Agent skill

Gplay Purchase Verification

by hanamizuki in hanamizuki/solopreneur

Server-side purchase verification for in-app products and subscriptions using Google Play Developer API.

MITAuto-check passedBackend & APIs

Install Gplay Purchase Verification

skills CLI
$ npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hanamizuki/solopreneur gplay-purchase-verification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hanamizuki/solopreneur.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/android-dev/gplay-purchase-verification .claude/skills/gplay-purchase-verification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gplay-purchase-verification
GitHub stars
152
Token cost
~2.9k tokens
SKILL.md length
542 words
Files
2
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

Server-side purchase verification for in-app products and subscriptions using Google Play Developer API.

  • Works in 4 steps: Go to Google Cloud Console → Create service account → Grant "Service Account User" role → …
  • Implementing receipt validation in your backend
  • SKILL.md covers Why Verify Purchases…, Authentication Setup, Verify In-App Product Purchase and Acknowledge Purchase, plus 7 more sections
  • Reaches googleapis.com; needs SUBSCRIPTION_TOKEN and PURCHASE_TOKEN

What it does

Gplay Purchase Verification is an agent skill from hanamizuki/solopreneur. Server-side purchase verification for in-app products and subscriptions using Google Play Developer API. Use when implementing receipt validation in your backend.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `_VENDOR.md`).

It sits in Backend & APIs, covering Backend development. It works with Android. The repository describes itself as: Skills and agents for solopreneurs — ship, review, debug, and think through problems with AI. The licence is MIT.

When your agent uses it

  • Implementing receipt validation in your backend
  • Tasks that involve Backend development

Example prompts

  • “/gplay-purchase-verification”

Requirements

  • Python 3
  • Node.js
  • A credential in PURCHASE_TOKEN
  • A credential in SUBSCRIPTION_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Go to Google Cloud Console
  2. Create service account
  3. Grant "Service Account User" role
  4. Download JSON key

What it can do on your machine

Read from SKILL.md and the folder at commit f43f001. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash, json, javascript and python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • googleapis.com

    Also links to:

    • console.cloud.google.com
    • play.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SUBSCRIPTION_TOKEN
    • PURCHASE_TOKEN
    • TEST_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gplay Purchase Verification loads about 2.9k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 542 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hanamizuki/solopreneur at commit f43f001, republished under its MIT licence (© hanamizuki). 542 words, ~2,869 tokens.

Download SKILL.mdSave it as .claude/skills/gplay-purchase-verification/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
gplay-purchase-verification
description
Server-side purchase verification for in-app products and subscriptions using Google Play Developer API. Use when implementing receipt validation in your backend.

Purchase Verification for Google Play

Use this skill when you need to verify in-app purchases or subscriptions from your backend server.

Why Verify Purchases Server-Side?

Client-side verification can be bypassed. Always verify purchases on your server:

  • Prevent fraud and piracy
  • Ensure user actually paid
  • Check subscription status
  • Handle refunds and cancellations

Authentication Setup

Your backend needs a service account with permissions to verify purchases.

Create service account
  1. Go to Google Cloud Console
  2. Create service account
  3. Grant "Service Account User" role
  4. Download JSON key
Grant API access
  1. Go to Play Console
  2. Users & Permissions → Service Accounts
  3. Grant service account access to your apps

Verify In-App Product Purchase

Get purchase details
bash
gplay purchases products get \
  --package com.example.app \
  --product-id premium_upgrade \
  --token <PURCHASE_TOKEN>
Response
json
{
  "kind": "androidpublisher#productPurchase",
  "purchaseTimeMillis": "1706400000000",
  "purchaseState": 0,
  "consumptionState": 0,
  "developerPayload": "user_123",
  "orderId": "GPA.1234-5678-9012-34567",
  "purchaseType": 0
}
Purchase states
  • 0 = Purchased
  • 1 = Canceled
  • 2 = Pending
Consumption states
  • 0 = Yet to be consumed
  • 1 = Consumed

Acknowledge Purchase

After verifying, acknowledge the purchase:

bash
gplay purchases products acknowledge \
  --package com.example.app \
  --product-id premium_upgrade \
  --token <PURCHASE_TOKEN>

Important: Unacknowledged purchases will be refunded after 3 days.

Consume Purchase (for consumables)

For consumable items (coins, gems, etc.):

bash
gplay purchases products consume \
  --package com.example.app \
  --product-id coins_100 \
  --token <PURCHASE_TOKEN>

Verify Subscription

Prefer the v2 API. For new integrations use gplay purchases subscriptionsv2 get (and subscriptionsv2 cancel/defer/revoke, purchases productsv2 get). The v2 SubscriptionPurchaseV2 model reflects base plans and offers; the v1 endpoints below still work but are the legacy shape.

bash
gplay purchases subscriptionsv2 get \
  --package com.example.app \
  --token <SUBSCRIPTION_TOKEN>
Get subscription details (v1, legacy)
bash
gplay purchases subscriptions get \
  --package com.example.app \
  --token <SUBSCRIPTION_TOKEN>
Response
json
{
  "kind": "androidpublisher#subscriptionPurchase",
  "startTimeMillis": "1706400000000",
  "expiryTimeMillis": "1709000000000",
  "autoRenewing": true,
  "priceCurrencyCode": "USD",
  "priceAmountMicros": "4990000",
  "paymentState": 1,
  "cancelReason": null,
  "userCancellationTimeMillis": null,
  "orderId": "GPA.1234-5678-9012-34567",
  "linkedPurchaseToken": null,
  "subscriptionState": 0
}
Subscription states
  • 0 = Active
  • 1 = Canceled (still valid until expiry)
  • 2 = In grace period
  • 3 = On hold (payment failed, retrying)
  • 4 = Paused
  • 5 = Expired
Payment states
  • 0 = Payment pending
  • 1 = Payment received
  • 2 = Free trial
  • 3 = Pending deferred upgrade/downgrade

Backend Implementation Example

Node.js/Express
javascript
const { google } = require('googleapis');

async function verifyPurchase(packageName, productId, token) {
  const auth = new google.auth.GoogleAuth({
    keyFile: '/path/to/service-account.json',
    scopes: ['https://www.googleapis.com/auth/androidpublisher'],
  });

  const androidpublisher = google.androidpublisher({
    version: 'v3',
    auth: await auth.getClient(),
  });

  const result = await androidpublisher.purchases.products.get({
    packageName: packageName,
    productId: productId,
    token: token,
  });

  return result.data;
}

// Endpoint
app.post('/verify-purchase', async (req, res) => {
  const { packageName, productId, token } = req.body;

  try {
    const purchase = await verifyPurchase(packageName, productId, token);

    if (purchase.purchaseState === 0) {
      // Purchase is valid
      // Grant access to user
      // Acknowledge purchase
      res.json({ valid: true, purchase });
    } else {
      res.json({ valid: false });
    }
  } catch (error) {
    res.status(400).json({ error: error.message });
  }
});
Python/Flask
python
from google.oauth2 import service_account
from googleapiclient.discovery import build

SCOPES = ['https://www.googleapis.com/auth/androidpublisher']
SERVICE_ACCOUNT_FILE = '/path/to/service-account.json'

credentials = service_account.Credentials.from_service_account_file(
    SERVICE_ACCOUNT_FILE, scopes=SCOPES)

androidpublisher = build('androidpublisher', 'v3', credentials=credentials)

@app.route('/verify-purchase', methods=['POST'])
def verify_purchase():
    data = request.json
    package_name = data['packageName']
    product_id = data['productId']
    token = data['token']

    try:
        result = androidpublisher.purchases().products().get(
            packageName=package_name,
            productId=product_id,
            token=token
        ).execute()

        if result['purchaseState'] == 0:
            # Purchase is valid
            return jsonify({'valid': True, 'purchase': result})
        else:
            return jsonify({'valid': False})

    except Exception as e:
        return jsonify({'error': str(e)}), 400

Handle Subscription Events

Real-time Developer Notifications (RTDN)

Set up Pub/Sub to receive subscription events:

  1. Create Pub/Sub topic in Google Cloud Console
  2. Configure in Play Console:
    • Monetization Setup → Real-time developer notifications
    • Enter topic name

gplay can scaffold and decode RTDN without hand-writing the base64/JSON parsing:

bash
# Print the Pub/Sub topic + Play Console setup steps
gplay rtdn setup --package com.example.app

# Decode an RTDN payload into readable JSON (notification type, token, etc.)
# Accepts a full Pub/Sub envelope (message.data is base64) or the raw notification.
gplay rtdn decode --data '{"message":{"data":"<BASE64_DATA>"}}'
cat payload.json | gplay rtdn decode --file -
  1. Subscribe to events:
python
from google.cloud import pubsub_v1

subscriber = pubsub_v1.SubscriberClient()
subscription_path = subscriber.subscription_path(project_id, subscription_id)

def callback(message):
    data = json.loads(message.data)

    if 'subscriptionNotification' in data:
        notification = data['subscriptionNotification']
        notification_type = notification['notificationType']
        purchase_token = notification['purchaseToken']

        # Handle different events
        if notification_type == 1:  # SUBSCRIPTION_RECOVERED
            # Subscription was recovered from account hold
            pass
        elif notification_type == 2:  # SUBSCRIPTION_RENEWED
            # Subscription renewed successfully
            pass
        elif notification_type == 3:  # SUBSCRIPTION_CANCELED
            # User canceled subscription
            pass
        elif notification_type == 4:  # SUBSCRIPTION_PURCHASED
            # New subscription purchase
            pass
        elif notification_type == 7:  # SUBSCRIPTION_EXPIRED
            # Subscription expired
            pass
        elif notification_type == 10:  # SUBSCRIPTION_PAUSED
            # Subscription paused
            pass
        elif notification_type == 12:  # SUBSCRIPTION_REVOKED
            # Subscription revoked (refunded)
            pass

    message.ack()

subscriber.subscribe(subscription_path, callback=callback)

Subscription Management

Cancel subscription
bash
gplay purchases subscriptions cancel \
  --package com.example.app \
  --token <SUBSCRIPTION_TOKEN>
Defer subscription
bash
gplay purchases subscriptions defer \
  --package com.example.app \
  --token <SUBSCRIPTION_TOKEN> \
  --json @defer.json
defer.json
json
{
  "deferralInfo": {
    "expectedExpiryTimeMillis": "1709000000000"
  }
}
Revoke subscription (refund)
bash
gplay purchases subscriptions revoke \
  --package com.example.app \
  --token <SUBSCRIPTION_TOKEN>

Check Voided Purchases

Get list of refunded/canceled purchases:

bash
gplay purchases voided list \
  --package com.example.app \
  --start-time 1706400000000 \
  --end-time 1709000000000

Remove entitlements for these purchases on your backend.

Show full SKILL.md (212 more words)Show less

Order Information

Get order details
bash
gplay orders get \
  --package com.example.app \
  --order-id GPA.1234-5678-9012-34567
Batch get orders
bash
gplay orders batch-get \
  --package com.example.app \
  --order-ids "GPA.1234,GPA.5678,GPA.9012"
Refund order

orders refund is a destructive write and requires --confirm — without it the command refuses to run.

bash
gplay orders refund \
  --package com.example.app \
  --order-id GPA.1234-5678-9012-34567 \
  --revoke \    # Also revoke entitlement/access
  --confirm     # Required — refund is irreversible

Security Best Practices

DO:
  • ✅ Always verify on server, never trust client
  • ✅ Store purchase tokens securely
  • ✅ Acknowledge purchases within 3 days
  • ✅ Handle refunds and cancellations
  • ✅ Use HTTPS for all API calls
  • ✅ Rate limit your verification endpoint
  • ✅ Log all verification attempts
DON'T:
  • ❌ Verify purchases only on client
  • ❌ Expose service account credentials
  • ❌ Skip acknowledging purchases
  • ❌ Grant access before verification
  • ❌ Ignore voided purchases
  • ❌ Store credit card info (PCI compliance)

Common Verification Flow

  1. User makes purchase in app
  2. App sends purchase token to your server
  3. Server verifies with Google Play API
  4. Server acknowledges purchase (if valid)
  5. Server grants access/content to user
  6. Server stores purchase token for future checks
  7. Server listens for RTDN events (cancellations, renewals)

Error Handling

Common errors
  • 401 Unauthorized - Service account not authorized
  • 404 Not Found - Purchase token invalid or expired
  • 410 Gone - Purchase was refunded/canceled
Retry logic
javascript
async function verifyWithRetry(packageName, productId, token, retries = 3) {
  for (let i = 0; i < retries; i++) {
    try {
      return await verifyPurchase(packageName, productId, token);
    } catch (error) {
      if (error.code === 404 || error.code === 410) {
        throw error; // Don't retry if purchase is invalid
      }
      if (i === retries - 1) throw error;
      await new Promise(resolve => setTimeout(resolve, 1000 * (i + 1)));
    }
  }
}

Testing

Test purchases

Use Google Play's test accounts to make test purchases without charging real money.

Test verification
bash
# Verify test purchase
gplay purchases products get \
  --package com.example.app \
  --product-id android.test.purchased \
  --token <TEST_TOKEN>

Monitoring

Track these metrics:

  • Purchase verification success rate
  • Acknowledgment rate
  • Refund rate
  • Subscription churn rate
  • Failed payment rate

Use this data to improve your monetization strategy.

© hanamizuki, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/android-dev/gplay-purchase-verification of hanamizuki/solopreneur.

  • SKILL.md
  • _VENDOR.md

Open the folder on GitHubat commit f43f001

Compare with similar skills

Gplay Purchase Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gplay Purchase Verification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gplay Purchase Verification this skillhanamizuki/solopreneur152—~2.9kAutomated safety check: PassMIT
Restore Credentialssreichholf/dreamDroid1162 repos~6.3kAutomated safety check: PassGPL-3.0
Firebase Messagingevanca/flutter-ai-rules650—~3.2kAutomated safety check: PassMIT
Mobile Checkouthashgraph-online/awesome-codex-plugins1.3k—~2.5kAutomated safety check: PassApache-2.0
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Restore Credentials

    sreichholf/dreamDroid

    Provides knowledge and workflows to implement Android's Restore Credentials feature using the androidx.credentials library.

    116 GitHub starsUsed in 2 repos~6.3k tokens
    Backend & APIsAuto-check passed
  • Firebase Messaging

    evanca/flutter-ai-rules

    A skill your agent uses when setting up Firebase Cloud Messaging, managing permissions and tokens, handling background/foreground notification taps, or dispatching messages server-side (HTTP v1).

    650 GitHub stars~3.2k tokensUpdated 27 days ago
    MobileAuto-check passed
  • Mobile Checkout

    hashgraph-online/awesome-codex-plugins

    Dodo Payments in-app checkout for React Native, Flutter, native iOS, and Android using SFSafariViewController or Chrome Custom Tabs.

    1.3k GitHub stars~2.5k tokensUpdated yesterday
    MobileAuto-check passed
  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Node Backend Development Guidelines

    diet103/claude-code-infrastructure-showcase

    Sets layered architecture and coding rules for Node.js, Express and TypeScript microservices, covering routes, controllers, services, repositories, Prisma, Sentry and Zod.

    10k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed

More from hanamizuki/solopreneur

All 31 skills in this repo
  • Preview

    hanamizuki/solopreneur

    Create an interactive HTML preview of any proposal, plan, idea, doc, brief, or spec and land it in the browsable local Preview Library by default (opens under file:// with a catalog sidebar and…

    152 GitHub stars~5.2k tokensUpdated 14 days ago
    Auto-check passed
  • iOS Patterns

    hanamizuki/solopreneur

    A skill your agent uses when building iOS/macOS apps with SwiftUI — covers localization (String Catalogs), date/time formatting, JSON date decoding, Previews, state management, sheet/navigation…

    152 GitHub stars~2.3k tokensUpdated 14 days ago
    Auto-check: notes
  • Linkedin Growth

    hanamizuki/solopreneur

    LinkedIn organic growth consultant — diagnoses profiles, discusses goals, and co-creates a personalized 90-day growth plan.

    152 GitHub stars~3.7k tokensUpdated 14 days ago
    Auto-check passed
  • Perspective

    hanamizuki/solopreneur

    Switch perspectives to think through problems using the mental models of ten iconic thinkers: Elon Musk, Richard Feynman, Charlie Munger, Naval Ravikant, Steve Jobs, Nassim Taleb, Ilya Sutskever…

    152 GitHub stars~971 tokensUpdated 14 days ago
    Auto-check passed
  • Slide Design

    hanamizuki/solopreneur

    Create brand-aware presentations using frontend-slides or reveal.js.

    152 GitHub stars~3.9k tokensUpdated 14 days ago
    Auto-check passed
  • X Growth

    hanamizuki/solopreneur

    X/Twitter growth consultant — diagnoses profiles, discusses goals, and co-creates a personalized growth plan.

    152 GitHub stars~3.8k tokensUpdated 14 days ago
    Auto-check passed

Works with

Categories

Questions about Gplay Purchase Verification

What does Gplay Purchase Verification do?

Server-side purchase verification for in-app products and subscriptions using Google Play Developer API. Gplay Purchase Verification is an agent skill from hanamizuki/solopreneur. Server-side purchase verification for in-app products and subscriptions using Google Play Developer API.

When should I use Gplay Purchase Verification?

Gplay Purchase Verification fits situations like: implementing receipt validation in your backend; tasks that involve Backend development.

How do I install Gplay Purchase Verification in Claude Code?

Run `npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a claude-code`. Or copy the skill folder (skills/android-dev/gplay-purchase-verification in hanamizuki/solopreneur) into .claude/skills/gplay-purchase-verification in your project. Claude Code loads it when a task matches its description.

How do I install Gplay Purchase Verification in Codex?

Run `npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a codex`. Or copy the skill folder (skills/android-dev/gplay-purchase-verification in hanamizuki/solopreneur) into .agents/skills/gplay-purchase-verification in your project. Codex loads it when a task matches its description.

Can I use Gplay Purchase Verification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gplay-purchase-verification, .gemini/skills/gplay-purchase-verification, .github/skills/gplay-purchase-verification and .opencode/skills/gplay-purchase-verification in your project.

What does Gplay Purchase Verification need to run?

Going by SKILL.md and its folder, Gplay Purchase Verification needs credentials named SUBSCRIPTION_TOKEN, PURCHASE_TOKEN and TEST_TOKEN. Our summary lists: Python 3; Node.js; A credential in PURCHASE_TOKEN; A credential in SUBSCRIPTION_TOKEN.

Does Gplay Purchase Verification access the network?

SKILL.md names 3 domains. In commands or code: googleapis.com; the agent is likely to contact it when it follows the instructions. As links in the text: console.cloud.google.com and play.google.com. This is read from the text; nothing was executed.

Is Gplay Purchase Verification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gplay Purchase Verification use?

Gplay Purchase Verification is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gplay Purchase Verification use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gplay Purchase Verification?

Skills that share tags, products or a category with Gplay Purchase Verification: Restore Credentials (sreichholf/dreamDroid, 116 stars), Firebase Messaging (evanca/flutter-ai-rules, 650 stars), Mobile Checkout (hashgraph-online/awesome-codex-plugins, 1.3k stars) and Configuring Horizon (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gplay Purchase Verification?

hanamizuki (a GitHub user) maintains it in hanamizuki/solopreneur, which has 152 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on September 26, 2026.

Source: hanamizuki/solopreneur on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.