Glossary · Store notifications
What is the App Store Server API?
App Store Server API
The App Store Server API is a REST API that your server calls to read and manage a customer's in-app purchases. It returns signed transaction and renewal data for a single customer, based on a transaction identifier you provide. It covers transaction history, subscription status, refund history, order lookup, notification history and subscription renewal date extensions.
Calls use a JSON Web Token as a bearer token, signed with a key you create in App Store Connect. Apple provides the open-source App Store Server Library in four languages, which creates the tokens and verifies the signed data. The API works whether or not the customer has your app installed, because it answers from the customer's purchase history. Every endpoint except one is available in the sandbox at a separate base URL, and a transaction identifier must be sent to the environment that created it.
Typical uses: get all subscription statuses to learn whether a subscriber is active, in a grace period or in billing retry; get the transaction history; send consumption information after a refund request; extend a subscription's renewal date to make up for an outage; look up an order from the ID on a customer's receipt email; and request a test notification.
RevenueDot uses the API with the app's In-App Purchase key to confirm each StoreKit 2 purchase, read the full history and renewal state, and extend subscriptions. It can also look up an order ID for a support restore. Without the key RevenueDot still verifies signed transactions against Apple's root certificate, but it knows only what the device sent.
Sources: Apple: App Store Server API · Apple: Look Up Order ID · Apple: Send Consumption Information
FAQ
App Store Server API: questions people ask
What do I need to call the App Store Server API?
A key from App Store Connect (Users and Access, Integrations, In-App Purchase), its key ID and your issuer ID. You sign a short-lived token with the key for each request or reuse it until it expires.
Can I call it from the app?
Call it from your server. The key is a secret, and the endpoints are made for backend use.
Does it work in the sandbox?
Yes. All endpoints except the order lookup work in the sandbox, using the sandbox base URL.
Get started
Run subscriptions without the revenue share.
Start free on RevenueDot Cloud, free up to $10,000 a month in tracked revenue, or move an existing RevenueCat app with one line of code.
Already have an account? Sign in · Prefer your own servers? Self-host free