On Android the bridge is one object, window.androidBridge, injected into the page before your code runs. MessageHandler.java creates it with the AndroidX 234 WebKit 15,343 call WebViewCompat.addWebMessageListener(webView, "androidBridge", bridge.getAllowedOriginRules(), listener), falling back to addJavascriptInterface only when the WebView lacks the feature or you set android.useLegacyBridge. The rules admit only the app's own origin plus server.url and allowNavigation hosts, and the listener drops iframe messages ("Plugin execution is allowed in Main Frame only"), so an ad or a page you navigated to cannot call your plugins. Messages must be strings, so native-bridge.js, the JavaScript half, stringifies every call and parses every reply:
postToNative = (data) => {
win.androidBridge.postMessage(JSON.stringify(data));
};
win.androidBridge.onmessage = function (event) {
returnResult(JSON.parse(event.data));
};On iOS the same file posts to window.webkit.messageHandlers.bridge, a WKScriptMessageHandler, and native code replies by evaluating JavaScript.
