What Is SSL Pinning? Why It Breaks Proxies and How to Debug Pinned Apps
SSL pinning (certificate pinning) is a technique where an app accepts only a specific server certificate or public key instead of any certificate signed by a trusted authority. It protects users from interception, but it also blocks debugging proxies such as Charles or Burp, because their generated certificates do not match the pin.
Also called: certificate pinning, public key pinning, TLS pinning
How pinning works
Normally a TLS client trusts any certificate that chains to a root authority in its trust store. With pinning, the app also checks that the server's certificate, or more commonly its public key hash, equals a value compiled into the app. A proxy can make the chain valid by installing its own root, but it cannot forge the pinned key, so the connection is rejected.
Debugging a pinned app you own
- Debug build without pins: the cleanest option. Ship pinning only in release builds, or allow the debug CA through config such as Android's network security config
debug-overrides. - Intercept before TLS: if the app is web-based (browser, Smart TV web app, hybrid WebView), hook requests in JavaScript where they are still plaintext. This is how the ProxyCeptor SDK works, so pinning is never involved.
- Runtime patching: security testers use tools such as Frida to disable pin checks on test devices. This is common in authorised mobile pentests, but it is fragile and platform-specific.
Where ProxyCeptor fits
ProxyCeptor does not break or bypass TLS. It works inside apps whose JavaScript you control: web apps in Chrome, and web-runtime apps on Samsung Tizen, LG webOS, Android TV WebViews and similar platforms. For those, pinning and root certificates are irrelevant because interception happens before the network layer. For closed native apps, use a debug build or a MITM proxy with an authorised pinning bypass.
Frequently asked questions
Is SSL pinning still recommended?
It is debated. Pinning adds protection but causes outages when certificates rotate unexpectedly. Many teams pin to a backup set of public keys, or rely on Certificate Transparency instead.
Can Charles Proxy bypass SSL pinning?
Not on its own. Charles needs the app to trust its certificate, which pinning prevents. You need a debug build or a runtime patch.
How do I test a Smart TV app that uses HTTPS?
Load the ProxyCeptor SDK into the TV web app and manage rules from the cloud dashboard. See debugging Smart TV apps without SSL certificates.
Keep learning
Intercept your first request in under a minute
Create a free ProxyCeptor account to mock, delay, block and rewrite API traffic, then share the same rules with your team.