AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery
Checked 30 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · AMAZON-WEB-SERVICES-37C03E74134886AC
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery
Scope: AWS services. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
AWS Identity and Access Management (IAM) outbound identity federation now supports Amazon Virtual Private Cloud (VPC) endpoints for the OpenID Connect (OIDC) discovery APIs. You can now access the OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints from within your VPC using AWS PrivateLink , without requiring traffic to traverse the public internet. IAM outbound identity federation eliminates the need to use long-lived credentials when your AWS workloads access external services. Instead, your workloads request short-lived JSON Web Tokens (JWTs) from AWS Security Token Service (AWS STS). External services verify these tokens using public verification keys and metadata available at OIDC discovery endpoints. Previously, the OIDC discovery endpoints were only reachable over the public internet, so a verifying workload running in a VPC without internet access could not retrieve them. With this launch, you can create an interface VPC endpoint to reach these endpoints privately, keeping the verification key retrieval traffic within the AWS network. This capability helps you meet network security requirements for workloads that operate in VPCs with restricted internet access, while still enabling external services to verify JWTs. This feature is available in all commercial AWS Regions, the AWS GovCloud (US) Regions, and China Regions. There is no additional charge for this feature beyond standard AWS PrivateLink pricing . To learn more, see the IAM User Guide .
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
Checked 30 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source