What Is Mutual TLS (mTLS)?

Mutual TLS extends ordinary TLS — where the client checks the server’s certificate — so that the server also checks the client’s. Both ends present a certificate and prove they hold the matching private key, so each knows who the other is before any data flows. It is a common way for services, and agents acting as services, to authenticate to one another without passwords or bearer tokens that can be stolen and replayed.

Ordinary TLS
Client verifies the server
Mutual TLS
Both verify each other with certificates
Avoids
Stealable, replayable bearer secrets

Identity before the first byte

A bearer token says "whoever holds this is allowed" — which is exactly the problem if it leaks. mTLS instead ties the connection to a key each side holds and never transmits, so authentication is proven cryptographically at handshake time rather than asserted by presenting a secret.

For machine-to-machine traffic between agents, mTLS is a natural fit: there is no human to type a password, and the certificates can encode which service each end is, so authorisation can be decided from a proven identity.

Related standards

RFC 8705 — OAuth 2.0 Mutual-TLS

Questions

Does mTLS replace authorization?

No — it proves identity (authentication). What that identity is allowed to do is a separate decision.

Why not just use API keys?

API keys are bearer secrets: anyone who copies one can use it. mTLS binds the connection to a private key that is never sent.

Keep reading

related
What Is Public-Key Cryptography?
related
How Should AI Agents Authenticate?
related
Zero-Trust Architecture for AI Agents
related
Authentication vs Authorization: What’s the Difference?
Trust & the Record
Verify, Don’t Trust: Verification for AI Agents
Trust & the Record
Provenance for Autonomous Actions
Trust & the Record
How Is AI Agent Reputation Earned and Verified?
Trust & the Record
What Is Agent Attestation?
Trust & the Record
What Is a Trust Graph for Agents?
Trust & the Record
What Is a Zero-Knowledge Proof?
Trust & the Record
What Is a zk-Rollup?
Trust & the Record
What Is a Merkle Tree?
Trust & the Record
What Is a Blockchain Oracle?
Trust & the Record
What Is Confidential Computing?
Trust & the Record
zk-Rollup vs Optimistic Rollup: What’s the Difference?
Trust & the Record
TEEs vs Zero-Knowledge Proofs: Two Roads to Privacy
Trust & the Record
What Is a Digital Signature?
Trust & the Record
What Is a Cryptographic Hash Function?
Trust & the Record
What Is a Sybil Attack?
Trust & the Record
What Is Certificate Transparency?
Trust & the Record
Symmetric vs Asymmetric Encryption: What’s the Difference?
Trust & the Record
Hashing vs Encryption: What’s the Difference?

By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.