Skip to tool
Mobile

App Link Association Studio

Build and simulate Apple AASA and Android assetlinks routing rules.

Web Worker Local onlyTools
Input0 characters
Result0 characters
Ready

Association studio · identity before routing

A valid file is only one side of the trust handshake.

The website, signed app, system verifier, and URL policy must agree. This studio builds the local evidence and simulates ordered Apple rules without pretending it can certify your production host or device cache.

Two-sided trust handshake

iOS APP

TEAM ID + BUNDLE ID

associated-domains entitlement

WEBSITE

HTTPS ORIGIN

AASA or assetlinks at exact path

ANDROID APP

PACKAGE + SHA-256

manifest intent filter + installed signer

Identity rails

Apple app IDABCDE12345.com.example.app

Team ID prefixes bundle ID

Android targetcom.example.app

application ID

Release signerAA:BB:…:32 BYTES

installed certificate fingerprint

Play App SigningPLAY CERTIFICATE

often differs from local upload key

Ordered route court

ORDERCOMPONENTRULINGEVIDENCE
01/private/*EXCLUDEfirst match stops
02/products/*INCLUDEpath evidence
03/search/* + queryINCLUDEpath and query
04/help/* + fragmentEXCLUDEfragment evidence
05*INCLUDEfallback

Platform divergence map

CONTRACTAPPLEANDROID
Website identityAASA appIDsDigital Asset Links target
URL scopecomponents path/query/fragmentmanifest intent filters
Website dynamic rulesAASA componentsAndroid 15+ dynamic components
Signing evidenceTeam ID + bundle IDSHA-256 certificate
Local simulationordered first-match policyidentity statement only without manifest

Production hosting runway

01 · Apple/.well-known/apple-app-site-associationHTTPS · no extension · JSON MIME · no redirect
02 · Android/.well-known/assetlinks.jsonHTTPS · application/json · no redirect
03 · Every hostseparate origin evidencesubdomain and apex verify independently
04 · CachesApple CDN / device verifierdeployment is not immediate local state
05 · Legacy Apple boundary128 KB uncompressedkeep rules concise

Failure ladder

01
FETCH

file unreachable or redirected

02
PARSE

wrong MIME or malformed JSON

03
IDENTITY

app ID/package/signer mismatch

04
APP CONFIG

entitlement or manifest missing

05
ROUTE

ordered rule does not match

06
DEVICE

install/cache/browser behavior

Security perimeter

Routed parameters remain untrusted input.

Association proves control relationships, not authorization. Validate and normalize the URL, require authentication, check resource ownership, confirm destructive actions, and preserve a safe web fallback.

Direct answer

Generate Apple AASA and Android assetlinks.json statements, inspect app identity, simulate ordered AASA route rules, and follow a production verification checklist.

What can it do?

  • Apple AASA
  • Android assetlinks
  • Simulate

How to use App Link Association Studio

  1. 01

    Choose a task

    Select Apple AASA, Android assetlinks, and Simulate in the workspace.

  2. 02

    Provide the input

    Paste association JSON or enter app identifiers. The input stays in the browser processing path.

  3. 03

    Review the result

    Run the tool, inspect its result and diagnostics, then copy or download the output when the page offers that action.

Frequently asked questions

What is App Link Association Studio?
Generate Apple AASA and Android assetlinks.json statements, inspect app identity, simulate ordered AASA route rules, and follow a production verification checklist.
What can App Link Association Studio do?
App Link Association Studio supports Apple AASA, Android assetlinks, and Simulate. Each mode is available directly in the page workspace.
Does App Link Association Studio upload my data?
App Link Association Studio processes your input locally in the browser. DevSexy does not add an upload, account, or server-processing step to this workflow.
DevSexy processes tool input locally. No paste tracking, accounts, or upload step.