StoreKit 2 verified
RevenueDot checks every signed JWS transaction against Apple's root certificate.
Store
To set up App Store Server Notifications v2, copy your app's notification URL from RevenueDot, paste it as both the Production and Sandbox Server URL in App Store Connect, and choose Version 2. Add an In-App Purchase key so RevenueDot can read each customer's full StoreKit 2 history from Apple's App Store Server API.
Free up to $10,000 a month in tracked revenue. Works with the RevenueCat SDK you already ship.
RevenueDot checks every signed JWS transaction against Apple's root certificate.
Renewals, cancellations, billing retries and refunds arrive when they happen, not when the app next opens.
The In-App Purchase key also signs promotional offers, answers refund requests and looks up order IDs.
Your app keeps import RevenueCat and changes one proxy URL line.
Setup
In the dashboard open Apps, add an App Store app and enter your bundle ID. The app's public SDK key starts with appl_. Start free on Cloud if you do not have an account yet.
In App Store Connect open Users and Access, then Integrations, then In-App Purchase. Click +, name the key and download the .p8 file. Apple lets you download it once. Note the Key ID and the Issuer ID.
Open the app in RevenueDot, drop the .p8 file, enter both IDs and click Check credentials. RevenueDot makes one harmless call to Apple and tells you whether the key works.
Copy the app's notification URL, which looks like https://api.revenuedot.app/v1/notifications/apple/{app_id}. In App Store Connect open your app, App Information, App Store Server Notifications. Paste it as both the Production Server URL and the Sandbox Server URL and pick Version 2.
Buy a subscription with a sandbox tester. The app's notification status in RevenueDot turns Ready when the first notification about a known purchase is processed.
How it works
| Status | When | What Apple does |
|---|---|---|
| 200 | Every verified notification, including ones about purchases RevenueDot has not seen | Stops retrying |
| 400 | The signature is invalid, or the notification belongs to another bundle ID | App Store Connect shows the delivery as failed |
| 500 | RevenueDot itself failed | Retries later |
Check any time with GET /v2/projects/{project_id}/setup_health, which lists each app's notification status.
API
# The notification URL to paste into App Store Connect
curl -s "$REVENUEDOT_URL/v2/projects/$PROJECT_ID/apps/$APP_ID/store_settings" \
-H "Authorization: Bearer $SECRET_KEY" | jq -r .notification_url
# One harmless call to Apple with the saved In-App Purchase key
curl -s -X POST "$REVENUEDOT_URL/v2/projects/$PROJECT_ID/apps/$APP_ID/actions/verify_credentials" \
-H "Authorization: Bearer $SECRET_KEY" Beyond validation
Before you ship, run a purchase with a sandbox tester and check that it reaches the customer page and your webhooks.
offer_code in webhooks.CONSUMPTION_REQUEST within the 12-hour window, after you confirm that customers agreed to share usage data with Apple.restore_purchase_by_order_id.FAQ
Copy the app's notification URL from RevenueDot, open App Store Connect, App Information, App Store Server Notifications, paste the URL as both the Production and the Sandbox Server URL and choose Version 2. Add an In-App Purchase key in RevenueDot so it can call the App Store Server API.
No. RevenueDot reads the environment from Apple's signed notification, so you paste the same URL in both fields. Sandbox purchases are marked sandbox and stay out of production numbers.
You need it for full history and renewal state, and for refund requests and promotional offers. Without it RevenueDot verifies StoreKit 2 transactions but knows only what the device sent. StoreKit 1 receipts are refused with a retryable 500 until you add the key.
No. RevenueDot verifies signed transactions locally and uses the App Store Server API with your In-App Purchase key. It stores the legacy shared secret but never calls verifyReceipt.
Yes. Set a forwarding URL on the app and RevenueDot copies each notification, byte for byte, to it. That is how a side-by-side run during a migration works. See Migrate from RevenueCat.
Get started
Start free on RevenueDot Cloud, free up to $10,000 a month in tracked revenue, or move an existing RevenueCat app with one line of code.
Already have an account? Sign in · Prefer your own servers? Self-host free