Tuesday, September 29, 2026 Newsletter Advertise
Breaking
Products

AWS adds PrivateLink VPC endpoints for IAM OIDC discovery APIs

Workloads in VPCs without internet access can now fetch JWKS verification keys and OIDC metadata over the AWS network, Amazon said.

AWS adds PrivateLink VPC endpoints for IAM OIDC discovery APIs. Source: Amazon Web Services

Amazon Web Services said on September 25, 2026 that AWS Identity and Access Management outbound identity federation now supports Amazon Virtual Private Cloud endpoints for the OpenID Connect discovery APIs. The company said the OIDC discovery metadata and JSON Web Key Set verification key endpoints can now be reached from inside a VPC using AWS PrivateLink, without traffic traversing the public internet.

What changed

Previously, according to AWS, the OIDC discovery endpoints were only reachable over the public internet, meaning a verifying workload running in a VPC without internet access could not retrieve them.

With the launch, AWS said customers can create an interface VPC endpoint to reach those endpoints privately, keeping verification key retrieval traffic within the AWS network.

How the federation flow works

AWS said IAM outbound identity federation eliminates the need to use long-lived credentials when AWS workloads access external services. Instead, workloads request short-lived JSON Web Tokens from AWS Security Token Service.

External services verify those tokens using public verification keys and metadata published at OIDC discovery endpoints, the company said.

Availability and pricing

The feature is available in all commercial AWS Regions, the AWS GovCloud (US) Regions and China Regions, according to the announcement.

AWS said there is no additional charge for the feature beyond standard AWS PrivateLink pricing, and pointed customers to the IAM User Guide for details.

Why AWS says it matters

The company said the capability helps customers meet network security requirements for workloads that operate in VPCs with restricted internet access, while still enabling external services to verify JWTs.

What to do

  • Create an interface VPC endpoint if you run verifying workloads in VPCs with restricted or no internet access, so they can retrieve OIDC discovery metadata and JWKS keys privately.
  • Account for standard AWS PrivateLink pricing, which still applies even though the feature itself carries no additional charge.
  • Consult the IAM User Guide for configuration details, as referenced in the AWS announcement.
Key facts and where they come from
  • IAM outbound identity federation now supports VPC endpoints for the OIDC discovery APIs.
    AWS Identity and Access Management (IAM) outbound identity federation now supports Amazon Virtual Private Cloud (VPC) endpoints for the OpenID Connect (OIDC) discovery APIs.
  • Discovery metadata and JWKS endpoints can be reached from a VPC via PrivateLink.
    You can now access the OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints from within your VPC using AWS PrivateLink
  • The endpoints were previously public-internet only.
    Previously, the OIDC discovery endpoints were only reachable over the public internet, so a verifying workload running in a VPC without internet access could not retrieve them.
  • Workloads request short-lived JWTs from AWS STS instead of using long-lived credentials.
    your workloads request short-lived JSON Web Tokens (JWTs) from AWS Security Token Service (AWS STS)
  • Available in commercial, GovCloud (US) and China Regions with no extra charge beyond PrivateLink pricing.
    This feature is available in all commercial AWS Regions, the AWS GovCloud (US) Regions, and China Regions. There is no additional charge for this feature beyond standard AWS PrivateLink pricing.

Read the original from Amazon Web Services →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Products