Passkeys集成遇Apple关联域名错误:应用与域名未关联
Passkeys 实现问题:应用与域名关联失败
错误提示:The operation couldn’t be completed. Application with identifier abc is not associated with domain xyz
我在实现Passkeys时,持续遇到apple-app-site-association相关问题,已完成以下排查:
- 设备开启开发者模式,启用Associated Domains开发选项
- 服务器端使用webauthn-swift框架
- 服务器与iOS App的RelyingPartyID均设置为ngrok域名
- Debug权限中已配置
webcredentials和appattest密钥为ngrok域名 - Public/.well-known/下的apple-app-site-association静态文件无重定向
- 通过中间件设置JSON响应头,代码如下:
final class AppleSiteAssociationMiddleware: Middleware { func respond(to request: Request, chainingTo next: Responder) -> EventLoopFuture<Response> { // Check if this is a request for the apple-app-site-association file if request.url.path == "\/.well-known\/apple-app-site-association" { let directory = DirectoryConfiguration.detect().publicDirectory let filePath = directory + "\/.well-known\/apple-app-site-association" if let data = FileManager.default.contents(atPath: filePath) { let response = Response(status: .ok, headers: ["Content-Type": "application\/json"], body: .init(data: data)) return request.eventLoop.makeSucceededFuture(response) } else { return request.eventLoop.makeFailedFuture(Abort(.notFound)) } } else { return next.respond(to: request) } } }
已确认可通过ngrok的HTTPS链接在Safari桌面浏览器中访问到apple-app-site-association文件,内容如下:
{ "applinks": { "details": [ { "appIDs": [ "TeamID:BundleID" ], "components": [] } ] }, "appattest": { "apps": [ "TeamID:BundleID" ] }, "webcredentials": { "apps": [ "TeamID:BundleID" ] } }
但在iOS App执行以下代码时抛出上述错误:
// iOS App // in view @Environment(\.authorizationController) private var authorizationController let challenge = try await registrationClient.establishChallenge(username: username) await accountStore.createPasskeyAccount(authorizationController: authorizationController, username: username, challenge: challenge) // in accountStore func createPasskeyAccount(authorizationController: AuthorizationController, username: String, challenge: Data, options: ASAuthorizationController.RequestOptions = []) async { do { let request = try await assertionRequest(type: .registration(username), challenge: challenge) let authorizationResult = try await authorizationController.performRequests([request], options: options) // 此处抛出错误
修复步骤
核对TeamID与BundleID
确保apple-app-site-association文件中的TeamID:BundleID与Xcode项目完全一致:- TeamID从Apple开发者后台会员中心获取
- BundleID需与Xcode「Signing & Capabilities」中的Bundle Identifier完全匹配,注意大小写和特殊字符
检查Associated Domains条目格式
在Xcode「Signing & Capabilities」中,确认添加的关联域名格式正确:webcredentials:your-ngrok-domain.comappattest:your-ngrok-domain.com
不要添加https://前缀或多余后缀
强制刷新关联缓存
iOS会缓存关联数据,可通过以下方式清除:- 卸载并重装App
- 进入「设置」>「Safari浏览器」>「清除历史记录与网站数据」
- 重启设备
检查服务器响应细节
- 确保apple-app-site-association文件没有被gzip压缩,Apple验证服务不处理压缩文件
- 避免设置
Cache-Control或Expires响应头,防止文件被缓存
验证RelyingPartyID
确认服务器与App中的RelyingPartyID是完整域名(如abc.ngrok.io),不包含协议、路径或端口,且与关联域名完全一致使用Apple官方工具验证
通过Apple开发者后台的「Associated Domains Validation Tool」输入域名,确认apple-app-site-association文件格式和内容被正确识别
内容的提问来源于stack exchange,提问作者bobby123uk
相关产品推荐
相关产品推荐

