Present client certificates to backend services with mutual TLS in API Gateway - Amazon API Gateway
Services or capabilities described in AWS documentation might vary by Region. To see the differences applicable to the AWS European Sovereign Cloud Region, see the AWS European Sovereign Cloud User Guide.

Present client certificates to backend services with mutual TLS in API Gateway

API Gateway can present a client certificate to your backend during the TLS handshake. Your backend can then verify that requests come from API Gateway. This creates a mutual TLS connection between API Gateway and your backend service.

You can choose from two approaches:

  • AWS Certificate Manager (ACM) certificates – Import your own CA-signed certificate from ACM and attach it to your API stage. With this approach, you get full certificate chains, automatic renewal, and integration with your existing PKI infrastructure.

  • API Gateway-generated certificates – Generate a self-signed certificate in API Gateway. This approach requires no external certificate infrastructure. The certificate expires after 365 days and must be rotated manually.