← Back to plugin index

FIDO Android App Origin

Description

A hash from an Android native app WebAuthn origin. Android native apps send origins of the form android:apk-key-hash:<hash>. The hash has to be configured in at least the following places to tie together the involved app, IAM and Google API Servers:

  • In this plugin.
  • Under https://<Relying Party ID>/.well-known/assetlinks.json in the field sha256_cert_fingerprints as specified by the Android App Link documentation.
There is no mechanism in IAM to host or automatically generate the assetlinks.json.
Type name
FidoAndroidApkKeyHashOrigin
Class
com.airlock.iam.factor.application.configuration.fido.FidoAndroidApkKeyHashOriginConfig
May be used by
License-Tags
FIDO
Properties
APK Key Hash (apkKeyHash)
Description
The URL-safe Base64 encoded SHA-256 hash. The hash can be obtained in a few different ways:
  • Release keystore with e.g. keytool -list -v -keystore app-release.keystore -alias my-signing-key.
  • A signed apk with apksigner verify --print-certs app-release.apk
  • In Android Studio use the Gradle task signingReport
  • In the Google Play Console: Go to your app > Setup > App integrity > App signing.
Usually it is a hex value that has to be converted to the URL-safe Base64 encoding.

You can also use the IAM logs during integration to obtain the hash, which already is in the required format. If you do not have the correct hash configured in the IAM you will see the following DEBUG log message:

No match: android:apk-key-hash:<your_hash_here> != https://

Consult your app developers or the Airlock documentation for more details on the android APK hash and Asset Link mechanism.
Attributes
String
Mandatory
Example
pRE0AbGoJZmZmYnJ6dP3aI7Yd0Wf9x8bqLQvWn1tYIa
YAML Template (with default values)

type: FidoAndroidApkKeyHashOrigin
id: FidoAndroidApkKeyHashOrigin-xxxxxx
displayName: 
comment: 
properties:
  apkKeyHash: