AWS IAM Outbound Federation Adds Private OIDC Discovery via VPC Endpoints
AWS Identity and Access Management (IAM) outbound identity federation now supports interface VPC endpoints for OIDC discovery APIs. This enables AWS workloads to privately access OIDC metadata and JSON Web Key Set (JWKS) verification keys from within a VPC using AWS PrivateLink, removing the need for traffic to traverse the public internet. The enhancement addresses network security requirements for workloads in VPCs with restricted internet access, allowing external services to verify JWTs without public endpoint access. This capability is available in all AWS commercial, GovCloud (US), and China Regions at standard PrivateLink rates.
Features (1) ›
- Private OIDC Discovery for IAM Outbound Identity Federation
IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints. This allows AWS workloads to privately access these endpoints from within a VPC using AWS PrivateLink, ensuring that verification key retrieval traffic remains within the AWS network.
https://aws.amazon.com/about-aws/whats-new/2026/09/aws-sts-vpc-oidc/
Related releases
- Amazon ElastiCache Global Datastore Adds Resource Tagging and TBAC AWS What's New ·
- Amazon EMR on EKS now supports Spark Connect for interactive workloads AWS What's New ·
- AWS Open-Sources TOLAP for Object-Level Access Control in AI Agent Tools AWS Open Source Blog ·
- AWS HealthOmics Adds IAM Session Policies for Dynamic Run Permissions AWS What's New ·
- AWS launches simplified experience for faster project setup and deployment AWS What's New ·
- AWS STS Simplifies Session Token Limits and Adds Monitoring AWS What's New ·