Restore Credentials
sreichholf/dreamDroid
Provides knowledge and workflows to implement Android's Restore Credentials feature using the androidx.credentials library.
Server-side purchase verification for in-app products and subscriptions using Google Play Developer API.
$ npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hanamizuki/solopreneur gplay-purchase-verification --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hanamizuki/solopreneur.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/android-dev/gplay-purchase-verification .claude/skills/gplay-purchase-verification && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gplay-purchase-verification" agent skill from https://github.com/hanamizuki/solopreneur/tree/main/skills/android-dev/gplay-purchase-verification into .claude/skills/gplay-purchase-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gplay-purchase-verification", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hanamizuki/solopreneur/tree/main/skills/android-dev/gplay-purchase-verificationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hanamizuki/solopreneur gplay-purchase-verification --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hanamizuki/solopreneur.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/android-dev/gplay-purchase-verification .agents/skills/gplay-purchase-verification && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gplay-purchase-verification" agent skill from https://github.com/hanamizuki/solopreneur/tree/main/skills/android-dev/gplay-purchase-verification into .agents/skills/gplay-purchase-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gplay-purchase-verification", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hanamizuki/solopreneur gplay-purchase-verification --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hanamizuki/solopreneur.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/android-dev/gplay-purchase-verification .cursor/skills/gplay-purchase-verification && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gplay-purchase-verification" agent skill from https://github.com/hanamizuki/solopreneur/tree/main/skills/android-dev/gplay-purchase-verification into .cursor/skills/gplay-purchase-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gplay-purchase-verification", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hanamizuki/solopreneur.git --path skills/android-dev/gplay-purchase-verification--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hanamizuki/solopreneur gplay-purchase-verification --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hanamizuki/solopreneur.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/android-dev/gplay-purchase-verification .gemini/skills/gplay-purchase-verification && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gplay-purchase-verification" agent skill from https://github.com/hanamizuki/solopreneur/tree/main/skills/android-dev/gplay-purchase-verification into .gemini/skills/gplay-purchase-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gplay-purchase-verification", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hanamizuki/solopreneur gplay-purchase-verificationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hanamizuki/solopreneur.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/android-dev/gplay-purchase-verification .github/skills/gplay-purchase-verification && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gplay-purchase-verification" agent skill from https://github.com/hanamizuki/solopreneur/tree/main/skills/android-dev/gplay-purchase-verification into .github/skills/gplay-purchase-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gplay-purchase-verification", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hanamizuki/solopreneur gplay-purchase-verification --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hanamizuki/solopreneur.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/android-dev/gplay-purchase-verification .opencode/skills/gplay-purchase-verification && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gplay-purchase-verification" agent skill from https://github.com/hanamizuki/solopreneur/tree/main/skills/android-dev/gplay-purchase-verification into .opencode/skills/gplay-purchase-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gplay-purchase-verification", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gplay-purchase-verificationServer-side purchase verification for in-app products and subscriptions using Google Play Developer API.
Gplay Purchase Verification is an agent skill from hanamizuki/solopreneur. Server-side purchase verification for in-app products and subscriptions using Google Play Developer API. Use when implementing receipt validation in your backend.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `_VENDOR.md`).
It sits in Backend & APIs, covering Backend development. It works with Android. The repository describes itself as: Skills and agents for solopreneurs — ship, review, debug, and think through problems with AI. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f43f001. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash, json, javascript and python).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
googleapis.comAlso links to:
console.cloud.google.complay.google.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SUBSCRIPTION_TOKENPURCHASE_TOKENTEST_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gplay Purchase Verification loads about 2.9k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 542 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hanamizuki/solopreneur at commit f43f001, republished under its MIT licence (© hanamizuki). 542 words, ~2,869 tokens.
.claude/skills/gplay-purchase-verification/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this skill when you need to verify in-app purchases or subscriptions from your backend server.
Client-side verification can be bypassed. Always verify purchases on your server:
Your backend needs a service account with permissions to verify purchases.
gplay purchases products get \
--package com.example.app \
--product-id premium_upgrade \
--token <PURCHASE_TOKEN>{
"kind": "androidpublisher#productPurchase",
"purchaseTimeMillis": "1706400000000",
"purchaseState": 0,
"consumptionState": 0,
"developerPayload": "user_123",
"orderId": "GPA.1234-5678-9012-34567",
"purchaseType": 0
}0 = Purchased1 = Canceled2 = Pending0 = Yet to be consumed1 = ConsumedAfter verifying, acknowledge the purchase:
gplay purchases products acknowledge \
--package com.example.app \
--product-id premium_upgrade \
--token <PURCHASE_TOKEN>Important: Unacknowledged purchases will be refunded after 3 days.
For consumable items (coins, gems, etc.):
gplay purchases products consume \
--package com.example.app \
--product-id coins_100 \
--token <PURCHASE_TOKEN>Prefer the v2 API. For new integrations use
gplay purchases subscriptionsv2 get(andsubscriptionsv2 cancel/defer/revoke,purchases productsv2 get). The v2SubscriptionPurchaseV2model reflects base plans and offers; the v1 endpoints below still work but are the legacy shape.
gplay purchases subscriptionsv2 get \
--package com.example.app \
--token <SUBSCRIPTION_TOKEN>gplay purchases subscriptions get \
--package com.example.app \
--token <SUBSCRIPTION_TOKEN>{
"kind": "androidpublisher#subscriptionPurchase",
"startTimeMillis": "1706400000000",
"expiryTimeMillis": "1709000000000",
"autoRenewing": true,
"priceCurrencyCode": "USD",
"priceAmountMicros": "4990000",
"paymentState": 1,
"cancelReason": null,
"userCancellationTimeMillis": null,
"orderId": "GPA.1234-5678-9012-34567",
"linkedPurchaseToken": null,
"subscriptionState": 0
}0 = Active1 = Canceled (still valid until expiry)2 = In grace period3 = On hold (payment failed, retrying)4 = Paused5 = Expired0 = Payment pending1 = Payment received2 = Free trial3 = Pending deferred upgrade/downgradeconst { google } = require('googleapis');
async function verifyPurchase(packageName, productId, token) {
const auth = new google.auth.GoogleAuth({
keyFile: '/path/to/service-account.json',
scopes: ['https://www.googleapis.com/auth/androidpublisher'],
});
const androidpublisher = google.androidpublisher({
version: 'v3',
auth: await auth.getClient(),
});
const result = await androidpublisher.purchases.products.get({
packageName: packageName,
productId: productId,
token: token,
});
return result.data;
}
// Endpoint
app.post('/verify-purchase', async (req, res) => {
const { packageName, productId, token } = req.body;
try {
const purchase = await verifyPurchase(packageName, productId, token);
if (purchase.purchaseState === 0) {
// Purchase is valid
// Grant access to user
// Acknowledge purchase
res.json({ valid: true, purchase });
} else {
res.json({ valid: false });
}
} catch (error) {
res.status(400).json({ error: error.message });
}
});from google.oauth2 import service_account
from googleapiclient.discovery import build
SCOPES = ['https://www.googleapis.com/auth/androidpublisher']
SERVICE_ACCOUNT_FILE = '/path/to/service-account.json'
credentials = service_account.Credentials.from_service_account_file(
SERVICE_ACCOUNT_FILE, scopes=SCOPES)
androidpublisher = build('androidpublisher', 'v3', credentials=credentials)
@app.route('/verify-purchase', methods=['POST'])
def verify_purchase():
data = request.json
package_name = data['packageName']
product_id = data['productId']
token = data['token']
try:
result = androidpublisher.purchases().products().get(
packageName=package_name,
productId=product_id,
token=token
).execute()
if result['purchaseState'] == 0:
# Purchase is valid
return jsonify({'valid': True, 'purchase': result})
else:
return jsonify({'valid': False})
except Exception as e:
return jsonify({'error': str(e)}), 400Set up Pub/Sub to receive subscription events:
gplay can scaffold and decode RTDN without hand-writing the base64/JSON parsing:
# Print the Pub/Sub topic + Play Console setup steps
gplay rtdn setup --package com.example.app
# Decode an RTDN payload into readable JSON (notification type, token, etc.)
# Accepts a full Pub/Sub envelope (message.data is base64) or the raw notification.
gplay rtdn decode --data '{"message":{"data":"<BASE64_DATA>"}}'
cat payload.json | gplay rtdn decode --file -from google.cloud import pubsub_v1
subscriber = pubsub_v1.SubscriberClient()
subscription_path = subscriber.subscription_path(project_id, subscription_id)
def callback(message):
data = json.loads(message.data)
if 'subscriptionNotification' in data:
notification = data['subscriptionNotification']
notification_type = notification['notificationType']
purchase_token = notification['purchaseToken']
# Handle different events
if notification_type == 1: # SUBSCRIPTION_RECOVERED
# Subscription was recovered from account hold
pass
elif notification_type == 2: # SUBSCRIPTION_RENEWED
# Subscription renewed successfully
pass
elif notification_type == 3: # SUBSCRIPTION_CANCELED
# User canceled subscription
pass
elif notification_type == 4: # SUBSCRIPTION_PURCHASED
# New subscription purchase
pass
elif notification_type == 7: # SUBSCRIPTION_EXPIRED
# Subscription expired
pass
elif notification_type == 10: # SUBSCRIPTION_PAUSED
# Subscription paused
pass
elif notification_type == 12: # SUBSCRIPTION_REVOKED
# Subscription revoked (refunded)
pass
message.ack()
subscriber.subscribe(subscription_path, callback=callback)gplay purchases subscriptions cancel \
--package com.example.app \
--token <SUBSCRIPTION_TOKEN>gplay purchases subscriptions defer \
--package com.example.app \
--token <SUBSCRIPTION_TOKEN> \
--json @defer.json{
"deferralInfo": {
"expectedExpiryTimeMillis": "1709000000000"
}
}gplay purchases subscriptions revoke \
--package com.example.app \
--token <SUBSCRIPTION_TOKEN>Get list of refunded/canceled purchases:
gplay purchases voided list \
--package com.example.app \
--start-time 1706400000000 \
--end-time 1709000000000Remove entitlements for these purchases on your backend.
gplay orders get \
--package com.example.app \
--order-id GPA.1234-5678-9012-34567gplay orders batch-get \
--package com.example.app \
--order-ids "GPA.1234,GPA.5678,GPA.9012"orders refund is a destructive write and requires --confirm — without it the
command refuses to run.
gplay orders refund \
--package com.example.app \
--order-id GPA.1234-5678-9012-34567 \
--revoke \ # Also revoke entitlement/access
--confirm # Required — refund is irreversible401 Unauthorized - Service account not authorized404 Not Found - Purchase token invalid or expired410 Gone - Purchase was refunded/canceledasync function verifyWithRetry(packageName, productId, token, retries = 3) {
for (let i = 0; i < retries; i++) {
try {
return await verifyPurchase(packageName, productId, token);
} catch (error) {
if (error.code === 404 || error.code === 410) {
throw error; // Don't retry if purchase is invalid
}
if (i === retries - 1) throw error;
await new Promise(resolve => setTimeout(resolve, 1000 * (i + 1)));
}
}
}Use Google Play's test accounts to make test purchases without charging real money.
# Verify test purchase
gplay purchases products get \
--package com.example.app \
--product-id android.test.purchased \
--token <TEST_TOKEN>Track these metrics:
Use this data to improve your monetization strategy.
© hanamizuki, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/android-dev/gplay-purchase-verification of hanamizuki/solopreneur.
Open the folder on GitHubat commit f43f001
Gplay Purchase Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gplay Purchase Verification this skillhanamizuki/solopreneur | 152 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Restore Credentialssreichholf/dreamDroid | 116 | 2 repos | ~6.3k | Automated safety check: Pass | GPL-3.0 | |
| Firebase Messagingevanca/flutter-ai-rules | 650 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Mobile Checkouthashgraph-online/awesome-codex-plugins | 1.3k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT |
sreichholf/dreamDroid
Provides knowledge and workflows to implement Android's Restore Credentials feature using the androidx.credentials library.
evanca/flutter-ai-rules
A skill your agent uses when setting up Firebase Cloud Messaging, managing permissions and tokens, handling background/foreground notification taps, or dispatching messages server-side (HTTP v1).
hashgraph-online/awesome-codex-plugins
Dodo Payments in-app checkout for React Native, Flutter, native iOS, and Android using SFSafariViewController or Chrome Custom Tabs.
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
diet103/claude-code-infrastructure-showcase
Sets layered architecture and coding rules for Node.js, Express and TypeScript microservices, covering routes, controllers, services, repositories, Prisma, Sentry and Zod.
hanamizuki/solopreneur
Create an interactive HTML preview of any proposal, plan, idea, doc, brief, or spec and land it in the browsable local Preview Library by default (opens under file:// with a catalog sidebar and…
hanamizuki/solopreneur
A skill your agent uses when building iOS/macOS apps with SwiftUI — covers localization (String Catalogs), date/time formatting, JSON date decoding, Previews, state management, sheet/navigation…
hanamizuki/solopreneur
LinkedIn organic growth consultant — diagnoses profiles, discusses goals, and co-creates a personalized 90-day growth plan.
hanamizuki/solopreneur
Switch perspectives to think through problems using the mental models of ten iconic thinkers: Elon Musk, Richard Feynman, Charlie Munger, Naval Ravikant, Steve Jobs, Nassim Taleb, Ilya Sutskever…
hanamizuki/solopreneur
Create brand-aware presentations using frontend-slides or reveal.js.
hanamizuki/solopreneur
X/Twitter growth consultant — diagnoses profiles, discusses goals, and co-creates a personalized growth plan.
Works with
Categories
Server-side purchase verification for in-app products and subscriptions using Google Play Developer API. Gplay Purchase Verification is an agent skill from hanamizuki/solopreneur. Server-side purchase verification for in-app products and subscriptions using Google Play Developer API.
Gplay Purchase Verification fits situations like: implementing receipt validation in your backend; tasks that involve Backend development.
Run `npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a claude-code`. Or copy the skill folder (skills/android-dev/gplay-purchase-verification in hanamizuki/solopreneur) into .claude/skills/gplay-purchase-verification in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a codex`. Or copy the skill folder (skills/android-dev/gplay-purchase-verification in hanamizuki/solopreneur) into .agents/skills/gplay-purchase-verification in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hanamizuki/solopreneur --skill gplay-purchase-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gplay-purchase-verification, .gemini/skills/gplay-purchase-verification, .github/skills/gplay-purchase-verification and .opencode/skills/gplay-purchase-verification in your project.
Going by SKILL.md and its folder, Gplay Purchase Verification needs credentials named SUBSCRIPTION_TOKEN, PURCHASE_TOKEN and TEST_TOKEN. Our summary lists: Python 3; Node.js; A credential in PURCHASE_TOKEN; A credential in SUBSCRIPTION_TOKEN.
SKILL.md names 3 domains. In commands or code: googleapis.com; the agent is likely to contact it when it follows the instructions. As links in the text: console.cloud.google.com and play.google.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Gplay Purchase Verification is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Gplay Purchase Verification: Restore Credentials (sreichholf/dreamDroid, 116 stars), Firebase Messaging (evanca/flutter-ai-rules, 650 stars), Mobile Checkout (hashgraph-online/awesome-codex-plugins, 1.3k stars) and Configuring Horizon (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hanamizuki (a GitHub user) maintains it in hanamizuki/solopreneur, which has 152 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on September 26, 2026.
Source: hanamizuki/solopreneur on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.