Review API Gateway backend client certificate settings

Configure the API Gateway client certificate required by the backend.

Description

API Gateway clientCertificateId identifies a client certificate used by a backend to authenticate API Gateway in supported integrations. Its absence does not disable HTTPS between callers and API Gateway.

A backend that requires this authentication needs both the stage setting and certificate verification. For API Gateway v2, the field supports WebSocket APIs only, not HTTP APIs.

Potential impact

  • Missing required backend authentication can reject connections or leave the intended source verification absent.
  • Expired certificates or missed rotation can interrupt service connections.

Remediation

For a supported API whose backend requires certificate authentication, set clientCertificateId and configure the backend to verify that certificate. Manage expiry and rotation and confirm that unauthenticated connections are rejected. Do not apply this field to API Gateway v2 HTTP APIs.

Examples

These excerpts compare backend certificates for a WebSocket API stage. Prepare exampleApi, exampleClientCertificate of type aws:apigateway:ClientCertificate, and the stage and deployment settings separately.

Before

yaml
resources:
  example:
    type: aws:apigatewayv2:Stage
    properties:
      apiId: ${exampleApi.id}

After

yaml
resources:
  example:
    type: aws:apigatewayv2:Stage
    properties:
      apiId: ${exampleApi.id}
      clientCertificateId: ${exampleClientCertificate.id}

The after example associates the prepared client certificate ID with the stage. Specifying the ID alone does not complete backend verification or caller authentication.

References