field Registered
Verified 2026-09-18 · registry updated
2026-08-28Public-Key-Pins
A legacy certificate-pinning response field retained in the registry.
Do not deploy HPKP or Public-Key-Pins in new applications; misconfiguration can lock users out and the mechanism is obsolete in modern browser practice.
httpheadersecuritydeprecated
Reference (http)
Public-Key-Pins: pin-sha256="..."; max-age=5184000
Do not deploy HPKP or Public-Key-Pins in new applications; misconfiguration can lock users out and the mechanism is obsolete in modern browser practice.
Common mistakes
- Copying an old HPKP example into a production site.
IANA registry: http-fields/field-names
Registry reference: RFC 7469: Public Key Pinning Extension for HTTP