K Khan
Jan 15, 2024
visibility 7467
star star star star star star
(2 votes)

Toptip - what is .well-known folder

Within your ~/public folder, you may come across a directory named ".well-known." This directory is frequently employed in web-based protocols to retrieve "site-wide metadata" related to a host before initiating a request. It's important to note that the absence of this folder doesn't necessarily indicate an issue; it simply means it hasn't been utilized or generated yet.

Here are some examples of what you might find in the ".well-known" directory:

  1. .well-known/security.txt: Contains information about a website's security policies and contact information for security researchers.
    Please read some helpful blogs on this topic.
    https://www.gulla.net/en/blog/security.txt
    https://optimizely.blog/2023/03/easy-implementation-of-security.txt-with-minimal-api-.net-core
  2. .well-known/apple-app-site-association (AASA): Used for associating iOS apps with websites, enabling features like Universal Links. This file doesn't have an extension.

  3. .well-known/assetlinks.json: Used in the context of Android App Links. Android App Links are a way to associate a website with a specific Android app, allowing the app to open when certain links are clicked, even if the app is not currently installed on the device.
Jan 15, 2024

Comments

Scott Reed
Scott Reed Jan 15, 2024 01:25 PM

I'll be honest it wasn't very clear to me that the link on security.txt was a link to another blog post that covered it in more detail, can you make that clearer.

Also (and I mentioned this on Tomas's blog) it might be worth a link to as well to https://optimizely.blog/2023/03/easy-implementation-of-security.txt-with-minimal-api-.net-core too as there's some more code exmples and explanation on the security.txt

K Khan
K Khan Jan 15, 2024 01:38 PM

Thanks for the feedback, I have updated the contents.

Scott Reed
Scott Reed Jan 15, 2024 05:49 PM

Super, great work :-)

error Please login to comment.
Latest blogs
Implementing the Bynder DAM Connector with Optimizely SaaS CMS: Lessons Learned

What I learned while integrating Bynder DAM with Optimizely SaaS CMS, exploring Optimizely Graph, and building a headless frontend experience....

Vipin Banka | Jul 3, 2026

Optimizely London developer meetup 2026: a round up

Well, what can I say? Last night we wrapped up! Yet another London Developer Meetup, hosted at the superb Lightwell venue And this is also a...

Scott Reed | Jul 3, 2026

AvantiBit Custom Settings for Optimizely CMS

AvantiBit Custom Settings is a free, Apache-2.0 Optimizely CMS add-on for typed, site- and language-aware configuration that stays out of content...

Enes Bajramovic | Jul 3, 2026 |

Building an experience with Visual Builder in Optimizely CMS 13

Visual Builder changes how we can think about campaign pages, landing pages and other highly curated editorial experiences in Optimizely CMS. Inste...

Pär Wissmark | Jul 2, 2026 |