# AWS adds private access to identity verification endpoints

_Published Friday, September 25, 2026 at 6:08 PM EDT · Infrastructure, Security · Latest · Tier 2 — Notable_

AWS says workloads in restricted virtual private clouds can now retrieve identity verification metadata and public keys through private network endpoints. Previously, those discovery endpoints were reachable only over the public internet, preventing workloads without internet access from retrieving the information needed to verify short-lived identity tokens.

The change extends AWS IAM outbound identity federation, which lets workloads use short-lived tokens when accessing external services instead of keeping long-lived credentials. AWS PrivateLink carries requests to the discovery endpoints within the AWS network. The feature is available in commercial, GovCloud and China Regions, with standard PrivateLink pricing.

## Sources

- [Recent Announcements](https://aws.amazon.com/about-aws/whats-new/2026/09/aws-sts-vpc-oidc/)

---
Canonical: https://techandbusiness.org/newswire/V-r3tG8uezL2xrjZ7NPXUT
Published: 2026-09-25T22:08:17.030Z
Story chronology: 2026-09-25T17:54:00.000Z
Retrieved: 2026-09-25T23:50:16.098Z
Publisher: Tech & Business (techandbusiness.org)
