来源:Google Codelabs:Set Up Seamless Credential Sharing Across Websites and Android Apps,Google Developers Codelabs身份认证文档贡献者。中文翻译与技术注释:未完纪,2026-10-05。本文覆盖推荐的Play Console路线、手动双向DAL、验证、多网站密码和passkey关系;所有配置仅经静态阅读,未部署或测试。
一、概览:用关联证明同一服务
如果同一服务同时有网站和Android应用,要求用户分别登录会增加操作负担。Digital Asset Links(DAL)让网站和应用声明关联,使Google Password Manager等支持的密码管理器可以在它们之间使用已保存的密码与passkey;这不是让任意网页脚本读取另一个站点的密码库。
两类凭据所需关系不同:密码需要 delegate_permission/common.get_login_creds;网站与Android应用共享passkey还必须包含 delegate_permission/common.handle_all_urls,用来证明应用与passkey所属域名的关联。该关系也用于Android App Links深链,不能因已经配置密码关系就省略它。

原文引用eBay案例称采用DAL后登录成功率提高10%;这是原案例报告,不是对其他服务的性能保证。完成本教程需要JSON和Android开发基础,并熟悉Credential Manager前置条件。
网站必须能在准确域名的 https://{your-domain}/.well-known/assetlinks.json 托管JSON。Play Console路线需要已在Google Play发布的应用;手动路线需要可以修改和构建的Android工程,而且要让Google Password Manager共享凭据,应用仍必须发布到Google Play,本地未发布应用不满足这一条件。
关联是双向的:Web→App由网站文件声明信任的Android应用;App→Web则需要应用侧声明信任的网站。可用Play Console自动管理应用侧关联,也可手动配置。
二、推荐路线:Google Play Console
此路线由Google Play管理App→Web关系,无需修改应用manifest或重新发布应用版本。你需要访问Deep links页面的Play Console权限,以及发布域名关联文件的权限。
- 进入Play Console的 Grow → Deep links。
- 如果域名尚未列出,在App configuration下选择Add domain。
- 找到该域名的Credential sharing列,点击Turn on;新增域名时确认Enable credential sharing已开启。
- 复制Play Console生成的JSON片段。
- 把JSON发布到该域名的
/.well-known/assetlinks.json。已有文件时,在现有JSON数组中追加新声明,保留其他有效关联。 - 返回Play Console,选择Create website association或Turn on credential sharing,由控制台验证托管内容。

网址必须可通过HTTPS访问,响应类型为 Content-Type: application/json,不能重定向。验证后关联生效,但配置变化传播可能需要1–2周;不要仅凭上传成功就判断所有设备已经更新。
三、手动路线:网站文件与Android资源
无法使用Play Console或需要更多控制时,可以自行建立双向关系。手动方式仍不绕过Google Password Manager对应用已发布到Google Play的要求。
1. 取得应用身份
对每个Android应用,取得build.gradle中声明的application ID及签名证书SHA-256指纹;原文推荐通过Credential Manager API实现登录。应使用实际发布身份,区分Play App Signing、调试、发布及不同flavor;指纹是公开证书摘要,不是私钥。原文允许指纹数组包含多把签名密钥,但生产域名只应关联真实需要且仍受控制的身份。
2. 创建assetlinks.json
下面保留原文结构及公开示例指纹。需要密码和passkey时同时包含两项关系。包名、域名和指纹都必须替换为自己的正确值,不能原样部署。
网站→Android原示例
[{
"relation": [
"delegate_permission/common.handle_all_urls",
"delegate_permission/common.get_login_creds"
],
"target": {
"namespace": "android_app",
"package_name": "com.example.app",
"sha256_cert_fingerprints":
["14:6D:E9:83:C5:73:06:50:D8:EE:B9:95:2F:34:FC:64:16:A0:83:42:E6:1D:BE:A8:8A:04:96:B2:3F:CF:44:E5"]
}
}]
3. 托管关联文件
放到域名根目录下的 .well-known/assetlinks.json,再次检查HTTPS、application/json和无重定向。子域要按实际认证主机分别配置,检查CDN缓存及代理是否改写JSON。

4. 配置Android应用
在res/values/strings.xml加入asset_statements字符串,注意JSON引号要转义。然后在AndroidManifest.xml的application元素中增加meta-data引用该字符串资源。以下两个完整片段来自原文;其余应用设置要与真实工程合并,不能把示例包名或备份设置无条件覆盖到现有项目。
strings.xml原示例
<resources>
<string name="asset_statements" translatable="false">
[{
\"include\": \"https://www.example.com/.well-known/assetlinks.json\"
}]
</string>
</resources>
AndroidManifest.xml原示例
<manifest xmlns:android="http://schemas.android.com/apk/res/android"
package="com.example.app">
<application
android:allowBackup="true"
android:icon="@mipmap/ic_launcher"
android:label="@string/app_name"
android:theme="@style/AppTheme">
<meta-data
android:name="asset_statements"
android:resource="@string/asset_statements" />
<activity android:name=".MainActivity">
<intent-filter>
<action android:name="android.intent.action.MAIN" />
<category android:name="android.intent.category.LAUNCHER" />
</intent-filter>
</activity>
</application>
</manifest>
完成后发布新应用版本,支持DAL的密码管理器才能在www.example.com与com.example.app之间提供凭据建议;传播同样可能需要1–2周。该配置没有实现登录服务器,也不能代替应用鉴权、CSRF、防钓鱼、MFA或账号恢复。
四、验证设置
错误JSON或无法访问的文件可能静默导致关联失败。上线前使用官方Statement Generator and Validator:输入网站域名与应用包名,按界面要求填写签名指纹并选择要检查的关系,点击Test Statement;工具检查文件是否正确托管并包含有效关联。分别验证密码与passkey所需关系,不把一次检查当作完整登录流程测试。

还应在目标密码管理器和测试账号中检查网站/应用互相提示凭据的行为。关联文件不含秘密,但部署权限、域名控制和签名身份属于信任边界;不要加入未知第三方应用或已失去控制的域名。
五、多个网站:密码与passkey分别配置

如果example.com与example.co.uk使用同一个登录系统,可把它们声明为关联网站。密码使用web→web的get_login_creds关系;在example.com的assetlinks.json中加入下列声明,并在example.co.uk发布指向example.com的对等声明。
网站→网站密码关联
[{
"relation": ["delegate_permission/common.get_login_creds"],
"target": {
"namespace": "web",
"site": "https://example.co.uk"
}
}]
Chrome会自动在某些same-site网站之间共享已保存凭据,例如www.example.com与m.example.com。但网站与Android应用(含App WebView)的行为不同:必须在实际发生登录的子域的 /.well-known/assetlinks.json 提供有效DAL。
跨网站使用passkey
passkey绑定Relying Party ID(RP ID)域名。多个网站共享同一passkey时需要使用同一RP ID;跨站来源可以通过Related Origin Requests声明允许使用该RP ID的其他origin。这与网站→Android使用DAL中的handle_all_urls不同。
原例选择example.com作为规范RP ID:example.co.uk的WebAuthn API调用必须使用 rpId: 'example.com';example.com在 https://example.com/.well-known/webauthn 发布以下允许列表。这样example.co.uk可创建和使用关联到example.com的passkey。是否支持仍需按目标浏览器和平台验证,不能任意扩大来源。
RP域名的.webauthn文件
{
"origins": [
"https://example.co.uk"
]
}
关联具有传递性。原文明确指出,如果实体A与B(网站或应用)都与C关联,密码管理器会把A与B也视为可共享凭据的关联方。因此每新增一个关系都可能扩大共享组,应只纳入同一授权体系并定期检查退役身份。
结语与验证边界
完成且验证上述配置后,用户可在同一服务的网站和Android应用中使用支持的密码或passkey,减少重复登录。可以继续阅读原文链接的Digital Asset Links官方文档、Credential Sharing Fundamentals和eBay案例。这里没有声称已经为任何真实应用部署或验证;所有JSON/XML和WebAuthn参数只经静态审查,没有调用Play Console、修改账户、发布应用或传输凭据。
来源与许可
原页及本文翻译来源:Google Developers Codelabs,Set Up Seamless Credential Sharing Across Websites and Android Apps。除另有说明,页面文档内容为Creative Commons Attribution 4.0,代码样例为Apache License 2.0。本稿进行中文翻译、结构重排和明确标注的安全解释,原五幅图片和五个代码块未改;不表示Google对编辑注释背书。原图中商标权不变;Java是Oracle及/或其关联公司的注册商标。完整代码许可证如下。
Apache License 2.0 全文
Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
1. Definitions.
"License" shall mean the terms and conditions for use, reproduction,
and distribution as defined by Sections 1 through 9 of this document.
"Licensor" shall mean the copyright owner or entity authorized by
the copyright owner that is granting the License.
"Legal Entity" shall mean the union of the acting entity and all
other entities that control, are controlled by, or are under common
control with that entity. For the purposes of this definition,
"control" means (i) the power, direct or indirect, to cause the
direction or management of such entity, whether by contract or
otherwise, or (ii) ownership of fifty percent (50%) or more of the
outstanding shares, or (iii) beneficial ownership of such entity.
"You" (or "Your") shall mean an individual or Legal Entity
exercising permissions granted by this License.
"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation
source, and configuration files.
"Object" form shall mean any form resulting from mechanical
transformation or translation of a Source form, including but
not limited to compiled object code, generated documentation,
and conversions to other media types.
"Work" shall mean the work of authorship, whether in Source or
Object form, made available under the License, as indicated by a
copyright notice that is included in or attached to the work
(an example is provided in the Appendix below).
"Derivative Works" shall mean any work, whether in Source or Object
form, that is based on (or derived from) the Work and for which the
editorial revisions, annotations, elaborations, or other modifications
represent, as a whole, an original work of authorship. For the purposes
of this License, Derivative Works shall not include works that remain
separable from, or merely link (or bind by name) to the interfaces of,
the Work and Derivative Works thereof.
"Contribution" shall mean any work of authorship, including
the original version of the Work and any modifications or additions
to that Work or Derivative Works thereof, that is intentionally
submitted to Licensor for inclusion in the Work by the copyright owner
or by an individual or Legal Entity authorized to submit on behalf of
the copyright owner. For the purposes of this definition, "submitted"
means any form of electronic, verbal, or written communication sent
to the Licensor or its representatives, including but not limited to
communication on electronic mailing lists, source code control systems,
and issue tracking systems that are managed by, or on behalf of, the
Licensor for the purpose of discussing and improving the Work, but
excluding communication that is conspicuously marked or otherwise
designated in writing by the copyright owner as "Not a Contribution."
"Contributor" shall mean Licensor and any individual or Legal Entity
on behalf of whom a Contribution has been received by Licensor and
subsequently incorporated within the Work.
2. Grant of Copyright License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
copyright license to reproduce, prepare Derivative Works of,
publicly display, publicly perform, sublicense, and distribute the
Work and such Derivative Works in Source or Object form.
3. Grant of Patent License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
(except as stated in this section) patent license to make, have made,
use, offer to sell, sell, import, and otherwise transfer the Work,
where such license applies only to those patent claims licensable
by such Contributor that are necessarily infringed by their
Contribution(s) alone or by combination of their Contribution(s)
with the Work to which such Contribution(s) was submitted. If You
institute patent litigation against any entity (including a
cross-claim or counterclaim in a lawsuit) alleging that the Work
or a Contribution incorporated within the Work constitutes direct
or contributory patent infringement, then any patent licenses
granted to You under this License for that Work shall terminate
as of the date such litigation is filed.
4. Redistribution. You may reproduce and distribute copies of the
Work or Derivative Works thereof in any medium, with or without
modifications, and in Source or Object form, provided that You
meet the following conditions:
(a) You must give any other recipients of the Work or
Derivative Works a copy of this License; and
(b) You must cause any modified files to carry prominent notices
stating that You changed the files; and
(c) You must retain, in the Source form of any Derivative Works
that You distribute, all copyright, patent, trademark, and
attribution notices from the Source form of the Work,
excluding those notices that do not pertain to any part of
the Derivative Works; and
(d) If the Work includes a "NOTICE" text file as part of its
distribution, then any Derivative Works that You distribute must
include a readable copy of the attribution notices contained
within such NOTICE file, excluding those notices that do not
pertain to any part of the Derivative Works, in at least one
of the following places: within a NOTICE text file distributed
as part of the Derivative Works; within the Source form or
documentation, if provided along with the Derivative Works; or,
within a display generated by the Derivative Works, if and
wherever such third-party notices normally appear. The contents
of the NOTICE file are for informational purposes only and
do not modify the License. You may add Your own attribution
notices within Derivative Works that You distribute, alongside
or as an addendum to the NOTICE text from the Work, provided
that such additional attribution notices cannot be construed
as modifying the License.
You may add Your own copyright statement to Your modifications and
may provide additional or different license terms and conditions
for use, reproduction, or distribution of Your modifications, or
for any such Derivative Works as a whole, provided Your use,
reproduction, and distribution of the Work otherwise complies with
the conditions stated in this License.
5. Submission of Contributions. Unless You explicitly state otherwise,
any Contribution intentionally submitted for inclusion in the Work
by You to the Licensor shall be under the terms and conditions of
this License, without any additional terms or conditions.
Notwithstanding the above, nothing herein shall supersede or modify
the terms of any separate license agreement you may have executed
with Licensor regarding such Contributions.
6. Trademarks. This License does not grant permission to use the trade
names, trademarks, service marks, or product names of the Licensor,
except as required for reasonable and customary use in describing the
origin of the Work and reproducing the content of the NOTICE file.
7. Disclaimer of Warranty. Unless required by applicable law or
agreed to in writing, Licensor provides the Work (and each
Contributor provides its Contributions) on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
implied, including, without limitation, any warranties or conditions
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
PARTICULAR PURPOSE. You are solely responsible for determining the
appropriateness of using or redistributing the Work and assume any
risks associated with Your exercise of permissions under this License.
8. Limitation of Liability. In no event and under no legal theory,
whether in tort (including negligence), contract, or otherwise,
unless required by applicable law (such as deliberate and grossly
negligent acts) or agreed to in writing, shall any Contributor be
liable to You for damages, including any direct, indirect, special,
incidental, or consequential damages of any character arising as a
result of this License or out of the use or inability to use the
Work (including but not limited to damages for loss of goodwill,
work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses), even if such Contributor
has been advised of the possibility of such damages.
9. Accepting Warranty or Additional Liability. While redistributing
the Work or Derivative Works thereof, You may choose to offer,
and charge a fee for, acceptance of support, warranty, indemnity,
or other liability obligations and/or rights consistent with this
License. However, in accepting such obligations, You may act only
on Your own behalf and on Your sole responsibility, not on behalf
of any other Contributor, and only if You agree to indemnify,
defend, and hold each Contributor harmless for any liability
incurred by, or claims asserted against, such Contributor by reason
of your accepting any such warranty or additional liability.
END OF TERMS AND CONDITIONS
APPENDIX: How to apply the Apache License to your work.
To apply the Apache License to your work, attach the following
boilerplate notice, with the fields enclosed by brackets "[]"
replaced with your own identifying information. (Don't include
the brackets!) The text should be enclosed in the appropriate
comment syntax for the file format. We also recommend that a
file or class name and description of purpose be included on the
same "printed page" as the copyright notice for easier
identification within third-party archives.
Copyright [yyyy] [name of copyright owner]
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.












暂无评论内容