AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery

Published
September 25, 2026
https://aws.amazon.com/about-aws/whats-new/2026/09/aws-sts-vpc-oidc/

AWS IAM Outbound Identity Federation

AWS IAM outbound identity federation now supports Amazon VPC endpoints for the OpenID Connect (OIDC) discovery APIs. You can access the OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints from within your VPC using AWS PrivateLink, without requiring traffic to traverse the public internet.

IAM outbound identity federation eliminates the need to use long-lived credentials when your AWS workloads access external services. Instead, your workloads request short-lived JSON Web Tokens (JWTs) from AWS Security Token Service (AWS STS). External services verify these tokens using public verification keys and metadata available at OIDC discovery endpoints.

What to do

  • Create an interface VPC endpoint to reach the OIDC discovery endpoints privately.
  • Ensure your workloads can retrieve verification keys within the AWS network.
  • Review the IAM User Guide for more details.

Source: AWS release notes




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.