aws AWS What's New ·

Amazon Bedrock AgentCore Gateway supports private TLS certificates for VPC endpoints

securityawsgaengineeraws-s3aws-bedrock
feature

Amazon Bedrock AgentCore Gateway now enables secure connections to private endpoints by supporting TLS certificates signed by private certificate authorities (CAs). This enhancement applies to MCP, OpenAPI, and HTTP proxy targets, allowing users to connect directly to VPC endpoints without needing an intermediate Application Load Balancer. The gateway fetches PEM-encoded CA certificates from Amazon S3 or AWS Secrets Manager to establish trust, integrating with Amazon VPC Lattice for private endpoints. This capability is available in all regions where both AgentCore Gateway and Amazon VPC Lattice operate.

Features (1) ›
  • Private TLS certificate support for AgentCore Gateway targets

    Amazon Bedrock AgentCore Gateway now supports TLS certificates signed by private certificate authorities (CAs) for MCP, OpenAPI, and HTTP proxy targets. This allows secure, native connections to private endpoints in a VPC, eliminating the need for an intermediate Application Load Balancer. Users can register private CA certificates fetched from Amazon S3 or AWS Secrets Manager as trust anchors for outbound TLS connections via Amazon VPC Lattice.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/10/agentcore-gateway-private-tls-vpc/

Related releases