aws AWS What's New ·

AWS IAM Outbound Federation Adds Private OIDC Discovery via VPC Endpoints

securityawsgaarchitectaws-iam
feature

AWS Identity and Access Management (IAM) outbound identity federation now supports interface VPC endpoints for OIDC discovery APIs. This enables AWS workloads to privately access OIDC metadata and JSON Web Key Set (JWKS) verification keys from within a VPC using AWS PrivateLink, removing the need for traffic to traverse the public internet. The enhancement addresses network security requirements for workloads in VPCs with restricted internet access, allowing external services to verify JWTs without public endpoint access. This capability is available in all AWS commercial, GovCloud (US), and China Regions at standard PrivateLink rates.

Features (1) ›
  • Private OIDC Discovery for IAM Outbound Identity Federation

    IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints. This allows AWS workloads to privately access these endpoints from within a VPC using AWS PrivateLink, ensuring that verification key retrieval traffic remains within the AWS network.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/09/aws-sts-vpc-oidc/

Related releases