- AgentCore Gateway now supports TLS certificates signed by private CAs for MCP, OpenAPI, and HTTP proxy targets.
- Enables native, secure connections to private VPC endpoints without an intermediate ALB, using PEM‑encoded CA certificates from S3 or Secrets Manager.
- Feature is available in all regions where AgentCore Gateway and Amazon VPC Lattice are supported.