Use the Admin Console to configure your Android App. The Admin Console also updates the trusted facets list at the same time.
Step 1. Login to the Admin Console and, if needed, switch to the desired tenant. Navigate to Configuration > Apps.
The Apps page appears. Find your app in the list and either click its name or the Edit icon at the end of its row. If your app is not in the list yet, click the blue Add App button, select the Android radio button and click Add.

The App page appears.

Step 2. Enter the app’s package name in Package Name/URL. This name cannot be changed later. Also enter the App Name which is used for display purposes here in the Admin Console.
Step 3. If you want your app to use the UAF protocol, make sure that you have already completed UAF configuration on the Server. Then you need to generate the UAF facet ID which is a URI derived from the Base64 encoding SHA-1 hash of the APK signing certificate, of the form android:apk-key-hash:<hash-of-apk-signing-cert>.
Use the keytool utility on either Linux or OSX to hash the fingerprint from your APK signing certificate. If the new app uses the same key as an existing Android app that you’ve implemented, then you can reuse the facet ID. Refer to Google's Sign your app documentation.
Locate your debug keystore file, which is named debug.keystore. This was created the first time you built your project. The default location is the same directory as your Android Virtual Device (AVD) files in ~/.android/.
Convert the SHA-1 to a facet ID using this command:
./keytool -exportcert -alias <alias name entry in your cert> \
-keystore \
<path-to-apk-signing-keystore> | openssl sha1 \
-binary| openssl base64 | sed 's/=//g’Toggle on FIDO UAF and enter the resulting FIDO UAF Facet ID into the App page in the Admin Console.
If your implementation uses a remote, standalone UAF FIDO client, then update facets.uaf.
The facet ID depends on the app signing key. To avoid adding multiple facet IDs during your development process, your developers can share the same signing key. This is accomplished by sharing the same keystore on each machine.
Step 4. If you want your app to use the FIDO2 protocol, make sure that you have already completed FIDO2 Configuration on the Server. Next, generate the FIDO2 facet ID. Use the keytool utility on either Linux or OSX to hash the fingerprint from your APK signing certificate. If the new app uses the same key as an existing Android app that you’ve implemented, then you can reuse the facet ID. Refer to Google's Sign your app documentation.
Locate your debug keystore file, which is named debug.keystore. This was created the first time you built your project. The default location is the same directory as your Android Virtual Device (AVD) files in ~/.android/.
Convert the SHA-256 to a facet ID using the command below:
./keytool -exportcert -alias androiddebugkey \
-keystore ./default.keystore | openssl sha256 -binary| \
openssl base64 | sed 's/=//g' | tr '+/' '-_’The facet ID depends on the app signing key. To avoid adding multiple facet IDs during your development process, your developers can share the same signing key. This is accomplished by sharing the same keystore on each machine.
Toggle on FIDO2/WebAuthn and enter the resulting FIDO2 Facet ID into the App page in the Admin Console.
Make sure that your app is represented in your digital asset links file assetlinks.json. See Creating Your Digital Asset Links File for more information.
Step 5. You can assign a default Adaptive Ruleset that this app uses. Select the ruleset's name from the Adaptive Ruleset dropdown. For more information, see Configure Adaptive Rulesets.
Step 6. If your app uses Google Play Integrity, you can set this up now. Refer to Support app integrity.
Step 7. If your app uses OOB authentication, you can set this up now. Refer to Configuring Out-of-band Authentication.
Step 8. If the package name changed, enter the previous package name into Old Package Names. If the package name changed multiple times, enter all previous package names separated by commas.
The Auth Server uses the package name to uniquely identify an app. The server uses Old Package Names to consolidate what would otherwise be duplicate information for the app.
Step 9. Save your changes. Verify that the facet ID was added correctly to the server database by performing a client registration operation using the protocols that you configured. If the application facet ID was not correctly added to the database, user registration fails with error 4402.