Skip to content
Back to skills

In App Purchases

ASecurity

Implement in-app purchases and subscriptions across iOS, Android, and Flutter with RevenueCat, paywalls, receipt validation, and subscription analytics.

  • 7 stars
  • 0 votes
  • 0 copies
  • 4 views
  • Added June 7, 2026
developmentrustgotestinggitapibackend

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 10 files and shows the line behind each finding

Scanned June 7, 2026

npx -y skills add modbender/skill-library-mcp --skill in-app-purchases --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of In App Purchases?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for In App Purchases
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-in-app-purchases/badge)](https://www.skillsdirectory.com/skills/modbender-in-app-purchases)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: In-App Purchases
slug: in-app-purchases
version: 1.0.0
description: Implement in-app purchases and subscriptions across iOS, Android, and Flutter with RevenueCat, paywalls, receipt validation, and subscription analytics.
metadata: {"clawdbot":{"emoji":"πŸ’³","requires":{"bins":[]},"os":["linux","darwin","win32"]}}
---

## When to Use

User needs to implement in-app purchases, subscriptions, paywalls, or monetization flows. Agent handles native APIs (StoreKit 2, Google Play Billing), cross-platform SDKs (RevenueCat, Adapty, Qonversion), paywall design, server verification, and subscription analytics.

## Quick Reference

| Topic | File |
|-------|------|
| iOS StoreKit 2 | `storekit.md` |
| Android Billing | `google-play.md` |
| Flutter packages | `flutter.md` |
| RevenueCat SDK | `revenuecat.md` |
| Platform comparison | `platforms.md` |
| Server verification | `server.md` |
| Paywall design | `paywalls.md` |
| Subscription metrics | `analytics.md` |
| Testing & sandbox | `testing.md` |

## Core Rules

### 1. Choose Your Architecture
| Approach | When to Use | Tradeoff |
|----------|-------------|----------|
| Native only | Single platform, full control | More code, no cross-platform sync |
| RevenueCat/Adapty | Cross-platform, fast launch | 1-2% fee, dependency |
| Hybrid | Native + own backend | Full control, more work |

### 2. Platform SDKs (Managed)
| Platform | Pricing | Best For |
|----------|---------|----------|
| RevenueCat | Free <$2.5k MTR, then 1% | Most apps, best docs |
| Adapty | Free <$10k MTR, then 0.6% | Cost-conscious, A/B paywalls |
| Qonversion | Free <$10k MTR, then 3% | Simple setup |
| Superwall | Paywall-focused | Paywall A/B only |
| Glassfy | Free <$10k, then 0.5% | Budget option |

### 3. Product Types
| Type | iOS | Android | Use Case |
|------|-----|---------|----------|
| Consumable | βœ… | βœ… | Credits, coins, lives |
| Non-consumable | βœ… | βœ… | Unlock feature forever |
| Auto-renewable | βœ… | βœ… | Subscriptions |
| Non-renewing | βœ… | ❌ | Season pass, time-limited |

### 4. Server Verification is Non-Negotiable
Never trust client-side validation alone:
- iOS: App Store Server API with JWS verification
- Android: Google Play Developer API
- RevenueCat: Webhooks + REST API

### 5. Handle All Transaction States
| State | Action |
|-------|--------|
| Purchased | Verify β†’ grant β†’ finish |
| Pending | Wait, show pending UI |
| Failed | Show error, don't grant |
| Deferred | Wait for parental approval |
| Refunded | Revoke immediately |
| Grace period | Limited access, prompt payment |
| Billing retry | Maintain access during retry |

### 6. Subscription Lifecycle Events
Must handle all of these (native or via webhooks):
- INITIAL_PURCHASE β†’ grant access
- RENEWAL β†’ extend access
- CANCELLATION β†’ mark will-expire
- EXPIRATION β†’ revoke access
- BILLING_ISSUE β†’ prompt to update payment
- GRACE_PERIOD β†’ limited access window
- PRICE_INCREASE β†’ consent required (iOS)
- REFUND β†’ revoke + flag user
- UPGRADE/DOWNGRADE β†’ prorate

### 7. Restore Purchases Always
Required by App Store guidelines:
- Prominent restore button
- Works for logged-out users
- Handles family sharing (iOS)
- Cross-device sync

### 8. Paywall Best Practices
See `paywalls.md` for detailed patterns:
- Show value before price
- Anchor pricing (3 options, highlight middle)
- Free trial prominent
- Social proof if available
- A/B test everything

### 9. Testing Strategy
| Environment | iOS | Android |
|-------------|-----|---------|
| Dev/Debug | StoreKit Config file | License testers |
| Sandbox | Sandbox accounts | Internal testing |
| Production | Real accounts | Production |

Sandbox subscription times:
- 1 week β†’ 3 minutes
- 1 month β†’ 5 minutes
- 1 year β†’ 1 hour

### 10. App Store Guidelines
- No external payment links (anti-steering)
- Must use IAP for digital goods
- Physical goods/services can use Stripe
- Reader apps have exceptions
- 15-30% commission applies

## Common Traps

- Testing with real money β†’ use sandbox/test accounts
- Not finishing transactions β†’ auto-refund (Android 3 days)
- Hardcoding prices β†’ always fetch from store (regional pricing)
- Missing transaction observer β†’ lose purchases made outside app
- No server verification β†’ trivially bypassable
- Ignoring grace period β†’ users churn when they could recover
- Poor paywall UX β†’ kills conversion regardless of price
- Not tracking metrics β†’ can't optimize what you don't measure
- Forgetting restore button β†’ App Store rejection
- Not handling family sharing β†’ confused users

Files in this skill

  • SKILL.md4.6 KB
  • analytics.md6.4 KB
  • flutter.md5 KB
  • google-play.md5.3 KB
  • paywalls.md7.4 KB
  • platforms.md5.5 KB
  • revenuecat.md7.5 KB
  • server.md6.2 KB
  • storekit.md3.9 KB
  • testing.md8.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…