FIDO Android App Origin
Description
A hash from an Android native app WebAuthn origin. Android native apps send origins of the form android:apk-key-hash:<hash>.
The hash has to be configured in at least the following places to tie together the involved app, IAM and Google API Servers:
- In this plugin.
- Under
https://<Relying Party ID>/.well-known/assetlinks.jsonin the fieldsha256_cert_fingerprintsas specified by the Android App Link documentation.
assetlinks.json.
May be used by
Properties
APK Key Hash (
apkKeyHash) Description
The URL-safe Base64 encoded SHA-256 hash. The hash can be obtained in a few different ways:
- Release keystore with e.g.
keytool -list -v -keystore app-release.keystore -alias my-signing-key. - A signed apk with
apksigner verify --print-certs app-release.apk - In Android Studio use the Gradle task
signingReport - In the Google Play Console: Go to your app > Setup > App integrity > App signing.
You can also use the IAM logs during integration to obtain the hash, which already is in the required format. If you do not have the correct hash configured in the IAM you will see the following DEBUG log message:
No match: android:apk-key-hash:<your_hash_here> != https://
Attributes
String
Mandatory
Example
pRE0AbGoJZmZmYnJ6dP3aI7Yd0Wf9x8bqLQvWn1tYIa
YAML Template (with default values)
type: FidoAndroidApkKeyHashOrigin
id: FidoAndroidApkKeyHashOrigin-xxxxxx
displayName:
comment:
properties:
apkKeyHash: