A TLS handshake where both client and server present and verify certificates — proves the identity of BOTH parties, not just the server. Common in zero-trust networks and service-to-service authentication.
Standard TLS authenticates the server to the client (your browser verifies google.com's certificate). mTLS adds the reverse: the server requires and verifies a client certificate too. Used for: service-to-service authentication in microservice meshes (Istio, Linkerd inject mTLS automatically), API access where username/password is insufficient (mTLS between two banking systems), and any zero-trust network where every connection requires cryptographic identity proof.
Configuring an Istio service mesh to enforce mTLS for all internal pod-to-pod traffic — no service can talk to another without a valid certificate.
mTLS is the gold standard for inter-service authentication in zero-trust architectures — much stronger than network-level controls alone.
Need help implementing this in your business?
Get Started