Identity
Client certificate represents an approved workload/integration, not an individual user.
DEVELOPER
Use mutual TLS where the integration profile requires workload-level authentication in addition to OAuth authorization.
Client certificate represents an approved workload/integration, not an individual user.
Validate chain, hostname and policy; do not disable certificate verification.
Private keys stay in protected keystore/HSM-equivalent boundary according to deployment policy.
Support overlap and staged rotation before expiry to avoid integration outage.
mTLS authenticates the approved workload identity; key protection, certificate trust, rotation and revocation must be operated for the deployed environment.