Signed responses
Every 2xx and 3xx response under /v1 and /rcbilling carries an X-Signature header.
Feature
RevenueDot signs every SDK response with an Ed25519 signature in the format the RevenueCat SDKs verify, once you set REVENUEDOT_SIGNING_KEY. The stock SDK trusts only RevenueCat's key, so against RevenueDot it reports verification FAILED. Turn verification off in the stock SDK, or use a RevenueDot fork that trusts your key.
Free up to $10,000 a month in tracked revenue. Works with the RevenueCat SDK you already ship.
Every 2xx and 3xx response under /v1 and /rcbilling carries an X-Signature header.
The server makes a new intermediate key every 30 days. Only the root seed is configured.
The server's contract tests check the format against real signatures and reject tampered bodies, nonces and paths.
RevenueDot Cloud signs with a public key published at /.well-known/revenuedot-signing-key.
Defaults differ per SDK. iOS and Android are informational, React Native, Flutter and Kotlin Multiplatform default to disabled, and purchases-js does not verify.
| App uses | Server | Result |
|---|---|---|
| Stock RevenueCat SDK, verification DISABLED | Any | No check. Everything works. Recommended for proxy mode. |
| Stock SDK, INFORMATIONAL (the iOS and Android default) | Any | Entitlements work, but each carries verification FAILED and the SDK logs an error. |
| Stock SDK, ENFORCED | Any | Every request fails. Never use it against RevenueDot. |
| RevenueDot fork, official build | RevenueDot Cloud | VERIFIED |
| RevenueDot fork built with your public key | Your server with REVENUEDOT_SIGNING_KEY | VERIFIED |
Steps
In a checkout of the server repository run pnpm tsx scripts/signing-keygen.ts. It prints the REVENUEDOT_SIGNING_KEY seed and the public key.
Set REVENUEDOT_SIGNING_KEY as an environment variable and keep it in your password manager. Anyone with the seed can sign responses your apps trust.
Call /.well-known/revenuedot-signing-key. Without a key it answers 404 and responses are not signed.
Turn verification off in the stock SDK, or build the SDK forks with your public key to get VERIFIED.
curl -s http://localhost:8787/.well-known/revenuedot-signing-key
# {"algorithm":"Ed25519","public_key":"ZzwPxGlon0E8ErpDh9QAH0Jh6+E6D6qufvTSetXZY9Y=","encoding":"base64","header":"X-Signature","docs":"https://revenuedot.app/docs"} The X-Signature value is base64 of 180 bytes: an intermediate Ed25519 public key, its expiry in days, the root key's signature over both, a random salt, and the intermediate key's signature over the message. The message is the salt, the API key, the nonce, the request path, the request hash headers, the response time and ETag headers, and the body. The SDK sends a random X-Nonce with requests it verifies, and the nonce is part of the message.
RevenueDot Cloud signs with the public key gXdn2hmqR/TbdtQwK02laE0YgFz0Rtf918LICLrgZhg=. A self-hosted server signs with its own key, so the official forks verify only against RevenueDot Cloud. Rotating the root key means shipping new SDK builds, because the key is compiled into the app.
FAQ
The stock SDK checks responses against RevenueCat's public key, and RevenueDot cannot sign with RevenueCat's private key. Set verification to disabled in the SDK, or use a RevenueDot fork that trusts RevenueDot's key. Access still works in informational mode, but the SDK logs errors.
Not with the stock SDK. Every request would fail, because the stock SDK trusts only RevenueCat's key. Use DISABLED in proxy mode, or a RevenueDot fork, which verifies RevenueDot's signatures.
Generate a signing key pair, set REVENUEDOT_SIGNING_KEY on the server, and build the RevenueDot SDK forks with your public key and host using the fork pipeline. The official forks trust only RevenueDot Cloud's key.
Yes. RevenueDot Cloud signs every SDK response, and its public key is served at /.well-known/revenuedot-signing-key. The official RevenueDot forks trust that key and report VERIFIED.
Get started
Start free on RevenueDot Cloud, free up to $10,000 a month in tracked revenue, or move an existing RevenueCat app with one line of code.
Already have an account? Sign in · Prefer your own servers? Self-host free