Store

App Store Server Notifications v2 setup and StoreKit 2 validation for your subscription backend

To set up App Store Server Notifications v2, copy your app's notification URL from RevenueDot, paste it as both the Production and Sandbox Server URL in App Store Connect, and choose Version 2. Add an In-App Purchase key so RevenueDot can read each customer's full StoreKit 2 history from Apple's App Store Server API.

Free up to $10,000 a month in tracked revenue. Works with the RevenueCat SDK you already ship.

The Refund Control page in the RevenueDot dashboard, where ordered policies pick the answer sent to Apple's CONSUMPTION_REQUEST notification
Refund Control answers Apple's refund requests with the same In-App Purchase key.

StoreKit 2 verified

RevenueDot checks every signed JWS transaction against Apple's root certificate.

Notifications v2

Renewals, cancellations, billing retries and refunds arrive when they happen, not when the app next opens.

One key, many jobs

The In-App Purchase key also signs promotional offers, answers refund requests and looks up order IDs.

RevenueCat SDK unchanged

Your app keeps import RevenueCat and changes one proxy URL line.

Setup

How to set up App Store Server Notifications v2 with RevenueDot

  1. 01

    Create the App Store app

    In the dashboard open Apps, add an App Store app and enter your bundle ID. The app's public SDK key starts with appl_. Start free on Cloud if you do not have an account yet.

  2. 02

    Generate an In-App Purchase key

    In App Store Connect open Users and Access, then Integrations, then In-App Purchase. Click +, name the key and download the .p8 file. Apple lets you download it once. Note the Key ID and the Issuer ID.

  3. 03

    Save the key and check it

    Open the app in RevenueDot, drop the .p8 file, enter both IDs and click Check credentials. RevenueDot makes one harmless call to Apple and tells you whether the key works.

  4. 04

    Paste the notification URL into App Store Connect

    Copy the app's notification URL, which looks like https://api.revenuedot.app/v1/notifications/apple/{app_id}. In App Store Connect open your app, App Information, App Store Server Notifications. Paste it as both the Production Server URL and the Sandbox Server URL and pick Version 2.

  5. 05

    Make a sandbox purchase

    Buy a subscription with a sandbox tester. The app's notification status in RevenueDot turns Ready when the first notification about a known purchase is processed.

How it works

What RevenueDot does with each purchase and notification

  • StoreKit 2: the SDK posts the signed transaction. RevenueDot verifies the JWS against Apple's root certificate and, with the key, reads the full history and renewal state (auto-renew, billing retry, grace period) from the App Store Server API.
  • Without the key: RevenueDot still verifies StoreKit 2 transactions, but it knows only what the device sent. StoreKit 1 receipts need the key. Without it RevenueDot answers 500 with code 7234, so the SDK keeps the purchase and retries after you add the key.
  • Notifications for purchases it has not seen: RevenueDot stores them and applies them only when Track new purchases from server-to-server notifications is on.
  • Bundle check: a notification for another bundle ID, or another Apple app ID when you set one, is refused.

How RevenueDot answers Apple

StatusWhenWhat Apple does
200Every verified notification, including ones about purchases RevenueDot has not seenStops retrying
400The signature is invalid, or the notification belongs to another bundle IDApp Store Connect shows the delivery as failed
500RevenueDot itself failedRetries later

Check any time with GET /v2/projects/{project_id}/setup_health, which lists each app's notification status.

API

Check the notification URL and the key from the command line

Read the URL, then ask Apple whether the key worksterminal
# The notification URL to paste into App Store Connect
curl -s "$REVENUEDOT_URL/v2/projects/$PROJECT_ID/apps/$APP_ID/store_settings" \
  -H "Authorization: Bearer $SECRET_KEY" | jq -r .notification_url

# One harmless call to Apple with the saved In-App Purchase key
curl -s -X POST "$REVENUEDOT_URL/v2/projects/$PROJECT_ID/apps/$APP_ID/actions/verify_credentials" \
  -H "Authorization: Bearer $SECRET_KEY"

Beyond validation

What else the same Apple key gives you

Before you ship, run a purchase with a sandbox tester and check that it reaches the customer page and your webhooks.

  • Win-back offers: Apple's iOS 18 win-back offers work with the SDK unchanged. RevenueDot records the offer on each purchase and sends it as offer_code in webhooks.
  • Refund requests: Refund Control answers Apple's CONSUMPTION_REQUEST within the 12-hour window, after you confirm that customers agreed to share usage data with Apple.
  • Promotional offers: the server signs promotional offers with the key.
  • Order lookup: a customer who sends you Apple's receipt email gets their subscription back through Apple's Look Up Order ID, with restore_purchase_by_order_id.
  • Extensions: extend one subscription by 1 to 90 days, or every active subscriber of a product after an outage.

FAQ

App Store: questions people ask

How do I set up App Store Server Notifications v2?

Copy the app's notification URL from RevenueDot, open App Store Connect, App Information, App Store Server Notifications, paste the URL as both the Production and the Sandbox Server URL and choose Version 2. Add an In-App Purchase key in RevenueDot so it can call the App Store Server API.

Do I need a different URL for sandbox and production?

No. RevenueDot reads the environment from Apple's signed notification, so you paste the same URL in both fields. Sandbox purchases are marked sandbox and stay out of production numbers.

Do I need an In-App Purchase key if I use StoreKit 2?

You need it for full history and renewal state, and for refund requests and promotional offers. Without it RevenueDot verifies StoreKit 2 transactions but knows only what the device sent. StoreKit 1 receipts are refused with a retryable 500 until you add the key.

Does RevenueDot use Apple's deprecated verifyReceipt endpoint?

No. RevenueDot verifies signed transactions locally and uses the App Store Server API with your In-App Purchase key. It stores the legacy shared secret but never calls verifyReceipt.

Can I keep sending notifications to RevenueCat while I test RevenueDot?

Yes. Set a forwarding URL on the app and RevenueDot copies each notification, byte for byte, to it. That is how a side-by-side run during a migration works. See Migrate from RevenueCat.

Get started

Run subscriptions without the revenue share.

Start free on RevenueDot Cloud, free up to $10,000 a month in tracked revenue, or move an existing RevenueCat app with one line of code.

Already have an account? Sign in · Prefer your own servers? Self-host free