What does signatureVerificationFailed (code 37) mean in the purchases SDK?
The purchases SDK raises signatureVerificationFailed (code 37 on iOS, 36 on Android) when a response fails the signature check and verification is enforced.
Quick facts#
| Error | ErrorCode.signatureVerificationFailed (iOS), PurchasesErrorCode.SignatureVerificationError (Android), code 37 |
| Where | Purchases SDK (iOS, Android and the hybrid SDKs built on them) |
| What the vendor says | Request failed signature verification. |
Cause#
- iOS: a response failed verification while the SDK was in enforced mode. In any other mode the SDK logs the failure and carries on.
- Android: a
SignatureVerificationExceptionbecomesSignatureVerificationError, numbered 36 on Android and 37 on iOS. - A server that does not sign with the key the SDK trusts. The stock SDK trusts only RevenueCat's key, and a proxy that rewrites responses breaks the signature too.
Fix#
- Turn verification off in the SDK configuration (disabled mode). Native iOS and Android default to informational mode, which only logs a failure.
- Never use enforced mode with the stock SDK against RevenueDot: it would reject every response.
- Or build the RevenueDot forks with your server's public signing key to get verified responses.
- Compare the key at
GET /.well-known/revenuedot-signing-keywith the key in your SDK build.
Example#
Swift
// The purchases SDK throws `ErrorCode` values; match the one you handle and let the rest fall through.
func handle(_ error: Error) {
guard let code = error as? ErrorCode else {
print("Not a purchases SDK error: \(error)")
return
}
switch code {
case .signatureVerificationFailed:
// In informational mode nothing is thrown; with enforcement on, never unlock from this response.
print("Signature verification failed")
default:
print("Other purchases error: \(code.description)")
}
}Compile-checked: npm run check:snippets type-checks this snippet with swiftc together with the ErrorCode.swift file of the RevenueDot purchases-ios fork (checked 2026-10-03).
How the RevenueDot SDK reports it#
RevenueDot signs 2xx and 3xx responses under /v1 when REVENUEDOT_SIGNING_KEY is set. See signature verification failed in proxy mode. Deep dive: revenuedot.app/errors/signature-verification-failed.
Related#
- What does invalidCredentialsError (code 11) mean in the purchases SDK?
- What does invalidReceiptError (code 8) mean in the purchases SDK?
- What does VerificationError.invalidSignature mean in StoreKit 2?
- What RevenueDot's API errors mean (server codes)
Source#
- RevenueDot purchases-ios: ErrorCode.swift (the iOS ErrorCode enum)
- RevenueDot purchases-android: PurchasesErrorCode.kt (the Android enum)
- RevenueDot purchases-android: common/errors.kt (backend code mapping)
Checked: 2026-10-03