Thanks, Albert.
We investigated this with our infrastructure team and found that requests to the AASA endpoint are currently subject to security controls, which explains why your request received an HTML response instead of the AASA file.
We also reviewed Apple's guidance regarding hosted AASA files and understand that the endpoint should accept requests from all user agents, including AASA-Bot and CFNetwork.
To ensure we align our configuration with Apple's requirements, could you please confirm whether there are any additional Apple user agents, services, or request sources that may be used to retrieve or validate the AASA file beyond AASA-Bot and CFNetwork?
As per our team, we are allowing for only AASA-Bot/1.0.0 now.
So help us rightly on this for which user agent we should allow for this AASA request.
Thanks,
Nethaji
Topic:
App Store Distribution & Marketing
SubTopic:
App Store Connect
Tags: