Apple Pay Domain Verification
Verify your merchant domain with Apple for Embedded Integration Apple Pay.
For Embedded Integration Apple Pay, Apple requires domain verification on your merchant domain. Hosted checkout merchants do not need to configure domain verification — DigetPay manages the checkout domain.
Hosted checkout: No domain verification or merchant-side Apple Pay domain configuration is required. See Apple Pay on Hosted Checkout.
The Apple Pay domain association file must be served over HTTPS at the exact path Apple expects. The file must be accessible directly and must not use redirects.
If domain verification fails, Apple Pay will not appear on your checkout. Always test the association file URL in a browser before going live.
Verification flow
flowchart LR A[Obtain association file] --> B[Host file on merchant domain] B --> C[Add domain in Apple Developer] C --> D[Verify domain] D --> E[DigetPay registers domain] E --> F[Apple Pay enabled]
Step 1 — Obtain the association file
Contact DigetPay Integration Support to obtain the Apple Pay domain association file:
apple-developer-merchantid-domain-associationFor production, DigetPay coordinates the required Apple Pay merchant-domain registration using your Apple Pay merchant ID.
Step 2 — Host the file on your domain
Place the association file at the exact path below:
https://yourdomain.com/.well-known/apple-developer-merchantid-domain-association| Requirement | Detail |
|---|---|
| Path | /.well-known/apple-developer-merchantid-domain-association |
| Protocol | HTTPS only |
| Content-Type | application/octet-stream or text/plain |
| Redirects | Must not redirect — serve the file directly |
| Access | The file must be publicly accessible |
Important: Do not rename the file or place it in another directory. Apple expects the association file at the exact
.well-knownpath.
Step 3 — Verify your domain in Apple Developer
- Log in to the Apple Developer portal.
- Navigate to Certificates, Identifiers & Profiles.
- Select Merchant IDs.
- Select the Apple Pay merchant ID used for your integration.
- Open Merchant Domains.
- Add your merchant domain.
- Click Verify.
- Apple will fetch the association file from your
.well-knownpath.
Make sure the domain you add is the same domain where the association file is hosted.
Staging vs production
| Environment | Notes |
|---|---|
| Fin staging | Use the staging Apple Pay merchant ID and staging merchant domain. |
| Production | Use the production Apple Pay merchant ID and live merchant domain. Contact DigetPay before go-live to coordinate production registration. |
Troubleshooting
| Issue | Fix |
|---|---|
| 404 on association file | Check the .well-known directory, file name, and web server configuration. |
| Redirect detected | Serve the file directly without HTTP 301/302 redirects. |
| HTTPS error | Ensure the domain has a valid SSL/TLS certificate and is accessible over HTTPS. |
| Verification timeout | Check your firewall, CDN, WAF, or security rules to ensure Apple's requests are not blocked. |
| Wrong domain | Confirm that the domain added in Apple Developer exactly matches the domain where the association file is hosted. |
| Button still missing | Confirm that the domain verification succeeded and that DigetPay has completed the required merchant-domain registration. |
Before going live
Use the following checklist to confirm that your Apple Pay domain is ready:
- Association file obtained from DigetPay.
- File uploaded to the exact
/.well-known/path. - File is accessible over HTTPS.
- File URL does not redirect.
- Domain added to the correct Apple Pay Merchant ID.
- Apple domain verification completed successfully.
- DigetPay confirmed production domain registration.
- Apple Pay tested on the production merchant domain.
Next steps
Updated about 1 month ago

