Mutual TLS authenticates both ends

Ordinary TLS checks the server. Mutual TLS makes the client prove itself too.

That is unnecessary for a public website, where the whole point is that anybody may visit, and valuable between systems, where only a known set of callers should ever connect. It replaces a shared secret in a config file with a certificate the workload holds, which is both stronger and easier to rotate.

More on TLS and PKI