Please exclude /.well-known/assetlinks.json from anti-bot security challenge

Website URL

https://madurgacscacademy.org.in/

Error Message

Hello Support,

I am using Android Trusted Web Activity (TWA) for my website:

https://madurgacscacademy.org.in/

I have correctly uploaded the Android Digital Asset Links file:

https://madurgacscacademy.org.in/.well-known/assetlinks.json

However, the server is not returning the actual JSON file to non-browser clients.

When I request the URL using PowerShell, the server returns:

HTTP 200 OK
Content-Type: text/html

and the response contains an HTML JavaScript security challenge loading:

/aes.js

Because of this, Google Chrome’s Digital Asset Links verifier receives HTML instead of JSON and reports:

“Digital Asset Links response parsing failed
expected value at line 1 column 1”

This prevents Android Trusted Web Activity from being verified, so the Android app falls back to Chrome Custom Tab and shows the browser address bar.

Please configure the hosting/server security layer to exclude this exact path from the anti-bot/security challenge:

/.well-known/assetlinks.json

The URL must return the actual file directly with:

HTTP 200
Content-Type: application/json

and without any HTML, JavaScript challenge, redirect, or /aes.js injection.

This file is required for Android Digital Asset Links / Trusted Web Activity verification.

Please confirm once this exclusion has been applied.

Thank you.

Other Information

Please confirm once this exclusion has been applied.

Beep boop, I’m a bot! I dug through the forum to get you started. I sometimes get things wrong though, so do with this what you will until a human has a look.

I couldn’t find anything on the forum or in the knowledge base that says this challenge can be switched off for a single path, so I can’t confirm that an exclusion for /.well-known/assetlinks.json is possible. I can’t apply one either. A person on our staff needs to look at this request.

The closest match I found is an old topic where a JSON endpoint returned the same HTML page loading /aes.js to an Android app. It looks like the same behaviour you’re seeing, but that topic has no answer, so it doesn’t tell you how to get around it.

Your topic: i cannot retrieve json string

The hosting offered here is a commodity service. This means everyone gets the same service. As such, any changes to the security system would affect everyone.

I can’t talk for admin, but when people have made similar requests previously the answer has always been no.

Please understand that we provide hosting for websites, not mobile apps. Only accessing websites through a web browser is supported.

Building a separate app and using the hosting for APIs does not work at all. Some people have had some success with PWAs, but it’s not officially supported, and I’m personally not quite sure why it even works.

In that context, specifically adding support for Trusted Web Activity doesn’t really make sense. And understand that any exception we make means poking a hole in our security systems that can be abused, so just making that change because a single developer needs it for their unsupported project isn’t something we can just do.

And I’ve never heard about this Trusted Web Activity thing before until now, so I don’t think that not making that exception affects many people.

So I’m sorry, but the answer is no. You’ll have to make do without the Trusted Web Activity and accept that there will be a browser frame around your content, or you can upgrade to premium hosting where this security system is not present.