Home icon

AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery

News



AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery APIs, allowing private access to verification keys via AWS PrivateLink.

  • Access OIDC discovery metadata and JWKS verification keys privately within VPC using PrivateLink
  • Eliminates need for long-lived credentials; workloads use short-lived JWTs from AWS STS
  • External services verify tokens using public keys without internet traversal
  • Supports workloads in VPCs with restricted internet access
  • Available in all commercial AWS Regions, GovCloud, and China Regions
  • No additional charge beyond standard PrivateLink pricing

This enhancement enables secure JWT verification for external services while maintaining network isolation for restricted VPC environments.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Nov 19
2025
Simplify access to external services using AWS IAM Outbound Identity Federation
Aug 31
2026
Amazon Redshift now supports AWS IAM Identity Center authentication with enhanced VPC routing
Nov 20
2025
AWS IAM enables identity federation to external services using JSON Web Tokens (JWTs)
Jul 29
2026
AWS IAM Identity Center extends multi-Region support to Identity Center directory

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.