Skip to content

Installation · Concept

Trusted Web Activity (TWA): PWAs in the Play Store

Published

Widely available since 2019-01Vendor

In one line: A Trusted Web Activity (TWA) is a full-screen Chrome Custom Tab that passes a cryptographic origin verification check (Digital Asset Links), letting you ship a PWA through the Google Play Store as a real Android app without an address bar.

A TWA is an Android activity (com.google.androidbrowserhelper.trusted.TwaLauncher) that opens a URL in a full-screen Chrome Custom Tab. The critical difference from an ordinary Custom Tab or WebView is Digital Asset Links (DAL) verification:

  1. Your website hosts a JSON file at /.well-known/assetlinks.json that declares the SHA-256 fingerprint of your Android signing certificate.
  2. Chrome verifies the fingerprint at launch. If it matches, Chrome shows the content with no address bar — the user sees a native-feeling app.
  3. If verification fails, Chrome falls back to a normal Custom Tab with an address bar, which is the safe, graceful degradation path.

This is fundamentally different from a WebAPK: a WebAPK is generated by Chrome at install time from the device without Play Store involvement; a TWA is an Android app you build, sign, and submit to the Play Store.

TWA WebAPK (Chrome install)
Distribution channel Google Play Store Chrome browser install prompt
Requires Android app project Yes (Kotlin/Java or Bubblewrap) No
Digital Asset Links required Yes No
Address bar when verification fails Shows address bar (graceful fallback) N/A
Play billing / Play integrity Accessible via postMessage bridge Not accessible
Update mechanism Play Store APK update Manifest re-mint (~24 h)
Suitable for Play Store presence, monetization, enterprise MDM Quick “add to home screen” install
[{
"relation": ["delegate_permission/common.handle_all_urls"],
"target": {
"namespace": "android_app",
"package_name": "com.example.myapp",
"sha256_cert_fingerprints": [
"AB:CD:EF:..."
]
}
}]

Host this at https://yourdomain.com/.well-known/assetlinks.json with a Content-Type: application/json header. The file must be reachable without redirects; otherwise verification silently fails and the address bar appears.

The recommended path is Bubblewrap CLI (@bubblewrap/cli), an open-source tool from Google that generates an Android Studio project pre-configured for TWA:

Terminal window
npm i -g @bubblewrap/cli
bubblewrap init --manifest https://yourdomain.com/manifest.json
bubblewrap build

Bubblewrap reads your web app manifest and generates the Android project. You supply the signing key; Bubblewrap produces a signed APK and AAB ready for Play Store submission.

TWAs are reviewed against Play’s standard policies. Your PWA’s web content is accessible via URL, so Play may apply additional scrutiny. Common requirements: a real privacy policy URL, working offline capability, and content that does not violate Play policies.

  • Chrome fetches assetlinks.json at TWA launch (with a short network timeout).
  • The fingerprint is compared to the APK’s signing certificate.
  • Verification results are cached for up to 5 minutes; a bad cache entry can delay the fix on a re-deploy.
  • You can test verification with Android’s Asset Links API tool or with:
    adb shell am start -a android.intent.action.VIEW \
    -d https://yourdomain.com com.example.myapp

TWA is an Android-only technology. On iOS, Chrome for iOS exists but does not support TWA. PWA distribution on iOS goes through Safari’s “Add to Home Screen” mechanism; there is no equivalent App Store path using web standards alone (a native iOS wrapper using WKWebView is a separate approach outside the PWA/TWA model).

TWA is Android-only. ChromeOS supports TWA as well (since ChromeOS is Android-based), allowing Play Store PWA apps to run on Chromebooks. Desktop Windows, macOS, and Linux do not have a TWA equivalent; the analogous desktop path is a direct Chrome install that uses a WebAPK-style isolated window.

TWAs can access Google Play billing through the Digital Goods API, a Chrome-specific extension that exposes Play’s payment infrastructure to web content running inside a verified TWA. This is not available to ordinary browser PWAs.

Store policies and distribution terms are covered in Distribution.

  • assetlinks.json hosted at /.well-known/assetlinks.json, no redirect, correct content-type.
  • SHA-256 fingerprint of release signing certificate in the file (not debug).
  • Bubblewrap (or equivalent) used to generate the Android project.
  • build.gradle applicationId matches package_name in assetlinks.json.
  • TWA verified with adb or Asset Links checker before Play submission.
  • Privacy policy URL live and linked in the Play listing.
  • Graceful address-bar fallback tested (temporarily break the fingerprint to confirm Chrome degrades cleanly).

Specifications

SpecificationStatus
Trusted Web Activity availabilityVendor
  • Legend
  • Yes
  • Partial
  • Flag
  • No
  • Unknown
Browser / PlatformSupportVersionsConfidenceSourceNotes
Chrome (Android)Yes72mediumsource123
  1. Per Chrome's documentation, Trusted Web Activity is available in Chrome on Android from version 72.
  2. No cross-browser compatibility dataset (BCD/caniuse) covers TWA; version verified from Chrome's own documentation.
  3. The same documentation notes other browsers may implement the same protocol, but does not itself document TWA support in any other browser.

Source data: /compatibility/twa.json · Global usage: 64 % (StatCounter 2026-05)

Source: spec · Last verified 2026-09-09 · Confidence: medium (computed from sources)