Upcoming TLS Certificate Rotation

Scheduled for Mar 5, 07:00 - 10:00 PST

Scheduled

PayTrace will be rotating our TLS certificates on March 5, 2026. To ensure uninterrupted service, please work with your developer or integration provider to review and implement the following recommendations before March 1, 2026.

Key Changes
Our API endpoints will undergo a planned TLS certificate rotation. While we will maintain the same Certificate Authority (CA), the leaf and intermediate certificates in the chain will be updated.

Important Implementation Advisory
We have observed that some integrators are implementing certificate pinning in a way that could lead to service disruptions. To maintain security while ensuring service continuity:
✅ DO: Pin the root CA certificate
❌ DO NOT: Pin the complete certificate chain or leaf certificates

Rationale
Root CA pinning provides the security benefits of certificate pinning while maintaining operational flexibility.
Full chain or leaf certificate pinning will cause failures during routine certificate rotations
Root CAs change very infrequently, reducing maintenance overhead

Implementation Resources
Amazon Trust Service Root CA Repository: https://www.amazontrust.com/repository/
Mozilla CA/Root CA Lifecycles: https://wiki.mozilla.org/CA/Root_CA_Lifecycles
OWASP Certificate and Public Key Pinning: https://owasp.org/www-community/controls/Certificate_and_Public_Key_Pinning

Expected Timeline
February 17, 2026: Announcement and preparation period begins
March 1, 2026: Date all modifications must be made by
March 5, 2026: Certificate rotation date

Support
If you have any questions around the upcoming certificate rotation, please contact Developer Support at developersupport@paytrace.com.
Posted Feb 17, 2026 - 16:34 PST
This scheduled maintenance affects: JSON API and Traditional API & Secure Checkout.