Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If your Apple App Site Association (AASA) endpoint returns HTTP 301 on AWS Amplify, the request is being redirected instead of serving the file. Apple does not support redirects for hosting the AASA file. Inspect Amplify’s ordered redirect and rewrite rules, serve the file directly at every hostname in the app’s Associated Domains entitlement, and verify the response before testing Universal Links again.

Check the exact AASA URL and response

Start with the hostname configured in the app’s Associated Domains entitlement. Request its AASA endpoint directly, normally https://<host>/.well-known/apple-app-site-association. A browser may follow a redirect and display a final page without making the original 301 obvious, so inspect the HTTP response and headers with curl -v, as Apple recommends in its TN3155 debugging guidance.

Apple’s rule is clear: redirects are not supported when hosting the AASA file. A 301 or 302 at the endpoint is therefore a hosting or routing issue to fix, not an acceptable way to point Apple to a file at another URL.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • 301 or 302: The endpoint is redirecting. Find and remove or change the matching Amplify rule so the requested URL serves the file directly.
  • 403: Check public access and whether user-agent filtering blocks Apple’s fetch. Apple suggests testing with an arbitrary user agent if access is denied.
  • 404: Check that the file is deployed at the requested path and reachable without authentication.
  • Successful response: Inspect the body as well as the status. It must contain valid AASA JSON for the intended app and URL rules.

Apple’s TN3155 describes supported current and legacy AASA structures. Compare your response body with the structure you intend to use rather than treating a successful status alone as proof that the association is correct.

Find the Amplify rule matching the AASA request

In the AWS Amplify Hosting console, open the app’s redirect and rewrite rules and inspect them in their listed order. Amplify processes rules from top to bottom, so an earlier broad rule can catch the AASA path before a later, more specific exception. AWS documents rule order and the available redirect, rewrite, and not-found behaviors in its Amplify redirects and rewrites guide.

  1. Look for a rule that explicitly matches /.well-known/apple-app-site-association or the AASA path you are requesting.
  2. Check host-normalization rules, such as apex-to-www redirects, that may apply to the request before it reaches the file.
  3. Review broad wildcard or single-page-app catch-all rules. Confirm whether their pattern matches the AASA request and whether an earlier rule takes precedence.
  4. Adjust the deployed rules so the associated hostname serves the AASA file at the requested endpoint. Then request the endpoint again and inspect the response.

AWS distinguishes a permanent 301 or temporary 302 redirect, which sends the request to a different destination, from a 200 rewrite, which serves destination content under the original address. That distinction helps explain the behavior of a rule, but a rewrite should not be assumed to solve AASA hosting by itself: verify that the requested endpoint directly returns the intended file and is not redirected.

AWS provides examples of specific path rules and wildcard matches in its redirect and rewrite examples. Use your live rule list and deployed configuration to identify the match; a generic SPA rule may not be appropriate for every app.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Serve the file on every associated hostname

The AASA URL’s hostname must match a hostname listed in the app’s Associated Domains entitlement. Apple says each specific subdomain needs its own matching AASA URL. An AASA file served at the apex domain does not automatically cover www or another named subdomain.

For example, if the entitlement includes applinks:example.com and applinks:www.example.com, check the AASA endpoint separately on both hosts. Each must serve the file directly; do not rely on an apex-to-www redirect for association. Apple explains the hostname requirements in its Universal Links debugging note and Associated Domains documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Verify the app configuration after fixing the response

Once the endpoint serves valid JSON directly, check that the server-side association and the app agree. Apple’s Associated Domains documentation and TN3155 provide the relevant configuration guidance.

  • Confirm the exact tested hostname appears in the app’s Associated Domains entitlement.
  • Confirm the AASA content identifies the intended application, including the app identifier expected by that configuration.
  • Check that the AASA rules include the URL paths or components you are testing.
  • Re-test with a URL that matches those rules after confirming the endpoint’s status, headers, and body.

If the AASA response is correct but a link still opens in Safari, the redirect is no longer the only configuration to investigate: check the hostname, app identifier, and path rules together. The exact Amplify rule responsible for a particular 301 depends on that deployment’s URL, response headers, and rule configuration; the checks above isolate it without assuming a specific cause.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.