What does signatureVerificationFailed (code 37) mean in the purchases SDK?

The purchases SDK raises signatureVerificationFailed (code 37 on iOS, 36 on Android) when a response fails the signature check and verification is enforced.

Quick facts#

Error ErrorCode.signatureVerificationFailed (iOS), PurchasesErrorCode.SignatureVerificationError (Android), code 37
Where Purchases SDK (iOS, Android and the hybrid SDKs built on them)
What the vendor says Request failed signature verification.

Cause#

  • iOS: a response failed verification while the SDK was in enforced mode. In any other mode the SDK logs the failure and carries on.
  • Android: a SignatureVerificationException becomes SignatureVerificationError, numbered 36 on Android and 37 on iOS.
  • A server that does not sign with the key the SDK trusts. The stock SDK trusts only RevenueCat's key, and a proxy that rewrites responses breaks the signature too.

Fix#

  1. Turn verification off in the SDK configuration (disabled mode). Native iOS and Android default to informational mode, which only logs a failure.
  2. Never use enforced mode with the stock SDK against RevenueDot: it would reject every response.
  3. Or build the RevenueDot forks with your server's public signing key to get verified responses.
  4. Compare the key at GET /.well-known/revenuedot-signing-key with the key in your SDK build.

Example#

Swift
// The purchases SDK throws `ErrorCode` values; match the one you handle and let the rest fall through.
func handle(_ error: Error) {
    guard let code = error as? ErrorCode else {
        print("Not a purchases SDK error: \(error)")
        return
    }
    switch code {
    case .signatureVerificationFailed:
        // In informational mode nothing is thrown; with enforcement on, never unlock from this response.
        print("Signature verification failed")
    default:
        print("Other purchases error: \(code.description)")
    }
}

Compile-checked: npm run check:snippets type-checks this snippet with swiftc together with the ErrorCode.swift file of the RevenueDot purchases-ios fork (checked 2026-10-03).

How the RevenueDot SDK reports it#

RevenueDot signs 2xx and 3xx responses under /v1 when REVENUEDOT_SIGNING_KEY is set. See signature verification failed in proxy mode. Deep dive: revenuedot.app/errors/signature-verification-failed.

Source#

Checked: 2026-10-03

Edit this page on GitHub ↗ View as Markdown Last updated