---
title: "What does VerificationError.invalidCertificateChain mean in StoreKit 2?"
description: "VerificationResult.VerificationError.invalidCertificateChain means the certificate chain of a signed StoreKit 2 value is not valid. Treat the transaction as untrusted, log the reason and verify it on your server before unlocking."
url: https://revenuedot.app/docs/errors/storekit-verification-error-invalid-certificate-chain
---

# What does VerificationError.invalidCertificateChain mean in StoreKit 2?

VerificationResult.VerificationError.invalidCertificateChain means the certificate chain of a signed StoreKit 2 value is not valid.

## Quick facts

| | |
|---|---|
| Error | `VerificationResult.VerificationError.invalidCertificateChain` |
| Where | StoreKit 2, Swift (`VerificationResult`) |
| Available since | iOS 15.0, iPadOS 15.0, macOS 12.0, tvOS 15.0, watchOS 8.0, visionOS 1.0 |
| What the vendor says | An error indicating that the certificate chain is invalid. |

## Cause

- StoreKit 2 returns transactions, renewal information and the app transaction wrapped in a `VerificationResult`. It checks them for you, and a value that fails is `.unverified` with the reason as a `VerificationError` ([VerificationResult](https://developer.apple.com/documentation/storekit/verificationresult)).
- Apple says this can happen when one or more certificates in the chain are expired or come from an untrusted source.
- `invalidCertificateChain` is one of six reasons Apple lists, next to `invalidSignature`, `invalidCertificateChain`, `invalidDeviceVerification`, `invalidEncoding`, `missingRequiredProperties` and `revokedCertificate`.

## Fix

1. Treat an `.unverified` result as untrusted. Do not unlock content from it and do not call `finish()` on it until you have decided what to do.
2. If the device clock is wrong, ask the person to set date and time automatically, because expired-looking certificates are a common result.
3. Log the `VerificationError` and the transaction ID, then check the same transaction on your server with Apple's App Store Server Library or the App Store Server API.
4. If it only happens in testing, check the test environment (Xcode StoreKit configuration, sandbox account) before changing code.

## Example

```swift
import StoreKit

// Only a verified transaction may unlock content. Log the reason when a transaction is unverified.
func handle(_ result: VerificationResult<Transaction>) {
    switch result {
    case .verified(let transaction):
        print("Unlock \(transaction.productID)")
    case .unverified(let transaction, let error):
        if case .invalidCertificateChain = error {
            print("The certificate chain is invalid for \(transaction.productID); do not unlock")
        } else {
            print("Verification failed: \(error)")
        }
    }
}
```

*Compile-checked: `npm run check:snippets` type-checks this snippet with `swiftc` against the Apple SDK (macOS target, checked 2026-10-03).*

## How the RevenueDot SDK reports it

The RevenueDot `purchases-ios` fork turns an unverified transaction from a purchase or a transaction update into `ErrorCode.storeProblemError` (code 2) with the `VerificationError` as the underlying error, and it does not unlock the purchase. When it only reads existing transactions (offline entitlements, transaction history), it logs a warning and skips the unverified ones.

## Related

- [What does VerificationError.invalidSignature mean in StoreKit 2?](https://revenuedot.app/docs/errors/storekit-verification-error-invalid-signature.md)
- [What does storeProblemError (code 2) mean in the purchases SDK?](https://revenuedot.app/docs/errors/sdk-store-problem-error.md)
- [What does invalidReceiptError (code 8) mean in the purchases SDK?](https://revenuedot.app/docs/errors/sdk-invalid-receipt-error.md)

## Source

- [Apple: VerificationResult.VerificationError.invalidCertificateChain](https://developer.apple.com/documentation/storekit/verificationresult/verificationerror/invalidcertificatechain)
- [Apple: VerificationResult](https://developer.apple.com/documentation/storekit/verificationresult)
- [RevenueDot purchases-ios: StoreKit2TransactionListener.swift](https://github.com/revenuedot/purchases-ios/blob/revenuedot/main-patches/Sources/Purchasing/StoreKit2/StoreKit2TransactionListener.swift)

Checked: 2026-10-03
