AWS IAM Now Lets You Verify OIDC Tokens Privately Inside Your VPC
AWS IAM outbound identity federation now supports VPC endpoints for OIDC discovery, meaning you can fetch verification keys and metadata without exposing traffic to the public internet. This is perfect if your workloads live in locked-down VPCs and need to verify short-lived JWTs from external services while keeping everything within AWS's private network.
source: [aws/whats-new]