What does the App Store notification REVOKE mean?

The App Store notification REVOKE means a purchase that a family member could use through Family Sharing is no longer shared with them.

Quick facts#

Notification notificationType REVOKE
Where App Store Server Notifications v2 (responseBodyV2DecodedPayload)
Sent by The App Store server, to your notification URL
What Apple says An in-app purchase the customer had through Family Sharing is no longer available that way. The App Store sends it when the purchaser turns off Family Sharing for it, when the purchaser or a family member leaves the family, or when the purchaser is refunded.

What triggers it#

  • The purchaser disabled Family Sharing for the purchase.
  • The purchaser or the family member left the family group.
  • The purchaser received a refund. Family Sharing applies to non-consumables and auto-renewable subscriptions.

What your server should do#

  1. Verify the signedPayload with Apple's App Store Server Library (SignedDataVerifier.verifyAndDecodeNotification) before you act on anything in it.
  2. Remove the family member's access to that purchase, and keep the purchaser's own access.
  3. On iOS the app also gets paymentQueue(_:didRevokeEntitlementsForProductIdentifiers:) for StoreKit 1 apps. A StoreKit 2 app sees the transaction's revocationDate.
  4. Offer the family member their own subscription.
  5. Answer HTTP 200 (any code from 200 to 206) once you have stored the notification. Apple retries other answers five times, at 1, 12, 24, 48 and 72 hours after the previous attempt, so make your handler safe to run twice (the payload carries a notificationUUID).

Example#

JavaScript
// Run on the decoded payload, after you verified Apple's signature.
const notification = {"notificationType":"REVOKE","data":{"environment":"Sandbox","bundleId":"com.example.app"}};

function decide(n) {
  if (n.notificationType !== "REVOKE") return "ignore";
  return "remove the family member's access, keep the purchaser's";
}

console.log(decide(notification));

Run-checked: npm run check:snippets runs this snippet with Node and compares its output with remove the family member's access (checked 2026-10-03).

How RevenueDot handles it#

RevenueDot verifies Apple's signature, checks the bundle ID, stores the notification and answers 200. A purchase RevenueDot has not seen is applied only when the app's Track new purchases from server-to-server notifications setting is on. REVOKE is one of the types that apply the signed transaction. RevenueDot reads the transaction's revocationDate as the refund time, so the stored purchase is treated like a refunded one and a CANCELLATION event with cancel_reason: CUSTOMER_SUPPORT follows.

Source#

Checked: 2026-10-03

Edit this page on GitHub ↗ View as Markdown Last updated