Glossary · Store notifications
What is receipt validation?
Receipt validation
Receipt validation is the check that a purchase is genuine before your app or server grants access. On Apple platforms you verify the signed transaction, either with StoreKit on the device or with the App Store Server Library on your server. On Google Play you send the purchase token to the Play Developer API. Never trust the app's own claim.
Apple's older receipt endpoint, verifyReceipt, is deprecated. For new work, verify the JWS signed transactions that StoreKit 2 returns, and use the App Store Server API when you need history or renewal state. Apple notes that you can verify transactions on your server or rely on StoreKit's verification.
On Google Play, send the purchase token to your backend, check that it is new, confirm it with purchases.subscriptionsv2.get or purchases.products.get, apply your own abuse checks, then grant access and acknowledge. If a purchase fails your checks, Google advises refunding it explicitly with the revoke option rather than letting the 3-day auto-refund happen.
RevenueDot takes the receipt from the SDK at POST /v1/receipts and uses the status code to steer the SDK. A 4xx means the purchase can never be accepted, so the SDK finishes the transaction. A 5xx means try again later, so the SDK keeps it and retries. RevenueDot never answers 4xx for its own failures, and a missing App Store key or Google service account answers 5xx, so a setup mistake never loses a paid customer's purchase.
Sources: Apple: App Store Receipts · Apple: VerificationResult · Apple: JWSTransaction · Android Developers: Fight fraud and abuse
FAQ
Receipt validation: questions people ask
Is verifyReceipt still supported?
Apple has marked it deprecated. Use signed transactions and the App Store Server API instead.
Do I have to validate on a server?
Not to give access on one device, because StoreKit verifies the signed data. You need a server to share access across platforms, to handle refunds and renewals when the app is closed, and to keep reliable records.
What should I do when validation fails?
Do not grant access. On Google Play, refund the purchase with the revoke option if it is clearly invalid. On the App Store, log the failure and check that the bundle ID and environment match.
Get started
Run subscriptions without the revenue share.
Start free on RevenueDot Cloud, free up to $10,000 a month in tracked revenue, or move an existing RevenueCat app with one line of code.
Already have an account? Sign in · Prefer your own servers? Self-host free