For developers · Checked 1 October 2026

Cleartext HTTP and certificate transparency on Android 17

Short answer: Google plans to deprecate the usesCleartextTraffic manifest attribute in a future release. Apps that still make plain HTTP connections should move to a network security configuration file that lists the domains allowed to use cleartext. Separately, apps targeting Android 17 (API level 37) get certificate transparency enabled by default, so HTTPS connections must use certificates recorded in public CT logs unless you opt a domain out.

Defaults by API level

From Android Developers’ Network security configuration page, read 1 October 2026.

API levelCleartext HTTPCertificate transparency
27 and lower (Android 8.1)Allowed by defaultNot available
28 to 35 (Android 9 to 15)Blocked by defaultNot available
36 (Android 16)Blocked by defaultAvailable, off unless you opt in
37 (Android 17) and higherBlocked by defaultOn by default

Moving off usesCleartextTraffic

Instead of switching cleartext on for the whole app, add a network security configuration with a domain-config that sets cleartextTrafficPermitted="true" only for the hosts that need HTTP. The file works on API level 24 and higher. If your minimum API level is 24 or above, use the file alone and drop usesCleartextTraffic. If it is lower than 24, Google says to do both: set usesCleartextTraffic="true" for older devices and add the configuration file. You can also use the file the other way, blocking cleartext for specific domains on apps that still allow it.

Certificate transparency by default

Certificate transparency (RFC 6962) checks that a server’s certificate was logged publicly, which helps catch mis-issued certificates. On Android 16 you opt in with <certificateTransparency enabled="true"/>; once you target Android 17 it is on for every connection. If you must reach a host whose certificate isn’t logged, for example an internal server, add a domain-config for it with <certificateTransparency enabled="false"/>. Connections that use custom trust anchors are not checked.

Also new in Android 17: Encrypted Client Hello

Android 17 adds Encrypted Client Hello, which hides the server name during the TLS handshake. It needs support in your networking library, and you can turn it off per domain in the network security configuration with domainEncryption mode="disabled".

Other Android 17 changes

Where Censuus fits

Secure connections protect the users you have; being found brings more. Censuus ranks apps by the visits they draw, and adding your app is free on the List my app form. Placement comes from traffic and sponsorship: apps climb on the visits they draw, and a sponsor can pay to rise higher.

Frequently asked questions

Is android:usesCleartextTraffic deprecated?

Google has announced a plan to deprecate it in a future release and asks apps to use a network security configuration file instead.

Why is cleartext HTTP blocked in my Android app?

Since Android 9 (API level 28), cleartext traffic is disabled by default. Allow it only for the domains that need it with cleartextTrafficPermitted="true" in a network security configuration.

Should I still set usesCleartextTraffic if my minSdk is below 24?

Yes. Network security configuration files only work on API level 24 and higher, so Google says to set usesCleartextTraffic="true" and also add the configuration file.

Is certificate transparency enabled by default on Android?

For apps targeting Android 17 (API level 37), yes. On Android 16 it is available but off unless you opt in, and it isn’t available on Android 15 and lower.

How do I turn off certificate transparency for one domain?

Add a domain-config for that domain in your network security configuration with certificateTransparency enabled="false".

Guides for app developers

Put your app in the ranking

Censuus ranks apps by the visits they draw and by sponsorship, no bots. Listing is free; sponsorship raises placement.