Free tool
AASA and assetlinks.json generator
Build the apple-app-site-association file for iOS Universal Links and the assetlinks.json file for Android App Links. Enter your app details, then copy or download a file that is ready to upload.
- Free, no account
- Runs in your browser
- Apple’s current components format
Already have the files? Check them with the validator
Apps
Add every app that should open links on this domain. Each one becomes an entry in appIDs.
- App 1
10 characters, in your Apple Developer account under Membership details.
From your app target in Xcode, for example com.example.app.
Paths that open the app
Rules are checked from top to bottom and the first match wins, so put exclusions above broader rules. * matches any characters, ? exactly one.
- Rule 1
name=value pairs joined by &
Other services
Your file
apple-app-site-association
Example. Fill in your details to replace it.
{
"applinks": {
"details": [
{
"appIDs": [
"ABCDE12345.com.example.app"
],
"components": [
{
"/": "/*"
}
]
}
]
}
}Generated in your browser. Nothing is sent anywhere.
Where to host it
- Upload it to
https://your-domain/.well-known/apple-app-site-association, without a.jsonextension. - Serve it over HTTPS with a valid certificate and a direct 200, with no redirects.
- Send the header
Content-Type: application/json. - Repeat on every host in your links:
example.comandwww.example.comeach need the file and anapplinks:entry. - Apple’s CDN fetches a new file within 24 hours. Test with
?mode=developerin the meantime.
Rather not host files yourself? Smart links are free, and on Enterprise Appy serves both files on your app’s link domain.
Create a free linkHow it fits together
Two files, one handshake
Universal Links and App Links only open your app when both sides vouch for each other. The app names the domain, and a file on that domain names the app. If either half is missing, the link opens your website instead.
iOS app
Associated Domains entitlement
applinks:example.comYour domain
example.com/.well-known/
apple-app-site-association
Lists the app ID: Team ID plus bundle ID
ABCDE12345.com.example.appassetlinks.json
Lists the package name and SHA-256 fingerprint
com.example.app · 14:6D:E9:…
Android app
Intent filter with autoVerify
android:autoVerify="true"android:host="example.com"Both halves match: the link opens the app
Anything missing: the link opens your website
Field by field
What each key in the files means
Both files are plain JSON. These are the keys the generator writes, plus the optional ones worth knowing.
apple-app-site-association
applinks- The Universal Links service. Everything about which URLs open which app sits inside it.
details- An array of entries, each pairing a set of apps with a set of URL rules. Use several entries when different apps handle different paths.
appIDs- App IDs in the form
<Team ID>.<bundle ID>, for exampleABCDE12345.com.example.app. Each app must also list the domain in its Associated Domains entitlement. components- The URL rules, checked in order. The first rule that matches decides whether the app opens.
/- A pattern for the URL path, such as
/products/*. Leave it out and any path matches. ?- Query items to match, as a dictionary.
{"ref": "?*"}requires a non-emptyrefparameter. #- A pattern for the fragment after
#. exclude- Set to
trueto keep matching URLs on the website. Put these rules above broader ones. comment- A note for people reading the file. iOS ignores it.
webcredentials- Optional. Lists the apps that can use passwords saved for this website through Password AutoFill.
appclips- Optional. Lists the App Clips this domain can launch.
* matches any number of characters, ? exactly one and ?* at least one. Matching is case-sensitive unless you add "caseSensitive": false.
assetlinks.json
[ ]- The file is a JSON array of statements, even when it holds only one.
relationdelegate_permission/common.handle_all_urlslets the app open links to this site.delegate_permission/common.get_login_credsadds shared sign-in credentials.target- The app the statement is about.
namespace- Always
android_appfor an Android app. package_name- The applicationId of the app, for example
com.example.app. sha256_cert_fingerprints- SHA-256 fingerprints of the certificates that sign the app, as uppercase pairs separated by colons. List every key that signs builds people install.
relation_extensions- Optional, Android 15 and later. Its
dynamic_app_link_componentsadds path rules in the style of Apple’s components. Older versions ignore it.
The legacy paths format
Before iOS 13, each entry had a single appID, a paths array with NOT in front of exclusions, and the file needed an empty apps array. iOS 13 and later read appIDs and components. The generator writes only the modern format. If you still support iOS 12, add the legacy keys to the same entry.
{
"applinks": {
"apps": [],
"details": [{
"appID": "ABCDE12345.com.example.app",
"paths": ["NOT /help/website/*", "/buy/*"]
}]
}
}{
"applinks": {
"details": [{
"appIDs": ["ABCDE12345.com.example.app"],
"components": [
{"/": "/help/website/*", "exclude": true},
{"/": "/buy/*"}
]
}]
}
}Common mistakes
Why a correct-looking file still fails
The JSON can be valid and links can still open the website. Check these seven before anything else.
- 01iOS
Wrong Team ID prefix
The file loads, but iOS never opens the app.
Fix
Use the Team ID of the account that signs the release, from Membership details. Not the numeric App Store ID, not a Key ID, and not an agency’s team when the app ships from yours.
Complete Guide to Universal Links for iOS and Android - 02Android
Upload key instead of the Play App Signing key
Your own builds open the app, installs from Google Play open the browser.
Fix
Google signs the apps it delivers with the app signing key. Copy that SHA-256 from Play Console, App integrity, and keep the upload key in the list only if you share builds signed with it.
Android App Links Not Verified: A Five-Minute Diagnosis with adb - 03iOS + Android
The file sits behind a redirect
The URL opens fine in a browser, yet verification fails.
Fix
Apple and Android expect a 200 at the exact URL. Exclude
Universal Links Open Safari? Fix AASA, App Links, Redirects, and Headers/.well-known/from bare-to-www, www-to-bare and language redirects. - 04iOS + Android
Wrong content type, or HTML instead of JSON
The file is there, yet the platform ignores it.
Fix
Serve both files as
Universal Links Open Safari? Fix AASA, App Links, Redirects, and Headersapplication/json. Servers often send the extensionless AASA file asapplication/octet-stream, and some hosts answer with a login page or a bot check. - 05iOS + Android
Forgetting the www host
Links to example.com open the app, links to www.example.com open the website.
Fix
Each host is checked on its own. Upload the file to both, list both in Associated Domains and declare both in your Android intent filters.
Complete Guide to Universal Links for iOS and Android - 06iOS
An exclusion below a catch-all rule
Pages you meant to keep on the website open the app.
Fix
The first matching rule wins. Move
excluderules above/*, as the Appy example in the generator does. - 07iOS
A .json extension or the wrong folder
Nothing is found at the address iOS requests.
Fix
The file is named
apple-app-site-association, with no extension, and lives in/.well-known/. The download button above already uses that name.
Skip the hosting
Let Appy serve both files for you
On Enterprise, your app gets its own link domain, and Appy hosts apple-app-site-association and assetlinks.json on it, built from the Team ID, bundle ID, package name and fingerprints you register. Smart links themselves are free, and deep links come with Pro.
- Free plan
- No credit card
- Unlimited clicks on every plan
- Links keep working if you cancel
Frequently asked questions
What is an apple-app-site-association file?
A JSON file on your domain that tells iOS which apps may open which of your URLs as Universal Links. It lives at https://your-domain/.well-known/apple-app-site-association, has no file extension and lists app IDs (Team ID plus bundle ID) with the URL rules each one handles.
What is assetlinks.json?
The Android counterpart, based on Google’s Digital Asset Links. It sits at https://your-domain/.well-known/assetlinks.json and names the package and the signing certificate fingerprints of the app allowed to open your links. Android checks it when the app is installed and only then treats your links as verified App Links.
Where do I upload the generated files?
Into the /.well-known/ folder at the root of every host you use in links. Both files must load over HTTPS with a direct 200, no redirects and the application/json content type. Static hosts often need a header rule for the AASA file, because it has no extension.
Where do I find my Team ID and bundle ID?
The Team ID is in your Apple Developer account under Membership details. The bundle ID is on the General tab of your app target in Xcode. Together they form the app ID, such as ABCDE12345.com.example.app.
How do I get the SHA-256 fingerprint for assetlinks.json?
If Google Play signs your app, open Play Console, go to App integrity and copy the SHA-256 of the app signing key certificate. For keys you hold yourself, run keytool -list -v -keystore my-release-key.keystore or ./gradlew signingReport. The generator accepts the value with or without colons.
Should the AASA file use paths or components?
Use components. Apple introduced it with iOS 13, and it supports query items, fragments, exclusions and comments. The older paths array is only needed if you still support iOS 12 or earlier; in that case put both in the same entry.
Can one file cover several apps?
Yes. In the AASA file, list every app ID in appIDs, or add separate details entries when apps handle different paths. In assetlinks.json, add one statement per package to the array. The generator handles several iOS apps; for a second Android package, copy the statement and change the package name and fingerprints.
How long do changes take to reach devices?
Apple says its CDN requests your AASA file within 24 hours, and devices check for updates about once a week after installation. Android verifies when the app is installed; on a test device, adb shell pm verify-app-links --re-verify com.example.app runs the check again.
Do I need to sign the AASA file?
No. Signing it with your TLS certificate was only needed on iOS 8. From iOS 9 on, a plain JSON file served over HTTPS is what Apple expects.
Is anything I enter sent to Appy?
No. The files are generated by code running in your browser, and nothing you type is uploaded or stored. The validator works differently: it fetches the files from your domain when you run it.
Next steps
Check the result and read on
- Free toolUniversal Link ValidatorOnce the files are live, check them on your domain, on Apple’s CDN and through Google’s Digital Asset Links API.
- GuideComplete Guide to Universal Links for iOS and AndroidEverything you need to know about universal links, deep links, and app links. Learn how to implement them and boost your mobile marketing.
- GuideUniversal Links Open Safari? Fix AASA, App Links, Redirects, and HeadersA practical troubleshooting workflow to fix universal links and app links that open the browser instead of your app.
- GuideAndroid App Links Not Verified: A Five-Minute Diagnosis with adbSince Android 12, an App Link that fails domain verification opens in the browser instead of your app — silently, and not on every device. The adb checklist that finds the cause fast, including the Play signing key mismatch behind most incidents.
- GuideDeep Linking vs Universal Links: Complete ComparisonUnderstand the key differences between deep links and universal links, when to use each, and how to implement them effectively.