Only perform the steps in this section if you implemented native Android apps that use FIDO2.
You must declare associations between your website and your native Android apps in a file called assetlinks.json. Refer to Google’s documentation about setting up interoperability with your website.
The steps are summarized below with some helpful notes and additional steps that have helped past Digipass S3 customers. See https://evaluation95.noknoktest.com/.well-known/assetlinks.json for an example.
Step 1. Create a directory named .well-known under the website root.
Step 2. Add a JSON file called assetlinks.json to the .well-known directory with the mobile application configurations. To ensure that you’ve correctly set this up, verify the points below:
Make sure the file is accessible from a public network, meaning that the file should be crawlable from Google. In other words, Google servers must be able to access your website. See Google documentation for more info.
The file should be accessible without any 301 or 302 redirects.
The Google documentation states that you host assetlinks.json at your domain. This domain must be identical to . To understand the rationale behind this, read How Facet IDs and RP ID Are Used. The table below shows the valid and invalid assetlinks.json URLs for domain mywebsite.com.
Assetlinks.json URL
Reason
https://mywebsite.com/.well-known/assetlinks.json
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A16%3A24Z&se=2026-09-30T02%3A28%3A24Z&sr=c&sp=r&sig=pwIynZ3FjEw%2BPtpcL2iQYgfcvD%2F8h6X5mTZLy7519NA%3D)
Domain = RP ID
https://other.mywebsite.com/.well-known/assetlinks.json
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A16%3A24Z&se=2026-09-30T02%3A28%3A24Z&sr=c&sp=r&sig=pwIynZ3FjEw%2BPtpcL2iQYgfcvD%2F8h6X5mTZLy7519NA%3D)
Has subdomain (other)
https://mywebsite.com/apps/.well-known/assetlinks.json
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A16%3A24Z&se=2026-09-30T02%3A28%3A24Z&sr=c&sp=r&sig=pwIynZ3FjEw%2BPtpcL2iQYgfcvD%2F8h6X5mTZLy7519NA%3D)
Has path (/apps)
You can find your RP ID by viewing the RP ID property in the Server Admin Console, Configuration > Authentication Methods > FIDO2/WebAuthn.
Step 3. Add configuration details in the assetlinks.json file. For example, to set up the Tutorial App mobile browser integration, add the entry below:
[{
"relation": ["delegate_permission/common.handle_all_urls"],
"target": {
"namespace": "android_app",
"package_name": "com.noknok.android.tutorialappplus",
"sha256_cert_fingerprints": ["F1:C0:35:0C:F3:54:42:60:21:4B:56:6B:B6:6A:39:18:62:58:01:24:62:61:41:FA:BE:9F:CE:3C:1A:68:28:88"]
}
}]When customizing your own app, replace the values for "package_name" ("com.noknok.android.tutorialappplus") with your own package name and "sha256_cert_fingerprints" with the SHA256 fingerprints of your app signing certificates. FIDO2 requires SHA-256 while UAF needs SHA-1. You can provide more than one fingerprint, for example, one fingerprint each for debug and production builds.
Use the Java keytool command to generate your app's SHA256 fingerprint:
$ keytool -list -v -keystore my-release-key.keystoreStep 4. To ensure that assetlinks.json is served with HTTP header Content_Type: application/json, create a directory named WEB-INF under the .well-known directory. Next, create a file named web.xml containing the content below:
<?xml version="1.0" encoding="UTF-8"?>
<web-app xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://java.sun.com/xml/ns/javaee" xmlns:web="http://java.sun.com/xml/ns/javaee" xsi:schemaLocation="http://java.sun.com/xml/ns/javaee http://java.sun.com/xml/ns/javaee/web-app_2_5.xsd" id="WebApp_ID" version="2.5">
<display-name>.wellknown</display-name>
<mime-mapping>
<extension>json</extension>
<mime-type>application/json</mime-type>
</mime-mapping>
</web-app>Step 5. assetlinks.json needs to be accessible using HTTPs and port 443. You may need to add a connector to your server.xml file in <tomcat_home>/conf as follows. Be sure to replace the values for certificateKeystoreFile and certificateKeystorePassword.
<Connector port="443" protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150" SSLEnabled="true">
<SSLHostConfig certificateVerification="none">
<Certificate
certificateKeystoreFile="/usr/share/tomcat/cert/server.pkcs12"
certificateKeystorePassword="<password>"
certificateKeystoreType="PKCS12"
sslProtocols="TLS"
type="RSA"
/>
</SSLHostConfig>
</Connector>