Appy

Free tool

AASA and assetlinks.json generator

Build the apple-app-site-association file for iOS Universal Links and the assetlinks.json file for Android App Links. Enter your app details, then copy or download a file that is ready to upload.

  • Free, no account
  • Runs in your browser
  • Apple’s current components format

Already have the files? Check them with the validator

Apps

Add every app that should open links on this domain. Each one becomes an entry in appIDs.

  1. App 1

    10 characters, in your Apple Developer account under Membership details.

    From your app target in Xcode, for example com.example.app.

Paths that open the app

Rules are checked from top to bottom and the first match wins, so put exclusions above broader rules. * matches any characters, ? exactly one.

  1. Rule 1

    name=value pairs joined by &

Other services

Your file

apple-app-site-association

Example. Fill in your details to replace it.

{
  "applinks": {
    "details": [
      {
        "appIDs": [
          "ABCDE12345.com.example.app"
        ],
        "components": [
          {
            "/": "/*"
          }
        ]
      }
    ]
  }
}

Generated in your browser. Nothing is sent anywhere.

Where to host it

  1. Upload it to https://your-domain/.well-known/apple-app-site-association, without a .json extension.
  2. Serve it over HTTPS with a valid certificate and a direct 200, with no redirects.
  3. Send the header Content-Type: application/json.
  4. Repeat on every host in your links: example.com and www.example.com each need the file and an applinks: entry.
  5. Apple’s CDN fetches a new file within 24 hours. Test with ?mode=developer in the meantime.
Check a domain with the validator

Rather not host files yourself? Smart links are free, and on Enterprise Appy serves both files on your app’s link domain.

Create a free link

How it fits together

Two files, one handshake

Universal Links and App Links only open your app when both sides vouch for each other. The app names the domain, and a file on that domain names the app. If either half is missing, the link opens your website instead.

iOS app

Associated Domains entitlement

applinks:example.com

Your domain

example.com/.well-known/

  • apple-app-site-association

    Lists the app ID: Team ID plus bundle ID

    ABCDE12345.com.example.app
  • assetlinks.json

    Lists the package name and SHA-256 fingerprint

    com.example.app · 14:6D:E9:…

Android app

Intent filter with autoVerify

android:autoVerify="true"android:host="example.com"

Both halves match: the link opens the app

Anything missing: the link opens your website

iOS fetches the file through Apple’s CDN when the app is installed and checks for updates about once a week. Android verifies when the app is installed. Neither looks at your domain at the moment of the tap.

Field by field

What each key in the files means

Both files are plain JSON. These are the keys the generator writes, plus the optional ones worth knowing.

apple-app-site-association

applinks
The Universal Links service. Everything about which URLs open which app sits inside it.
details
An array of entries, each pairing a set of apps with a set of URL rules. Use several entries when different apps handle different paths.
appIDs
App IDs in the form <Team ID>.<bundle ID>, for example ABCDE12345.com.example.app. Each app must also list the domain in its Associated Domains entitlement.
components
The URL rules, checked in order. The first rule that matches decides whether the app opens.
/
A pattern for the URL path, such as /products/*. Leave it out and any path matches.
?
Query items to match, as a dictionary. {"ref": "?*"} requires a non-empty ref parameter.
#
A pattern for the fragment after #.
exclude
Set to true to keep matching URLs on the website. Put these rules above broader ones.
comment
A note for people reading the file. iOS ignores it.
webcredentials
Optional. Lists the apps that can use passwords saved for this website through Password AutoFill.
appclips
Optional. Lists the App Clips this domain can launch.

* matches any number of characters, ? exactly one and ?* at least one. Matching is case-sensitive unless you add "caseSensitive": false.

assetlinks.json

[ ]
The file is a JSON array of statements, even when it holds only one.
relation
delegate_permission/common.handle_all_urls lets the app open links to this site. delegate_permission/common.get_login_creds adds shared sign-in credentials.
target
The app the statement is about.
namespace
Always android_app for an Android app.
package_name
The applicationId of the app, for example com.example.app.
sha256_cert_fingerprints
SHA-256 fingerprints of the certificates that sign the app, as uppercase pairs separated by colons. List every key that signs builds people install.
relation_extensions
Optional, Android 15 and later. Its dynamic_app_link_components adds path rules in the style of Apple’s components. Older versions ignore it.

The legacy paths format

Before iOS 13, each entry had a single appID, a paths array with NOT in front of exclusions, and the file needed an empty apps array. iOS 13 and later read appIDs and components. The generator writes only the modern format. If you still support iOS 12, add the legacy keys to the same entry.

Legacy, iOS 12 and earlier
{
  "applinks": {
    "apps": [],
    "details": [{
      "appID": "ABCDE12345.com.example.app",
      "paths": ["NOT /help/website/*", "/buy/*"]
    }]
  }
}
Modern, iOS 13 and later
{
  "applinks": {
    "details": [{
      "appIDs": ["ABCDE12345.com.example.app"],
      "components": [
        {"/": "/help/website/*", "exclude": true},
        {"/": "/buy/*"}
      ]
    }]
  }
}

Common mistakes

Why a correct-looking file still fails

The JSON can be valid and links can still open the website. Check these seven before anything else.

  1. 01iOS

    Wrong Team ID prefix

    The file loads, but iOS never opens the app.

    Fix

    Use the Team ID of the account that signs the release, from Membership details. Not the numeric App Store ID, not a Key ID, and not an agency’s team when the app ships from yours.

    Complete Guide to Universal Links for iOS and Android
  2. 02Android

    Upload key instead of the Play App Signing key

    Your own builds open the app, installs from Google Play open the browser.

    Fix

    Google signs the apps it delivers with the app signing key. Copy that SHA-256 from Play Console, App integrity, and keep the upload key in the list only if you share builds signed with it.

    Android App Links Not Verified: A Five-Minute Diagnosis with adb
  3. 03iOS + Android

    The file sits behind a redirect

    The URL opens fine in a browser, yet verification fails.

    Fix

    Apple and Android expect a 200 at the exact URL. Exclude /.well-known/ from bare-to-www, www-to-bare and language redirects.

    Universal Links Open Safari? Fix AASA, App Links, Redirects, and Headers
  4. 04iOS + Android

    Wrong content type, or HTML instead of JSON

    The file is there, yet the platform ignores it.

    Fix

    Serve both files as application/json. Servers often send the extensionless AASA file as application/octet-stream, and some hosts answer with a login page or a bot check.

    Universal Links Open Safari? Fix AASA, App Links, Redirects, and Headers
  5. 05iOS + Android

    Forgetting the www host

    Links to example.com open the app, links to www.example.com open the website.

    Fix

    Each host is checked on its own. Upload the file to both, list both in Associated Domains and declare both in your Android intent filters.

    Complete Guide to Universal Links for iOS and Android
  6. 06iOS

    An exclusion below a catch-all rule

    Pages you meant to keep on the website open the app.

    Fix

    The first matching rule wins. Move exclude rules above /*, as the Appy example in the generator does.

  7. 07iOS

    A .json extension or the wrong folder

    Nothing is found at the address iOS requests.

    Fix

    The file is named apple-app-site-association, with no extension, and lives in /.well-known/. The download button above already uses that name.

Skip the hosting

Let Appy serve both files for you

On Enterprise, your app gets its own link domain, and Appy hosts apple-app-site-association and assetlinks.json on it, built from the Team ID, bundle ID, package name and fingerprints you register. Smart links themselves are free, and deep links come with Pro.

  • Free plan
  • No credit card
  • Unlimited clicks on every plan
  • Links keep working if you cancel

Frequently asked questions

What is an apple-app-site-association file?

A JSON file on your domain that tells iOS which apps may open which of your URLs as Universal Links. It lives at https://your-domain/.well-known/apple-app-site-association, has no file extension and lists app IDs (Team ID plus bundle ID) with the URL rules each one handles.

What is assetlinks.json?

The Android counterpart, based on Google’s Digital Asset Links. It sits at https://your-domain/.well-known/assetlinks.json and names the package and the signing certificate fingerprints of the app allowed to open your links. Android checks it when the app is installed and only then treats your links as verified App Links.

Where do I upload the generated files?

Into the /.well-known/ folder at the root of every host you use in links. Both files must load over HTTPS with a direct 200, no redirects and the application/json content type. Static hosts often need a header rule for the AASA file, because it has no extension.

Where do I find my Team ID and bundle ID?

The Team ID is in your Apple Developer account under Membership details. The bundle ID is on the General tab of your app target in Xcode. Together they form the app ID, such as ABCDE12345.com.example.app.

How do I get the SHA-256 fingerprint for assetlinks.json?

If Google Play signs your app, open Play Console, go to App integrity and copy the SHA-256 of the app signing key certificate. For keys you hold yourself, run keytool -list -v -keystore my-release-key.keystore or ./gradlew signingReport. The generator accepts the value with or without colons.

Should the AASA file use paths or components?

Use components. Apple introduced it with iOS 13, and it supports query items, fragments, exclusions and comments. The older paths array is only needed if you still support iOS 12 or earlier; in that case put both in the same entry.

Can one file cover several apps?

Yes. In the AASA file, list every app ID in appIDs, or add separate details entries when apps handle different paths. In assetlinks.json, add one statement per package to the array. The generator handles several iOS apps; for a second Android package, copy the statement and change the package name and fingerprints.

How long do changes take to reach devices?

Apple says its CDN requests your AASA file within 24 hours, and devices check for updates about once a week after installation. Android verifies when the app is installed; on a test device, adb shell pm verify-app-links --re-verify com.example.app runs the check again.

Do I need to sign the AASA file?

No. Signing it with your TLS certificate was only needed on iOS 8. From iOS 9 on, a plain JSON file served over HTTPS is what Apple expects.

Is anything I enter sent to Appy?

No. The files are generated by code running in your browser, and nothing you type is uploaded or stored. The validator works differently: it fetches the files from your domain when you run it.