What Is Mutual TLS (mTLS)?
Mutual TLS extends ordinary TLS — where the client checks the server’s certificate — so that the server also checks the client’s. Both ends present a certificate and prove they hold the matching private key, so each knows who the other is before any data flows. It is a common way for services, and agents acting as services, to authenticate to one another without passwords or bearer tokens that can be stolen and replayed.
Identity before the first byte
A bearer token says "whoever holds this is allowed" — which is exactly the problem if it leaks. mTLS instead ties the connection to a key each side holds and never transmits, so authentication is proven cryptographically at handshake time rather than asserted by presenting a secret.
For machine-to-machine traffic between agents, mTLS is a natural fit: there is no human to type a password, and the certificates can encode which service each end is, so authorisation can be decided from a proven identity.
Related standards
Questions
Does mTLS replace authorization?
No — it proves identity (authentication). What that identity is allowed to do is a separate decision.
Why not just use API keys?
API keys are bearer secrets: anyone who copies one can use it. mTLS binds the connection to a private key that is never sent.
Keep reading
By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.