Skip to main content
Pinecone Docs

Search documentation

Type to search this documentation.

On this pageOverview

Configure Private Endpoints

Configure Pinecone Private Endpoints with AWS PrivateLink or Azure Private Link to keep index traffic off the public internet and secure VPCs.

This page describes how to create and use Private Endpoints to connect to Pinecone through AWS PrivateLink or Azure Private Link, keeping your traffic private from the public internet.

The following steps assume you have:

  • Access to the AWS console.
  • Created an Amazon VPC in the same AWS region as the index you want to connect to. You can optionally enable DNS hostnames and resolution, if you want your VPC to automatically discover the DNS CNAME for your PrivateLink and don't want to configure a CNAME.
    Index regionPinecone DNS entry
    us-east-1 (N. Virginia)*.private.aped-4627-b74a.pinecone.io
    us-west-2 (Oregon)*.private.apw5-4e34-81fa.pinecone.io
    eu-west-1 (Ireland)*.private.apu-57e2-42f6.pinecone.io
    eu-central-1 (Frankfurt)*.private.apec-a2ee-38c6.pinecone.io
    ap-southeast-1 (Singapore)*.private.aps-d9bb-582b.pinecone.io
  • Access to the Azure portal.
  • Created an Azure VNet in the same region as the index you want to connect to.
  • A subnet with Private endpoint network policies set to Disabled. This is required for Azure Private Endpoints.
    • DNS resolution for private endpoints requires a manual setup step after creating the endpoint (unlike AWS, where DNS can be auto-configured). See the DNS setup note below.
    Index regionPinecone DNS entry
    eastus2 (Virginia)*.private.eastus2-5e25.prod-azure.pinecone.io

1. Create a private endpoint in your cloud provider

Section titled “1. Create a private endpoint in your cloud provider”

In the AWS console:

  1. Open the Amazon VPC console.
  2. In the navigation pane, click Endpoint.
  3. Click Create endpoint.
  4. For Service category, select Other endpoint services.
  5. In Service settings, enter the Service name, based on the region your Pinecone index is in:
    Index regionService name
    us-east-1 (N. Virginia)com.amazonaws.vpce.us-east-1.vpce-svc-05ef6f1f0b9130b54
    us-west-2 (Oregon)com.amazonaws.vpce.us-west-2.vpce-svc-04ecb9a0e0d5aab01
    eu-west-1 (Ireland)com.amazonaws.vpce.eu-west-1.vpce-svc-03c6b7e17ff02a70f
    eu-central-1 (Frankfurt)com.amazonaws.vpce.eu-central-1.vpce-svc-037997ff6b3d25e34
    ap-southeast-1 (Singapore)com.amazonaws.vpce.ap-southeast-1.vpce-svc-0c12f00812e786068
  6. Click Verify service.
  7. Select the VPC to host the endpoint.
  8. (Optional) In Additional settings, Enable DNS name. The enables you to access our service with the DNS name we configure. An additional CNAME record is needed if you disable this option.
  9. Select the Subnets and Subnet ID for the endpoint.
  10. Select the Security groups to apply to the endpoint.
  11. Click Create endpoint.
  12. Copy the VPC endpoint ID (e.g., vpce-XXXXXXX). This will be used to add a Private Endpoint in Pinecone.

In the Azure portal:

  1. Search for Private Link and select Private Link Center.
  2. In the navigation pane, click Private endpoints.
  3. Click Create.
  4. Select your Subscription and Resource group.
  5. Enter a Name for the private endpoint and select the Region matching your Pinecone index.
  6. Click Next: Resource.
  7. For Connection method, select Connect to an Azure resource by resource ID or alias.
  8. Enter the Resource ID or alias for Pinecone's Private Link Service, based on the region your Pinecone index is in:
    Index regionPrivate Link Service alias
    eastus2 (Virginia)pinecone.bdbc7759-0243-46c1-af51-794c4602745b.eastus2.azure.privatelinkservice
  9. Click Next: Virtual Network.
  10. Select the Virtual network and Subnet for the private endpoint.
  11. Click Next: DNS. Skip the DNS integration tab (you will configure DNS manually after setup).
  12. Click Next: Tags.
  13. Click Review + create, then Create.
  14. Once the private endpoint is created, open it and copy the Resource ID from the Properties tab (or the Overview tab — it's the /subscriptions/…/privateEndpoints/<name> ARM ID). This will be used to add a Private Endpoint in Pinecone.

To add a Private Endpoint using the Pinecone console:

  1. Select your project.
  2. Go to Manage > Network.
  3. Click Add a connection.
  4. Select your cloud provider and region. Only indexes in the selected region in this project will be affected.
  5. Click Next.
  6. Enter the endpoint ID you copied in the section above:
    • AWS: The VPC endpoint ID (e.g., vpce-XXXXXXX)
    • Azure: The private endpoint's ARM Resource ID (e.g., /subscriptions/<sub-uuid>/resourceGroups/<rg>/providers/Microsoft.Network/privateEndpoints/<name>)
  7. Click Next.
  8. (optional) To enable private endpoint access only, turn the toggle on. This can also be enabled later. For more information, see Manage internet access to your project.
  9. Click Finish setup.

Once your private endpoint is configured, you can run data operations against an index as usual, but you must target the index using its private endpoint URL. The only difference in the URL is that .svc. is changed to .svc.private..

You can get the private endpoint URL for an index from the Pinecone console or API.

To get the private endpoint URL for an index from the Pinecone console:

  1. Open the Pinecone console.
  2. Select the project containing the index.
  3. Select the index.
  4. Copy the URL under PRIVATE ENDPOINT.

To get the private endpoint URL for an index from the API, use the describe_index operation, which returns the private endpoint URL as the private_host value:

JavaScript
import { Pinecone } from '@pinecone-database/pinecone';

const pc = new Pinecone({ apiKey: 'YOUR_API_KEY' });

await pc.describeIndex('docs-example');
Go
package main

import (
    "context"
    "encoding/json"
    "fmt"
    "log"

    "github.com/pinecone-io/go-pinecone/v4/pinecone"
)

func prettifyStruct(obj interface{}) string {
    bytes, _ := json.MarshalIndent(obj, "", "  ")
    return string(bytes)
}

func main() {
    ctx := context.Background()

    pc, err := pinecone.NewClient(pinecone.NewClientParams{
        ApiKey: "YOUR_API_KEY",
    })
    if err != nil {
        log.Fatalf("Failed to create Client: %v", err)
    }

    idx, err := pc.DescribeIndex(ctx, "docs-example")
    if err != nil {
        log.Fatalf("Failed to describe index \"%v\": %v", idx.Name, err)
    } else {
        fmt.Printf("index: %v\n", prettifyStruct(idx))
    }
}
curl
PINECONE_API_KEY="YOUR_API_KEY"

curl -i -X GET "https://api.pinecone.io/indexes/docs-example" \
    -H "Api-Key: $PINECONE_API_KEY" \
    -H "X-Pinecone-Api-Version: 2026-07"

The response includes the private endpoint URL as the private_host value:

JavaScript
{  name: 'docs-example',  dimension: 1536,  metric: 'cosine',  host: 'docs-example-jl7boae.svc.aped-4627-b74a.pinecone.io',  privateHost: 'docs-example-jl7boae.svc.private.aped-4627-b74a.pinecone.io',  deletionProtection: 'disabled',  tags: { environment: 'production' },  embed: undefined,  spec: {    byoc: undefined,    pod: undefined,    serverless: { cloud: 'aws', region: 'us-east-1' }  },  status: { ready: true, state: 'Ready' },  vectorType: 'dense'}
Go
index: {  "name": "docs-example",  "dimension": 1536,  "host": "docs-example-jl7boae.svc.aped-4627-b74a.pinecone.io",  "private_host": "docs-example-jl7boae.svc.private.aped-4627-b74a.pinecone.io",  "metric": "cosine",  "deletion_protection": "disabled",  "spec": {    "serverless": {      "cloud": "aws",      "region": "us-east-1"    }  },  "status": {    "ready": true,    "state": "Ready"  },  "tags": {    "environment": "production"  }}
curl
{  "name": "docs-example",  "host": "docs-example-jl7boae.svc.aped-4627-b74a.pinecone.io",  "private_host": "docs-example-jl7boae.svc.private.aped-4627-b74a.pinecone.io",  "status": {    "ready": true,    "state": "Ready"  },  "deployment": {    "deployment_type": "managed",    "region": "us-east-1",    "cloud": "aws",    "environment": "aped-4627-b74a"  },  "read_capacity": {    "mode": "OnDemand",    "status": {      "state": "Ready",      "current_shards": null,      "current_replicas": null    }  },  "schema": {    "fields": {      "embedding": {        "type": "dense_vector",        "description": null,        "dimension": 1536,        "metric": "cosine"      }    }  },  "tags": {    "environment": "production"  },  "deletion_protection": "disabled"}

Once your Private Endpoint is configured, you can turn off internet access to your project. To enable private endpoint access only:

  1. Open the Pinecone console.

  2. Select your project.

  3. Go to Network > Access.

  4. Turn the Private endpoint access only toggle on. This will turn off internet access to the project. This can be turned off at any point.

In addition to creating Private Endpoints, you can also:

To view Private Endpoints using the Pinecone console:

  1. Select your project.
  2. Go to Manage > Network. A list of Private Endpoints displays with the associated endpoint ID and cloud provider.

To delete a Private Endpoint using the Pinecone console:

  1. Select your project.
  2. Go to Manage > Network.
  3. For the Private Endpoint you want to delete, click the ... (Actions) icon.
  4. Click Delete.
  5. Enter the endpoint name.
  6. Click Delete Endpoint.
Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu