Browse documentation
On this page

Peren documentation

Outbound network

Choose among allowlisted outbound fetch, client mTLS, and host-owned AWS SigV4 signing.

A Worker cannot call the network until you configure a binding. Choose the binding for the call you need, then use it from the Worker. Peren checks the host and holds the credentials in the node process.

Network bindings

Three bindings, three calls. OUTBOUND MTLS_CERTIFICATE AWS_SIGV4 env.PUBLIC_API.fetch TypeError host absent cf.mtlsCertificate missing PEM fails before listen env.AWS_BEDROCK.fetch node signs host operation failed
Capability Binding type When to use it
Allowlisted fetch outbound Call a specific HTTPS host without credentials or signing
Client mTLS mtls_certificate Present a client certificate on an outbound request
AWS SigV4 aws_sigv4 Sign requests to an AWS service without exposing keys to Worker code

Use Outbound fetch when the Worker only needs an allowlisted host. Use Client mTLS when the upstream requires a client certificate. Use AWS SigV4 when Peren must sign the request in the node process.

Fleet [mtls] peer material is separate from the Worker client-certificate binding. See Networking and ports.