Build Notification Hub registration configs with APNS, FCM, and WNS platform credentials, template registrations, and SAS rules.
Build Notification Hub registration configs with APNS, FCM, and WNS platform credentials, template registrations, and SAS authorization rules.
Required Fields
namespaceNamehubNameresourceGroupskuplatformCredentialsregistrationsOutput will appear here...Build an Azure Notification Hub with per-platform credentials (APNS certificate or token-based auth, FCM v1 service account, WNS package/secret) and template registrations using platform-specific payload shapes, since a single logical notification (title, message, badge count) needs an entirely different JSON structure for APNS versus FCM, which the template's platform-specific body handles via the shared $(title)/$(message) placeholder substitution. authorizationRules with distinct rights combinations (Listen-only, Send-only, full Listen+Manage+Send) matter for credential hygiene: a backend service that only ever sends notifications should use the BackendSendOnly rule, not the DefaultFullSharedAccessSignature rule, since a Send-only credential leak can't be used to also manage or read the hub's registration data.
Never use a full Listen+Manage+Send credential for a backend service that only needs to send, scope it to a Send-only rule, this is a cheap, high-value security improvement that limits the damage from an accidental credential leak.
Design registration tags deliberately as a real segmentation scheme (platform, environment, user tier) from the start, retrofitting a tagging strategy after devices have already registered without meaningful tags means you can't retroactively target historical registrations by a dimension they were never tagged with.
Verify you're using fcmV1 with service account credentials for new Android integrations, not a legacy FCM server key approach, since Google's platform direction has moved away from the older authentication method.
The builder validates that namespaceName, hubName, resourceGroup, sku, platformCredentials, and registrations all resolve before accepting the JSON as a valid combined hub configuration; it can't verify the platform credentials (APNS certificate validity, FCM service account permissions, WNS package SID) are actually valid and currently active with each platform provider, those are only confirmed when the hub actually attempts to send a real push notification.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.