Glossary · Store notifications
What is a purchase token (Google Play)?
Purchase token (Google Play)
A purchase token is the string that Google Play issues to the device when a customer buys a product or subscription. It is globally unique, so you can use it as a primary key. Your server sends it to the Google Play Developer API to verify the purchase, read its current state and acknowledge it.
Send the token from the app to your backend, record every token you see, and check that it has not been used before. Then call purchases.subscriptionsv2.get for a subscription or purchases.products.get for a one-time product to confirm the purchase with Google. Only after those checks should you grant access, and then acknowledge the purchase within three days or Google refunds it.
For subscriptions the token stays the same through renewals, grace period, account hold and a restore. A new token appears when the customer repurchases after expiry, or when a plan change creates a new purchase, as a deferred replacement does. When a subscription has a linkedPurchaseToken, remove the old token from your database and revoke the access you granted under it, so two users are never entitled to one purchase. The token is valid from signup until 60 days after expiry.
RevenueDot keys each Google Play subscription by its purchase token. It verifies the purchase with the service account you add, acknowledges it within Google's 3-day limit, and answers 400 to the SDK when Google says the token is not valid.
Sources: Android Developers: Fight fraud and abuse · Android Developers: Subscription lifecycle · Android Developers: Integrate the Play Billing Library
FAQ
Purchase token (Google Play): questions people ask
Is the purchase token the same as the order ID?
No. An order ID names one order, and the Developer API returns the latest one for a subscription. The purchase token names the purchase itself and stays the same through renewals.
How long is a purchase token valid?
From signup until 60 days after the subscription expires. After that you can no longer call the Developer API with it.
Can I trust a token that my app sends me?
Treat it as a claim. Verify it with Google before you grant access, because the app can send anything.
Get started
Run subscriptions without the revenue share.
Start free on RevenueDot Cloud, free up to $10,000 a month in tracked revenue, or move an existing RevenueCat app with one line of code.
Already have an account? Sign in · Prefer your own servers? Self-host free