Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Plugin.Maui.TlsPin 1.0.2 is presented as a way to apply SPKI SHA-256 pin checks to a specific .NET MAUI HttpClient. A pin mismatch should reject the request when normal enforcement is enabled; the package article also describes a ReportOnly mode that logs a failure callback but allows the request. Its configuration, platform, and failure-behavior details below are claims from the NuvyntraLabs article; the linked package documentation and repository could not be independently retrieved here.
How the package is configured on a named HttpClient
The article describes registering the pinning service and then attaching pin data to the client that needs it. Its example uses a named payments client, so pin checks are associated with that client rather than applied indiscriminately to every HTTP request in the app.
builder.Services
.UseTlsPin()
.AddHttpClient("payments")
.AddTlsPin(new TlsPinSet
{
// Configure host-specific SPKI SHA-256 pins here.
});
This is the article’s registration pattern; the exact API should be checked against the package version used by your project because its official documentation and repository were not independently verified. The article characterizes UseTlsPin as a no-op registrar and says it does not create a Current singleton.
Free tools Windows power users keep installed
One-click scans. No signup required.
What value to configure as an SPKI pin
A configured pin is described as the base64-encoded SHA-256 hash of the certificate’s Subject Public Key Info (SPKI), not a hash of the entire certificate. The article identifies TlsPin.ComputeSpkiSha256 as a helper that accepts an X509Certificate2 and returns the value to configure. It describes the underlying input as certificate.PublicKey.ExportSubjectPublicKeyInfo().
#1 Best Overall
Configure a primary pin and a backup pin for each host. The backup should represent a key you can use in a future certificate, not simply duplicate the active pin; its purpose is to let clients accept the planned key after rotation.
What happens when pins are empty or a host is not listed
The package article reports registration-time validation and strict host handling:
Rank #2
- Full Stack Python Security: Cryptography, TLS, and attack resistance
- Manning
- ABIS BOOK
- Empty configuration:
AddTlsPinthrows during registration if the pin dictionary is empty or a host’sSpkiSha256list is empty. - Unlisted host: The described default is to reject an unpinned host when
AllowUnpinnedHostsis not enabled. - HTTPS requirement: The article says
RequireHttpsdefaults totrue.
For a client that calls multiple hosts, make sure each host it actually uses is represented in the pin configuration when unpinned hosts are disallowed. These defaults and validation details are attributed to the NuvyntraLabs article rather than independently confirmed package behavior.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What a pin mismatch does
With ReportOnly disabled, the article says a mismatch fails the request: the server’s presented SPKI does not match the configured pins, so the call is rejected. This is the fail-closed behavior to use when pinning is meant to enforce trust beyond ordinary certificate validation.
Rank #3
With ReportOnly enabled, the article says OnPinFailure is invoked with a reason such as “pin mismatch” or “unpinned host,” and the request is allowed to continue. That makes it useful as a staging diagnostic, not as enforcement: a request permitted in this mode is not protected from the pin failure.
How to stage pins and prepare for key rotation
- Calculate the pin values. Use the package’s described helper or another verified process to obtain the base64 SHA-256 SPKI hash for the public key that the host will present.
- Configure both active and backup pins. Add the current key and a planned replacement key to that host’s pin list before rotating the server’s leaf key.
- Exercise the client in staging. The article recommends enabling
ReportOnlyto observe failures and confirm that the host and hash configuration match what the server presents. - Review every failure callback. Investigate “pin mismatch” and “unpinned host” reports rather than treating the allow-through mode as proof that the configuration is correct.
- Disable ReportOnly for the production build. The article recommends turning it off before a store build so mismatches reject requests.
- Rotate the server key only after clients have the backup pin. This reduces the risk that installed app versions become unable to connect when the active leaf key changes.
Pinning can make a key change an availability event for clients that do not yet trust the replacement. A backup pin is therefore part of deployment planning, not merely an extra configuration value.
Rank #4
Platform details and implementation scope
The article lists Android, iOS, Mac Catalyst, and Windows, and names net10.0 platform target frameworks. It says Android needs the INTERNET permission only if the host manifest does not already declare it, that iOS requires no extra usage string, and that App Transport Security (ATS) remains enabled when RequireHttps is true. Because package metadata and official platform guidance were not independently retrievable, verify these target and platform claims against the exact package release and current platform requirements before relying on them.
The described package handles pin checks; it is not presented as a replacement for the rest of an HTTP stack. The article points to HttpForge for source-generated REST interfaces, ApiResilience for retry, circuit-breaker, or offline-queue functions, and SecureSession for access tokens and 401 refresh. These are alternatives named by the article, not independently evaluated recommendations. If the app already owns a custom HttpClientHandler or platform certificate callback, the article says that existing callback may be a better place to implement pin checks.
Quick Recap
Common configuration problems to check
- Confirm the pin dictionary contains at least one host and each host has a non-empty
SpkiSha256list. - Check that the configured value is a base64 SHA-256 SPKI hash, rather than a certificate fingerprint or a differently encoded digest.
- When unpinned hosts are disallowed, enumerate every host the named client contacts, including any separate API host it uses.
- Ensure the production configuration has
ReportOnlydisabled if a mismatch must reject the call. - Before changing the server leaf key, ensure a backup pin for the replacement key has already reached the relevant app installations.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

