Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Verify a store purchase

Verifies a store purchase with the store, binds it to the subject, and returns its record and a signed grant.

Verifies a store purchase with the store, binds it to the subject, and returns its record and a signed grant. Re-verifying returns the same record and grant. Called from the app's server with a secret key that holds billing:write; a publishable key cannot call it.

  • Path POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_purchases:verify
  • Scope billing:write
  • Effect write — a successful call changes state.
  • Collection store_purchases

#Request

FieldTypeWhat it is
parentstringThe environment the purchase is verified in. Required.
subjectSubjectWho bought it. Required.
storestringapp_store or google_play. Required.
signed_transactionstringApp Store: the StoreKit 2 signed transaction (jwsRepresentation).
purchase_tokenstringGoogle Play: the purchase token.
product_idstringGoogle Play: the store product id (for a subscription, its id).
package_namestringGoogle Play: the package name, when the connection covers several.

#Subject

FieldTypeWhat it is
end_userstringAn end user's id (Sylphx Auth, or the app's own OIDC issuer). One of the kind group.
customer_organizationstringA customer organization's id. One of the kind group.

#Response

FieldTypeWhat it is
store_purchaseStorePurchaseThe verified purchase.
grant_tokenstringA compact EdDSA JWS (typ money-grant+jwt) the app's server or client verifies offline against Money's published keys; it names the subject, the store product, the transaction, the quantity, and the catalog grants.
already_verifiedboolWhether this transaction was verified before; the record and grant are the same.
customer_subscriptionCustomerSubscriptionThe subscription, for a subscription purchase.

#StorePurchase

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/store_purchases/{store_purchase}.
uidstringspu_<cell><ulid>; never reused. Output only.
metaResourceMetaResource metadata.
subjectSubjectWho it belongs to. Output only.
storestringapp_store or google_play. Output only.
product_idstringThe store product id. Output only.
productstringThe catalog product it sells, when the catalog maps the store product. Output only.
bundle_or_packagestringThe bundle id or package name. Output only.
transaction_idstringThe store's transaction id (App Store transaction id, Play order id). Output only.
original_transaction_idstringThe first transaction of a subscription or restored purchase. Output only.
quantityint32Units bought. Output only.
environmentstringproduction or sandbox. Output only.
statestringpurchased, pending, or revoked. Output only.
purchase_timetimestampWhen the store says it was bought. Output only.
revoke_timetimestampWhen the store refunded or revoked it. Output only.
pricestringThe price the store charged, in minor units of currency, when the store reports it. Output only.
currency_codestringISO 4217 currency of price. Output only.
customer_subscriptionstringThe subscription it belongs to, for a subscription purchase. Output only.

#CustomerSubscription

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/customer_subscriptions/{customer_subscription}.
uidstringcsb_<cell><ulid>; never reused. Output only.
metaResourceMetaResource metadata.
subjectSubjectWho holds it. Output only.
sourcestringstripe, app_store, or google_play. Output only.
processor_subscription_idstringThe processor's subscription id. Output only.
statusstringtrialing, active, past_due, paused, canceled, unpaid, incomplete, or incomplete_expired, as the processor reports it. Output only.
itemsLineItem[]The prices, by lookup key, and their quantities. Output only.
current_period_end_timetimestampThe end of the paid period. Output only.
cancel_at_period_endboolWhether it ends at current_period_end_time instead of renewing. Output only.
trial_end_timetimestampThe end of the trial, when there is one. Output only.
metadatastructThe checkout's metadata. Output only.

#ResourceMeta

FieldTypeWhat it is
generationint64Increases by one on every change to spec. Output only.
etagstringStrong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only.
create_timetimestampWhen the Resource was created. Output only.
update_timetimestampWhen the Resource last changed. Output only.
delete_timetimestampSet while the Resource is being deleted. Output only.
labelsmap<string, string>Caller-writable, indexed labels (AIP-122 label rules).
annotationsmap<string, string>Caller-writable, unindexed annotations.
display_namestringCaller-writable human-readable name.
creatorstringThe principal that created the Resource. Output only.

#Subject

FieldTypeWhat it is
end_userstringAn end user's id (Sylphx Auth, or the app's own OIDC issuer). One of the kind group.
customer_organizationstringA customer organization's id. One of the kind group.

#LineItem

FieldTypeWhat it is
pricestringThe price's lookup key. Required.
quantityint32How many; default 1. Seats for a per-seat or family price.

#Errors

  • UNAUTHENTICATED — No valid key or token was presented.
  • PERMISSION_DENIED — The key lacks the method's permission.
  • INVALID_FIELD — A field failed validation.
  • INVALID_STATE — The Resource is in a state that forbids the call.
  • RESOURCE_IN_USE — The Resource is attached to or held by another Resource, for example a volume attached to a running lease.
  • UNAVAILABLE — The Resource store, the owning service's backend, or the key verifier's snapshot is unavailable; retry after Retry-After.

Every error arrives in the body Errors describes.

#Examples

curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_purchases:verify" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"store":"…","subject":{}}'