@haavardmolland : You're correct that Android OS allows such linked app to handle URLs by default. (Little known fact: users can still change the URL handler app in settings.) Apps have access to read the SHA256 fingerprint of the payment app's signer cert as well. See [PackageInfo.signatures](

