Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A private API in Amazon API Gateway is a REST API that clients can call only from an Amazon VPC through an interface VPC endpoint powered by AWS PrivateLink. It keeps access off the public internet, but it also requires a resource policy and brings DNS, protocol, and API-type constraints you should weigh before choosing it.

What a private API does

A private API controls how clients reach API Gateway. A client inside a VPC sends its request through an interface VPC endpoint; the API is not callable through a public API Gateway endpoint. AWS describes this traffic as using secure connections, isolated from the public internet, and staying within the Amazon network.

This boundary suits services intended for internal applications, regulated workloads, or systems whose network design requires private access. It does not, by itself, define how API Gateway reaches the application behind the API; that is a separate architectural choice.

How clients connect

From a VPC

Create an interface VPC endpoint for API Gateway in the client VPC, then configure the private REST API and its policies to allow the intended requests. One endpoint can serve multiple private APIs, which can reduce the number of endpoints you need to manage. You can associate an endpoint with an API to create a Route 53 alias for invocation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

From an on-premises network

A network connected to the VPC through AWS Direct Connect can reach the private API through the VPC endpoint. This extends private connectivity to on-premises callers without making the API publicly reachable.

Across accounts

A cross-account design can allow a specific interface endpoint in the private API’s resource policy and use an endpoint policy in the caller’s account. The API and endpoint must be in the same AWS Region for this pattern.

Which policies you need

API resource policy

A private REST API requires a resource policy; AWS deployments without one fail. Use conditions such as aws:SourceVpc or aws:SourceVpce to restrict calls to named VPCs or interface endpoints. The choice depends on whether the intended boundary is a VPC or a particular endpoint.

VPC endpoint policy

An endpoint policy is an additional control point. It can restrict which principals may use the endpoint and which APIs they may invoke. The API resource policy governs access at the API; the endpoint policy governs use of the endpoint. Combining them creates separate checks rather than a substitute for either layer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Private API versus private integration

These terms describe different sides of the connection. A private API governs how a client reaches API Gateway; a private integration governs how API Gateway reaches an HTTP or HTTPS backend inside a VPC.

Architecture term Controls Typical use
Private API Client-to-API Gateway access Keep API access within a VPC endpoint boundary
Private integration API Gateway-to-backend access Expose an HTTP/HTTPS VPC resource to API clients, including clients outside the VPC

For REST APIs, AWS supports VPC links V2 to Application Load Balancers. VPC links V1 are legacy and are not the choice for new links. A private integration lets API Gateway reach VPC backends such as containerized applications while the API continues to use its normal authorization methods.

DNS choices and the public API trade-off

Use private DNS for simpler calls

With private DNS enabled for the interface endpoint, callers in the VPC can invoke the private API without sending a Host or x-apigw-api-id header. The trade-off is that those callers cannot reach API Gateway public default endpoints from the same VPC while private DNS is enabled.

Support private and public APIs from one VPC

If callers need both private APIs and public API Gateway default endpoints, AWS recommends disabling private DNS and creating a private hosted zone for each private API. Other invocation options include Route 53 aliases, custom domains, and the interface endpoint’s public DNS names. Choose the DNS pattern around the APIs callers must reach and how you want them addressed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Private API versus regional or edge-optimized API

Decision point Private API Regional or edge-optimized API
Exposure boundary Callable through an interface VPC endpoint from a VPC-connected network Internet reachable
Policy controls Requires an API resource policy; an endpoint policy can add endpoint-level restrictions Does not use the private API endpoint boundary described here
Connectivity VPC access, on-premises access through Direct Connect, and a same-Region cross-account endpoint pattern Public API access
Endpoint type Private endpoint type is available only for REST APIs Not subject to the private-endpoint-only REST API constraint

Choose a private API when the network boundary is a requirement and you can manage the VPC endpoint, policy, and DNS implications. A regional or edge-optimized API is the relevant alternative when the API must be internet reachable; it does not provide the same VPC-only access boundary.

Limitations to account for

  • API type: Only REST APIs support the private endpoint type.
  • TLS: Private APIs support TLS 1.2.
  • HTTP protocol: HTTP/2 requests are enforced to HTTP/1.1.
  • IP addressing: Only dualstack addressing is supported, so you cannot restrict the private API to IPv4-only addressing.
  • Private integration transport: Integration traffic uses HTTP by default; configure HTTPS if encrypted transport to the backend is required.
  • Integration ownership: All resources used by a private integration must be owned by the same AWS account.

Decide whether a private API fits

  • Use one when callers should reach the API through a VPC endpoint rather than a public API endpoint.
  • Plan for a required API resource policy and decide whether an endpoint policy should further restrict endpoint use.
  • Check whether clients need both private and public API Gateway default endpoints from the same VPC before enabling private DNS.
  • Confirm that REST API support and the TLS, HTTP/2, and dualstack constraints fit the workload.
  • If API Gateway must reach a VPC backend, design the private integration separately and account for its VPC link, transport, and account-ownership requirements.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.