Skip to content Skip to footer

Amazon RDS for Oracle Adds APEX 26.1 Support — and Amazon SES Click Tracking Now Preserves Mobile Deep Links

What Happened

On 2026-08-14 Amazon updated two platform capabilities relevant to application and email delivery stacks:

  • Amazon RDS for Oracle now supports Oracle Application Express (APEX) 26.1, making that APEX release available on managed RDS instances in all regions where RDS for Oracle is offered. See Oracle and Amazon RDS documentation for feature and option-group instructions [1].
  • Amazon Simple Email Service (SES) added a new HTML attribute ses:custom-path for <a> tags used in emails. SES will preserve the path segment through its click-tracking redirect, enabling iOS Universal Links and Android App Links to match app deep-link configurations when using a custom redirect domain and the required AASA / Digital Asset Links verification files hosted on that domain [2].

Why It Matters to Businesses

  • APEX 26.1 on RDS lets teams deploy the latest low-code enterprise UI features inside a managed Oracle environment without self-managing the DB option — useful for accelerating internal apps and customer portals while outsourcing patching and backups to AWS [1].
  • SES’s ses:custom-path closes a common gap between email engagement analytics and mobile deep linking. Marketers and product teams can keep click-tracking for attribution while still launching users into specific in-app routes on iOS/Android, reducing friction and measurement loss from previous workarounds [2].
  • Both updates reduce custom operational work: APEX support saves an on-prem maintenance burden; SES custom-path reduces reliance on bespoke redirection infrastructures or complex link-wrapping logic.

Kimbodo Engineering Perspective

APEX 26.1 on Amazon RDS for Oracle

  • Trade-offs: using RDS for Oracle with APEX minimizes operational overhead (backups, Multi-AZ, minor patching) but keeps you on Amazon’s managed option-group lifecycle. If you need a custom, non-supported Oracle extension or deep DB-level control, RDS may constrain you.
  • Judgment: adopt RDS-hosted APEX for standard enterprise apps and internal portals where rapid delivery, HA, and managed operations are priorities. Reserve self-managed Oracle when you require unsupported third-party DB components or nonstandard kernel patches.

SES ses:custom-path for Mobile Deep Linking

  • Trade-offs: enabling SES click-tracking with a custom redirect domain plus AASA/assetlinks support gives best UX and attribution, but requires maintaining an HTTPS redirect domain and verification artifacts. If you rely on vendor-managed redirect domains without verification, deep linking will remain unreliable.
  • Judgment: use SES custom-path where mobile user acquisition and in-app conversion measurement matter. For highly security-sensitive deep links (containing tokens or PII), prefer token exchange flows rather than exposing data in URLs.

How We Would Implement It

Implementing APEX 26.1 on RDS for Oracle

  • Inventory: confirm your Oracle DB engine version compatibility with APEX 26.1 using Oracle APEX 26.1 release notes and RDS supported engine matrix [1].
  • Staging: create a staging RDS instance (same instance class, parameter group, option group) and enable the APEX option in the instance option group per Amazon RDS for Oracle documentation [1].
  • Migrate and test: export existing APEX workspaces or applications, import into the staging APEX 26.1 instance, and run functional and regression tests for UI components and REST services.
  • Production rollout: schedule a maintenance window, apply the APEX option change to production RDS via an option-group modification, and validate DB backups and automated snapshots before and after the change.
  • Operational setup: enable Multi-AZ for HA, configure automated backups and point-in-time recovery, monitor APEX/DB performance (CPU, PGA/SGA, I/O), and set alerts for APEX-specific errors logged to CloudWatch.
  • Security and compliance: enforce encryption at rest (AWS KMS), TLS for connections, least-privilege accounts for APEX database schemas, and segregate APEX runtime data from sensitive schemas.

Enabling SES Click Tracking with ses:custom-path

  • Prepare a custom redirect domain: provision a DNS-controlled domain (or subdomain) with HTTPS and a public TLS certificate.
  • Host verification files: upload an Apple App Site Association (AASA) file at the custom redirect domain and an Android Digital Asset Links JSON (assetlinks.json) at the expected path. Verify file formats and HTTPS availability [2].
  • Configure SES: set the custom redirect domain for click tracking in SES and ensure SES is set to rewrite links using your domain; include ses:custom-path attributes on <a> tags in your HTML email templates for segments you want to preserve [2].
  • Test device flows: verify that rewritten links open the correct in-app routes on iOS (Universal Links) and Android (App Links) and that click tracking metrics are still recorded in SES.
  • Monitoring and rollback: monitor click-through and app-open attribution; retain a tested fallback URL for clients or email clients that break deep links, and implement a fast rollback plan (disable custom redirect) if issues appear.

Risks, Costs and Security

  • Licensing and compliance (APEX/Oracle): confirm Oracle licensing terms for RDS (BYOL vs license-included). Misaligned licensing can produce unexpected costs and compliance exposure.
  • Operational cost: RDS instance size, storage, IO, Multi-AZ, and additional snapshot retention increase monthly spend. SES costs may include custom domain hosting, TLS certificates, and any click-tracking charges—review AWS pricing pages for region-specific costs [1][2].
  • Availability and region parity: both features are available in all regions where the services are offered, but validate regional availability for your accounts and pricing zones [1][2].
  • Security of deep links: do not embed sensitive tokens or PII in deep-link paths preserved by ses:custom-path. Use short-lived token exchanges or one-time codes validated by your app backend.
  • Open-redirect and phishing risk: ensure your custom redirect domain enforces strict validation of target paths to avoid open-redirect vulnerabilities that attackers could exploit.
  • Email client compatibility: some email clients strip unknown HTML attributes; SES processes the ses:custom-path server-side when rewriting links, but perform cross-client testing because rendering or sanitization differences can affect user experience [2].
  • Backup and rollback: when enabling APEX via RDS option groups, ensure pre-change snapshots and tested recovery procedures to revert if application incompatibilities appear [1].

Where Kimbodo Comes In

Kimbodo builds and operates this in production for businesses — see our AI Application Development practice. Wondering what it would cost for your organization? Get a preliminary range, timeline and architecture in about a minute.

Estimate My AI Application

Sources

  1. [1] Amazon RDS for Oracle now supports Oracle Application Express (APEX) version 26.1
  2. [2] Amazon SES click tracking now supports custom URL paths for mobile app deep linking

Leave a comment

0.0/5