What are projects, apps and API keys?
A project is one product you sell, such as "Scanner". It owns the catalog, the customers, the webhooks and the secret keys. An app is that product on one store. Each app has its own public key, which the SDK sends with every request.
Projects#
- Signing up in the dashboard (
/signup) or withPOST /auth/signupcreates your account and its first project. - More projects: dashboard → New project, or
POST /v2/projectswhile signed in to the dashboard. A secret key belongs to one project, so it cannot create projects. - Project settings (
GETorPOST /v2/projects/{project_id}):name,transfer_behaviorandsandbox_transfer_behavior. See Customers and app user IDs. - Deleting a project deletes everything in it. Only an admin can do it, and only from the dashboard.
Apps#
Create an app per store with POST /v2/projects/{project_id}/apps or on the dashboard's Apps page.
type |
Store | Public key prefix | Store id field | Receipts accepted today |
|---|---|---|---|---|
app_store |
Apple App Store (iOS, iPadOS, tvOS, visionOS, watchOS) | appl_ |
app_store.bundle_id |
Yes |
mac_app_store |
Mac App Store | mac_ |
mac_app_store.bundle_id |
Yes |
play_store |
Google Play | goog_ |
play_store.package_name |
Yes |
test_store |
RevenueDot Test Store | test_ |
none | Yes |
amazon |
Amazon Appstore | amzn_ |
amazon.package_name |
No (Tier 2) |
stripe, rc_billing, paddle, roku |
Web and other stores | strp_, rcb_, pdl_, roku_ |
none | No (planned) |
curl -s -X POST http://localhost:8787/v2/projects/$PROJECT_ID/apps \
-H "Authorization: Bearer $SECRET_KEY" -H "Content-Type: application/json" \
-d '{"name":"Scanner (iOS)","type":"app_store","app_store":{"bundle_id":"com.example.scanner"}}'{"object":"app","id":"appk6jbcorn","name":"Scanner (iOS)","created_at":1790798214712,"type":"app_store","project_id":"projujvzn2wl","custom_url_scheme":"rc-3c3d62a884","app_store":{"bundle_id":"com.example.scanner","app_store_connect_api_key_configured":false,"subscription_key_configured":false,"app_store_connect_vendor_number":null}}Store credentials, such as Apple's in-app purchase key and Google's service account, belong to the app. They are never returned by the API; responses only say whether each is configured. Setup is in Connect the App Store and Connect Google Play.
Which key goes where#
| Key | Looks like | Where it lives | What it can do |
|---|---|---|---|
| Public app key | appl_…, goog_…, test_… |
In your app, passed to Purchases.configure |
The SDK endpoints for that app's project: customer info, offerings, receipts, logIn, attributes |
| Secret key | sk_… |
Your backend and scripts only | REST API v1 and v2 for one project, limited by its permissions |
| Dashboard session | cookie rd_session |
Your browser | The dashboard, and /v2 for every project you are a member of |
| Webhook signing secret | whsec_… |
Your backend | Verifying webhook signatures |
Get an app's public key with GET /v2/projects/{project_id}/apps/{app_id}/public_api_keys or on the app's dashboard page. Create secret keys on API keys or with POST /v2/projects/{project_id}/api_keys. The key is returned once. See Authentication.