← Back to Labs
Certificate Pinning Outcome Explorer
Compare plain PKI, brittle certificate pins, SPKI pins, and backup-pin rotations under the same TLS scenarios.
Pin strategyChoose what the client enforces after path validation
Pinned primary SPKI
sha256/8A1euX3N7sLQW0fE4y0QxQ8Fm7g1bVn0m3fV2H1x6Eg=
Pinned backup SPKI
sha256/wY3R9W1vL6x4pQF5dD4nS5qP2tXg8rM4aC1uZ7bK0LA=
Scenario
Real edge certificate
No interception. Expected chain and expected key.
Operational reading
Accept: the chain validates and the chosen pin rule matches.
Step 1 / 5Normal PKI accepts the real service certificate
The first connection succeeds because the certificate chains to a trusted root and the key matches what the app expected during rollout.
Arrow keys to navigate · R to reset
Tap dots to jump to any step