS security policies for REST APIs
Jun 7
2024
Amazon API Gateway customers can easily secure APIs using Amazon Verified Permissions

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.