Summary
Sentry is changing the Certificate Authority (CA) that issues the TLS certificates on our customer-facing endpoints, including our web and event ingestion domains. We are moving from DigiCert to Let's Encrypt and Google Trust Services (GTS).
For almost all customers, this change is transparent and requires no action. Your SDKs and applications will keep connecting to Sentry as they do today.
A small number of customers need to act:
You pin Sentry's TLS certificates in your application.
You send data to Sentry from very old devices or runtimes that don't trust Let's Encrypt or GTS root certificates.
If neither applies to you, there is nothing to do.
What Is Changing
Sentry's TLS certificates secure the connection between your applications and our endpoints. Today those certificates are issued by DigiCert. Going forward, they will be issued by Let's Encrypt and Google Trust Services.
Both Let's Encrypt and GTS have been listed as trusted CAs in our SSL documentation for some time. The certificates themselves are just as secure as our current ones, and the domains you connect to are not changing.
Are You Affected?
Work through the two checks below.
1. Do you pin Sentry's TLS certificates?
Certificate pinning is when your application is configured to trust only a specific certificate or CA when connecting to a service. If your application is pinned to DigiCert, it will reject the connection to Sentry once we switch CAs, and your data will stop being ingested.
You are affected if your application enforces certificate pinning for Sentry's domains. Check your network layer, SDK transport configuration, or mobile app networking settings for pinned certificates or CAs that reference Sentry.
2. Do you send data from very old devices or runtimes?
Devices and software released before the Let's Encrypt and GTS root certificates existed do not trust them, so they cannot establish a secure connection to Sentry after the change.
Known affected platforms:
Platform | Notes |
Android 5 – Android 7 | Released roughly 10–12 years ago |
Java 7 | Released roughly 15 years ago |
Java 8 (without the root CA update) | Fixed in later Java 8 updates |
The most likely impact is on long-lived embedded or IoT devices running unpatched software. Modern, up-to-date devices and runtimes already trust these CAs — most of the web relies on Let's Encrypt today.
What to Do If You Are Affected
If you pin certificates
We recommend that you stop pinning Sentry's TLS certificates. Industry guidance, including from OWASP, advises against pinning because the availability risk outweighs the security benefit for most services.
Recommended: Remove certificate pinning for Sentry's domains and ship a release with the change.
If you must pin: Update your pin set to include the current Let's Encrypt and Google Trust Services CAs, listed on our SSL documentation page. Because certificates now rotate more often, check that page at least every six months and update your pins before they change. Pinning is at your own risk for future rotations.
Either change requires a release of your application, so plan the work with your normal release cycle.
If you use old devices or runtimes
Update the device or runtime to a version that includes the current root CA store.
Where the platform can no longer be updated, add the Let's Encrypt (ISRG Root X1) and Google Trust Services root certificates to the device's trust store.
For embedded or IoT fleets that cannot be updated, plan how those devices will continue to reach Sentry, or expect them to lose connectivity after the change.
Timeline
Sentry's will be making the change in February, 2027. An exact date will be shared when finalized.
If either check above applies to you, make your changes before February 2027 to avoid an interruption in data ingestion.
FAQ
Do I need to do anything?
For most customers, no. Action is only needed if you pin Sentry's certificates or send data from very old, unpatched devices or runtimes.
Is this less secure?
No. Let's Encrypt and Google Trust Services are just as secure as DigiCert, and rotating certificates more frequently improves security.
Are the domains I send data to changing?
No. Only the Certificate Authority that issues our certificates is changing. Your endpoints stay the same.
Where can I find the new certificate details?
See our SSL documentation for the current CAs and certificate information.
Can I still pin certificates?
Yes, but we recommend against it. If you must pin, pin the new CAs and re-check our SSL documentation every few months.
