Distribution
Published
A PWA reaches a device through one of four channels: the browser’s own install flow, a Trusted Web Activity listed on Google Play, a packaged listing on the Microsoft Store, or a URL onboarded into the Galaxy Store. The code is the same in all four; what differs is who reviews it, who controls the install UI, and how an update reaches the user.
How it works
Section titled “How it works”Each channel adds one artefact in front of the same origin. The browser channel adds nothing; the store channels add a package whose only job is to prove that the package publisher owns the origin.
Browser install
Section titled “Browser install”Chromium browsers on Android, Windows, macOS, ChromeOS, and Linux offer an install entry once
the installability criteria are met: a manifest with icons, a
start_url in scope, a secure origin, and a registered service worker. On Android, Chrome mints
a WebAPK so the app appears in the launcher and app settings
like a native app. Safari on iOS and iPadOS installs through
Add to Home Screen from the Share menu, with
no prompt event. There is no review and no catalogue; every update is a normal deploy to your
server.
Trusted Web Activity on Google Play
Section titled “Trusted Web Activity on Google Play”A Trusted Web Activity is an Android app whose activity opens
your origin in Chrome 72 or later, full screen, sharing the browser’s cookies, storage, and
service worker. Trust comes from Digital Asset Links: the site publishes
https://example.com/.well-known/assetlinks.json with a statement whose relation is
delegate_permission/common.handle_all_urls and whose target names the package_name and
sha256_cert_fingerprints of the signing certificate. Google states that a statement list “in
any other location, or with any other name” is not valid.
Bubblewrap generates the project:
bubblewrap init --manifest <url> reads your web manifest, bubblewrap build produces
app-release-signed.apk and app-release-bundle.aab, and bubblewrap fingerprint generateAssetLinks writes the assetlinks.json to upload. It requires Node.js 14.15 or later
and JDK 17; the CLI offers to download the JDK and Android command-line tools on first run.
PWABuilder is a web front end over the same core.
If verification fails, Chrome’s quick-start guide states: “the browser falls back to displaying
your website as a Custom Tab”, with browser UI at the top of the page. The usual cause is a
fingerprint mismatch: Bubblewrap signs with the key created during init, while Google Play may
sign the upload with a different key depending on your signing setup, and that key’s
fingerprint must also appear in the file.
The cost of this channel is a one-time Play listing, a signing key you must keep, and the
Payments policy described under Store policy.
Packaged listing on the Microsoft Store
Section titled “Packaged listing on the Microsoft Store”The Microsoft Store takes a PWA as a Windows package without a native shell. PWABuilder turns
the URL into an .msixbundle and a .classic.appxbundle; Partner Center takes both files on the
Packages step of a submission. Code updates ship from your web server with no new package;
a manifest change (icon, name, file_handlers, protocol_handlers, share_target) requires a
new package because the manifest is copied into it. A Store-installed PWA has a hard-coded
start_url, so a redirect to a locale domain is treated as out of scope and Edge shows the URL
and page title at the top of the window; Microsoft documents no way to suppress that bar for
Store installs.
Galaxy Store by URL
Section titled “Galaxy Store by URL”Samsung’s announcement of 2019-10-24 asks developers to “send us the URL to pwasupport@samsung.com”; Samsung then handles onboarding and licensing for the icon, and the listing opens the PWA in Samsung Internet. Listings were “only visible in the US Galaxy Store” at launch, and no self-service submission path was documented in 2026-10.
| Channel | Review | Who draws the install UI | How an update reaches the user |
|---|---|---|---|
| Browser install | None | The browser | Next navigation; service worker update cycle |
| Trusted Web Activity | Google Play policy review | Google Play | Web code: next launch; TWA shell: Play update |
| Microsoft Store package | Microsoft Store certification (stated 24 to 48 hours) | The Store | Web code: next launch; manifest: new package |
| Galaxy Store URL | Manual onboarding by Samsung | The Store | Next launch |
Observed behaviour
Section titled “Observed behaviour”The same page states when a changed assetlinks.json is picked up: Android 15 and later
re-verify in the background and “changes can take up to seven days to propagate”, while
Android 14 and lower re-read the file only when the app is installed or updated. A fingerprint
rotation therefore needs both fingerprints in the file during the transition.
See also
Section titled “See also”- Trusted Web Activities (developer.chrome.com)
- Verify Android App Links (developer.android.com)
- Publish a PWA to the Microsoft Store (learn.microsoft.com)
- Store policy
- Trusted Web Activity
- WebAPK
- Install prompt compatibility
← Back to the Ecosystem overview.