You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Passkeys集成遇Apple关联域名错误:应用与域名未关联

Passkeys 实现问题:应用与域名关联失败

错误提示:The operation couldn’t be completed. Application with identifier abc is not associated with domain xyz

我在实现Passkeys时,持续遇到apple-app-site-association相关问题,已完成以下排查:

  • 设备开启开发者模式,启用Associated Domains开发选项
  • 服务器端使用webauthn-swift框架
  • 服务器与iOS App的RelyingPartyID均设置为ngrok域名
  • Debug权限中已配置webcredentials和appattest密钥为ngrok域名
  • Public/.well-known/下的apple-app-site-association静态文件无重定向
  • 通过中间件设置JSON响应头,代码如下:
final class AppleSiteAssociationMiddleware: Middleware {
    func respond(to request: Request, chainingTo next: Responder) -> EventLoopFuture<Response> {
        // Check if this is a request for the apple-app-site-association file
        if request.url.path == "\/.well-known\/apple-app-site-association" {
            let directory = DirectoryConfiguration.detect().publicDirectory
            let filePath = directory + "\/.well-known\/apple-app-site-association"
            
            if let data = FileManager.default.contents(atPath: filePath) {
                let response = Response(status: .ok, headers: ["Content-Type": "application\/json"], body: .init(data: data))
                return request.eventLoop.makeSucceededFuture(response)
            } else {
                return request.eventLoop.makeFailedFuture(Abort(.notFound))
            }
        } else {
            return next.respond(to: request)
        }
    }
}

已确认可通过ngrok的HTTPS链接在Safari桌面浏览器中访问到apple-app-site-association文件,内容如下:

{
  "applinks": {
    "details": [
      {
        "appIDs": [
          "TeamID:BundleID"
        ],
        "components": []
      }
    ]
  },
  "appattest": {
    "apps": [
      "TeamID:BundleID"
    ]
  },
  "webcredentials": {
    "apps": [
      "TeamID:BundleID"
    ]
  }
}

但在iOS App执行以下代码时抛出上述错误:

// iOS App

// in view
@Environment(\.authorizationController) private var authorizationController
let challenge = try await registrationClient.establishChallenge(username: username)
await accountStore.createPasskeyAccount(authorizationController: authorizationController, username: username, challenge: challenge)

// in accountStore
func createPasskeyAccount(authorizationController: AuthorizationController, username: String, challenge: Data, options: ASAuthorizationController.RequestOptions = []) async {
        do {
            let request = try await assertionRequest(type: .registration(username), challenge: challenge)
            let authorizationResult = try await authorizationController.performRequests([request], options: options) // 此处抛出错误

修复步骤

  1. 核对TeamID与BundleID
    确保apple-app-site-association文件中的TeamID:BundleID与Xcode项目完全一致:

    • TeamID从Apple开发者后台会员中心获取
    • BundleID需与Xcode「Signing & Capabilities」中的Bundle Identifier完全匹配,注意大小写和特殊字符
  2. 检查Associated Domains条目格式
    在Xcode「Signing & Capabilities」中,确认添加的关联域名格式正确:

    • webcredentials:your-ngrok-domain.com
    • appattest:your-ngrok-domain.com
      不要添加https://前缀或多余后缀
  3. 强制刷新关联缓存
    iOS会缓存关联数据,可通过以下方式清除:

    • 卸载并重装App
    • 进入「设置」>「Safari浏览器」>「清除历史记录与网站数据」
    • 重启设备
  4. 检查服务器响应细节

    • 确保apple-app-site-association文件没有被gzip压缩,Apple验证服务不处理压缩文件
    • 避免设置Cache-Control或Expires响应头,防止文件被缓存
  5. 验证RelyingPartyID
    确认服务器与App中的RelyingPartyID是完整域名(如abc.ngrok.io),不包含协议、路径或端口,且与关联域名完全一致

  6. 使用Apple官方工具验证
    通过Apple开发者后台的「Associated Domains Validation Tool」输入域名,确认apple-app-site-association文件格式和内容被正确识别

内容的提问来源于stack exchange,提问作者bobby123uk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 16:25:29