What does VerificationError.invalidSignature mean in StoreKit 2?
VerificationResult.VerificationError.invalidSignature means the signature of a signed StoreKit 2 value did not match its header and payload.
Quick facts#
| Error | VerificationResult.VerificationError.invalidSignature |
| Where | StoreKit 2, Swift (VerificationResult) |
| Available since | iOS 15.0, iPadOS 15.0, macOS 12.0, tvOS 15.0, watchOS 8.0, visionOS 1.0 |
| What the vendor says | The signature did not match the header and payload. |
Cause#
- StoreKit 2 returns transactions, renewal information and the app transaction wrapped in a
VerificationResult. It checks them automatically, and a value that fails is.unverified, with the reason as aVerificationError(VerificationResult). invalidSignatureis one of six reasons Apple lists, next toinvalidCertificateChain,invalidDeviceVerification,invalidEncoding,missingRequiredPropertiesandrevokedCertificate.- It means the signed text was altered or does not belong to the signature. Apple gives no further detail on the case page.
Fix#
- Treat an
.unverifiedresult as untrusted. Do not unlock content from it. - Log the
VerificationErrorand the transaction ID, then check the same transaction on your server with the App Store Server Library, as Apple suggests for the highest security. - Check that the test environment is set up correctly if you only see it in testing.
- Do not call
finish()on an unverified transaction until you have decided what to do with it.
Example#
Swift
import StoreKit
// Only a verified transaction may unlock content. Log the reason for an unverified one.
func handle(_ result: VerificationResult<Transaction>) {
switch result {
case .verified(let transaction):
print("Unlock \(transaction.productID)")
case .unverified(let transaction, let error):
if case .invalidSignature = error {
print("Signature check failed for \(transaction.productID); do not unlock")
} else {
print("Verification failed: \(error)")
}
}
}Compile-checked: npm run check:snippets type-checks this snippet with swiftc against the Apple SDK (macOS target, checked 2026-10-03).
How the RevenueDot SDK reports it#
The RevenueDot purchases-ios fork turns an unverified transaction into ErrorCode.storeProblemError (code 2) with the VerificationError as the underlying error, and it does not unlock the purchase. RevenueDot's server also verifies the signed transaction on its side.
Related#
- What does invalidReceiptError (code 8) mean in the purchases SDK?
- What does Product.PurchaseError.invalidOfferSignature mean?
- What does storeProblemError (code 2) mean in the purchases SDK?
Source#
- Apple: VerificationResult.VerificationError.invalidSignature
- Apple: VerificationResult
- RevenueDot purchases-ios: StoreKit2TransactionListener.swift
Checked: 2026-10-03