What Is SSL Pinning? Why Is It Important in Mobile Apps?

· Mobile Security

SSL Pinning forces a mobile or client application to trust only a specific pre-defined certificate or public key during TLS connections, providing a security layer beyond standard TLS validation.

Why Standard TLS Isn't Always Enough

Standard TLS trusts any certificate signed by a CA in the OS trust store. Attackers can install rogue CA certificates on devices (via corporate proxies or malware) to intercept API traffic with a valid-looking certificate. Pinning prevents this.

Certificate Pinning vs Public Key Pinning

Certificate Pinning: The app stores a specific certificate (or its hash). If the server cert doesn't match, the connection is rejected. Requires an app update when the certificate is renewed.

Public Key Pinning: Pins the public key inside the certificate. More flexible — the key can persist across certificate renewals. Requires an update only when the key pair changes.

Implementation

Android: Network Security Config (XML, API 24+) or OkHttp's CertificatePinner. iOS: URLSession with custom SecTrustEvaluate logic, or the TrustKit library. Flutter/React Native: Platform channels or http_certificate_pinning libraries.

Risks

Renewal planning: A pinned certificate renewal requires a coordinated app update — if the old cert expires before the update is approved in the app store, all users lose connectivity.

Backup pins: Always define at least one backup pin to cover emergency certificate changes.

HPKP is dead: Web-based HTTP Public Key Pinning was removed from all major browsers due to management risks. Mobile app pinning remains recommended but requires careful lifecycle management.

Visit the PekiSSL product page to find the right certificate for your needs.

All blog posts