field Registered
Verified 2026-09-18 · registry updated 2026-08-28

Public-Key-Pins

A legacy certificate-pinning response field retained in the registry.

Do not deploy HPKP or Public-Key-Pins in new applications; misconfiguration can lock users out and the mechanism is obsolete in modern browser practice.

httpheadersecuritydeprecated

Reference (http)

Public-Key-Pins: pin-sha256="..."; max-age=5184000

Do not deploy HPKP or Public-Key-Pins in new applications; misconfiguration can lock users out and the mechanism is obsolete in modern browser practice.

Common mistakes

  • Copying an old HPKP example into a production site.

IANA registry: http-fields/field-names

Registry reference: RFC 7469: Public Key Pinning Extension for HTTP

Permalink: https://merginit.com/reference/http/field-public-key-pins