AgentCore Gateway supports private TLS certificates for VPC endpoints

Published
October 2, 2026
https://aws.amazon.com/about-aws/whats-new/2026/10/agentcore-gateway-private-tls-vpc/

Amazon Bedrock AgentCore Gateway Updates

Amazon Bedrock AgentCore Gateway now supports TLS certificates signed by private certificate authorities (CAs) on MCP, OpenAPI, and HTTP proxy targets. This feature allows secure connections to gateway targets using TLS certificates issued by your own private certificate authority, enabling native connections to private endpoints in your VPC without needing an intermediate Application Load Balancer.

You can register a private CA certificate with gateway targets using private endpoints powered by Amazon VPC Lattice. The gateway fetches your PEM-encoded CA certificate from Amazon S3 or AWS Secrets Manager and uses it as the trust anchor for outbound TLS connections. This support is available for MCP server targets, OpenAPI targets, and HTTP proxy (passthrough) targets.

Private CA support on AgentCore Gateway is available in all Regions where both AgentCore Gateway and Amazon VPC Lattice are available. For more information, see the AgentCore Developer Guide.

What to do

  • Register your private CA certificate with your gateway targets.
  • Configure your gateway to fetch the CA certificate from Amazon S3 or AWS Secrets Manager.
  • Update your connection settings to use the new private CA certificates.

Source: AWS release notes




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.