Description
API Gateway clientCertificateId identifies a client certificate used by a backend to authenticate API Gateway in supported integrations. Its absence does not disable HTTPS between callers and API Gateway.
A backend that requires this authentication needs both the stage setting and certificate verification. For API Gateway v2, the field supports WebSocket APIs only, not HTTP APIs.
Potential impact
- Missing required backend authentication can reject connections or leave the intended source verification absent.
- Expired certificates or missed rotation can interrupt service connections.
Remediation
For a supported API whose backend requires certificate authentication, set clientCertificateId and configure the backend to verify that certificate. Manage expiry and rotation and confirm that unauthenticated connections are rejected. Do not apply this field to API Gateway v2 HTTP APIs.
Examples
These excerpts compare backend certificates for a WebSocket API stage. Prepare exampleApi, exampleClientCertificate of type aws:apigateway:ClientCertificate, and the stage and deployment settings separately.
Before
resources:
example:
type: aws:apigatewayv2:Stage
properties:
apiId: ${exampleApi.id}
After
resources:
example:
type: aws:apigatewayv2:Stage
properties:
apiId: ${exampleApi.id}
clientCertificateId: ${exampleClientCertificate.id}
The after example associates the prepared client certificate ID with the stage. Specifying the ID alone does not complete backend verification or caller authentication.