Deep-link signing and callback corrections¶
Three statements in the integration reference did not match the shipped apps. If you built deep-link signing from the docs on or after 2026-08-18, re-read Signing — the HTTPS example signed the wrong bytes.
Corrected behaviour¶
app_sigcovers the canonicalyanezbio://sign?<query>bytes, not the HTTPS URL. YanezYID rewriteshttps://<host>/open?<query>toyanezbio://sign?<query>before verifying. Sign the canonical form, then deliver the identical query on{DEEP_LINK_BASE}. A signature over the HTTPS URL is rejected with "Untrusted signing request". See Signing.- There is no callback-domain allowlist.
method=postdelivers to whatever URL the signed link carries, on both platforms. The 2026-07-07 entry that said Android drops non-allowlisted hosts was wrong. Return2xxfrom your callback; see Delivery Modes. - iOS test builds register only their suffixed scheme (
yanezbio-dev://,yanezbio-partner://); every Android flavor acceptsyanezbio://. The 2026-07-07 entry had this backwards. See Custom Scheme (Deprecated).
Clarified¶
methodmust be present: an omitted value is rejected at the signature gate; an unrecognized value falls back toredirect.- Two rejection messages: "Untrusted signing request" (signature or parameter
problem) versus "This signing request could not be verified" (the partner's
keys could not be fetched — usually a
partner_idfrom the other environment). See Common Errors. - Signed requests carry seven
X-Yanez-*headers, not eight.