Mobile Starter Kit

Deep links and universal links

Replace example URLs with verified, allow-listed routing for your final app.

The starter supports a custom scheme for development/auth and verified HTTPS links for store-facing routes. Deep links can arrive from a browser, QR, auth callback, or push notification; all of them should enter the same route allow-list.

Prompt

Read agent-skills/add-deep-linking.md. Replace the example scheme, bundle/package
IDs, link domain, and legal origin with my final values. Generate and deploy the
Apple association file and Android assetlinks file from the exact signing IDs.
Keep auth callbacks separate and validate every route parameter.

Public verification files

The legal-site build generates:

/.well-known/apple-app-site-association
/.well-known/assetlinks.json

Serve both over public HTTPS with the correct content type, no redirect, and the exact Apple team/bundle and Android package/signing values from the build you will ship.

Decide edge cases

Define what happens when the user is signed out, content was deleted, a feature is premium-only, or an ID is invalid. Never route an external string directly to privileged behavior. Preserve a pending destination through auth only when safe.

Test cold, background, and foreground opens from browser and Notes/messages, plus auth callbacks and push taps, on signed physical-device builds.

On this page