Dodo Payments in-app checkout for React Native, Flutter, native iOS, and Android using SFSafariViewController or Chrome Custom Tabs.

Apache-2.0Auto-check passedMobile

Install Mobile Checkout

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill mobile-checkout -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins mobile-checkout --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dodopayments/dodo-agent-plugin/skills/mobile-checkout .claude/skills/mobile-checkout && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mobile-checkout
GitHub stars
1.3k
Token cost
~2.5k tokens
SKILL.md length
692 words
Files
5 (incl. references)
Skills in repo
714
Repo updated
First seen
Licence
Apache-2.0

At a glance

Dodo Payments in-app checkout for React Native, Flutter, native iOS, and Android using SFSafariViewController or Chrome Custom Tabs.

  • Works in 5 steps: Backend: Create a checkout session via… → Mobile app: Call the platform-specific… → Browser context: The SDK opens the URL… → …
  • A mobile app must open a backend-created checkout session
  • SKILL.md covers When to use this skill, Core principle: Backend…, Architecture overview and React Native (Turbo Module), plus 9 more sections
  • Needs DODO_PAYMENTS_API_KEY

What it does

Mobile Checkout is an agent skill from hashgraph-online/awesome-codex-plugins. Dodo Payments in-app checkout for React Native, Flutter, native iOS, and Android using SFSafariViewController or Chrome Custom Tabs. Use when a mobile app must open a backend-created checkout session, handle deep link or custom URL scheme returns, recover abandoned checkouts, and verify payment server-side before unlocking access.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/android.md`, `references/flutter.md` and `references/ios.md`).

It sits in Mobile, covering Cross-platform mobile apps and Backend development. It works with iOS, Flutter, Android and React Native. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • A mobile app must open a backend-created checkout session
  • Handle deep link
  • Custom URL scheme returns
  • Recover abandoned checkouts

Example prompts

  • “/mobile-checkout”

Requirements

  • A credential in DODO_PAYMENTS_API_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Backend: Create a checkout session via client.checkoutSessions.create(...) and return the checkout_url to your mobile app.
  2. Mobile app: Call the platform-specific SDK with the checkout URL and a registered return URL scheme.
  3. Browser context: The SDK opens the URL in a secure system browser: SFSafariViewController on iOS and Chrome Custom Tabs on Android.
  4. Return: After payment, the browser navigates to your return URL. The SDK captures the result and passes it to your app.
  5. Verification: Query the checkout session or listen for a webhook to confirm the payment before granting access.

What it can do on your machine

Read from SKILL.md and the folder at commit 9e7b281. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.dodopayments.com
    • pub.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DODO_PAYMENTS_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mobile Checkout loads about 2.5k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 87 tokens; SKILL.md has 692 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 9e7b281, republished under its Apache-2.0 licence (© hashgraph-online). 692 words, ~2,453 tokens.

Download SKILL.mdSave it as .claude/skills/mobile-checkout/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
mobile-checkout
description
Dodo Payments in-app checkout for React Native, Flutter, native iOS, and Android using SFSafariViewController or Chrome Custom Tabs. Use when a mobile app must open a backend-created checkout session, handle deep link or custom URL scheme returns, recover abandoned checkouts, and verify payment server-side before unlocking access.

Mobile In-App Checkout

This skill covers integrating Dodo Payments hosted checkout into native and cross-platform mobile apps using secure system browser contexts.

When to use this skill

  • Building a React Native app with Turbo Module checkout integration
  • Adding checkout to a Flutter app via native bridge
  • Implementing native iOS or Android checkout with secure browser contexts
  • Registering custom URL schemes and deep links for payment return
  • Handling abandoned checkout sessions and recovery flows
  • Confirming payment authority server-side before granting access

Core principle: Backend creates, mobile opens

Your backend creates the checkout session and returns a URL. The mobile app opens that URL in a secure browser context. Your API key must never be embedded in the app binary. The mobile SDK result is informational only; always verify the payment server-side via webhook or API before unlocking features or granting access.

Architecture overview

  1. Backend: Create a checkout session via client.checkoutSessions.create(...) and return the checkout_url to your mobile app.
  2. Mobile app: Call the platform-specific SDK with the checkout URL and a registered return URL scheme.
  3. Browser context: The SDK opens the URL in a secure system browser: SFSafariViewController on iOS and Chrome Custom Tabs on Android.
  4. Return: After payment, the browser navigates to your return URL. The SDK captures the result and passes it to your app.
  5. Verification: Query the checkout session or listen for a webhook to confirm the payment before granting access.

React Native (Turbo Module)

Full guide: references/react-native.md.

Covers:

  • Installation
  • Setup
  • Starting checkout
  • Abandoned session recovery
  • Android minSdk requirement

Flutter

Full guide: references/flutter.md.

Covers:

  • Installation
  • Setup
  • Starting checkout
  • Return URL registration

iOS (native)

Full guide: references/ios.md.

Covers:

  • Installation
  • Starting checkout
  • Forwarding the return URL
  • Abandoned sessions

Android (native)

Full guide: references/android.md.

Covers:

  • Installation
  • Starting checkout
  • Abandoned sessions

Backend: Creating checkout sessions

Always create checkout sessions on your backend. Never embed your API key in the mobile app.

typescript
import DodoPayments from 'dodopayments';

const client = new DodoPayments({
  bearerToken: process.env.DODO_PAYMENTS_API_KEY,
  environment: 'test_mode',
});

const MOBILE_PRODUCTS = new Map([
  ['starter', 'pdt_starter123'],
  ['pro', 'pdt_pro456'],
]);

app.post('/api/mobile-checkout', requireAuth, async (req, res) => {
  const productId = MOBILE_PRODUCTS.get(req.body.plan);

  if (!productId) {
    return res.status(400).json({ error: 'Invalid plan' });
  }

  // requireAuth derives this mapping from the authenticated server-side session.
  const customerId = req.auth.dodoCustomerId;
  
  const session = await client.checkoutSessions.create({
    product_cart: [{ product_id: productId, quantity: 1 }],
    customer: { customer_id: customerId },
    return_url: 'myapp://checkout/return',
  });
  
  res.json({ checkout_url: session.checkout_url });
});

Verifying payment server-side

Never grant access based on the mobile SDK result alone. Always verify via webhook or API.

Via webhook

Listen for payment.succeeded webhooks. Webhook signature verification is covered in the webhook-integration skill.

typescript
// Mount with express.raw({ type: 'application/json' }) so req.body is the raw Buffer.
app.post('/webhook', async (req, res) => {
  let event;
  try {
    event = client.webhooks.unwrap(req.body.toString(), {
      headers: {
        'webhook-id': req.headers['webhook-id'] as string,
        'webhook-signature': req.headers['webhook-signature'] as string,
        'webhook-timestamp': req.headers['webhook-timestamp'] as string,
      },
    });
  } catch {
    return res.status(401).json({ error: 'Invalid signature' });
  }

  try {
    // Dodo retries and may redeliver: claim webhook-id with a UNIQUE insert
    // and grant in the same transaction so a duplicate is a no-op.
    await db.$transaction(async (tx) => {
      const claim = await tx.webhookLog.createMany({
        data: [{ webhookId: req.headers['webhook-id'] as string, eventType: event.type }],
        skipDuplicates: true,
      });
      if (claim.count === 0) return; // already processed

      if (event.type === 'payment.succeeded') {
        await grantAccess(event.data.customer.customer_id, tx);
      }
    });
  } catch (error) {
    // Non-2xx makes Dodo retry; the transaction rolled back the claim.
    return res.status(500).json({ error: 'Processing failed' });
  }

  res.json({ received: true });
});
Via API

Query the checkout session to confirm payment:

typescript
const session = await client.checkoutSessions.retrieve(sessionId);

if (session.payment_status === 'succeeded' && session.payment_id) {
  const payment = await client.payments.retrieve(session.payment_id);
  await grantAccess(payment.customer.customer_id);
}
Show full SKILL.md (336 more words)Show less

Selling digital goods on iOS

Dodo Payments hosted checkout can sell digital goods (subscriptions, courses, downloads, SaaS plans) in an iOS app only on App Store storefronts where Apple allows external purchases:

  • United States: Guideline 3.1.1(a) allows buttons and links to other purchase methods without an entitlement (subject to the Epic v. Apple proceedings).
  • European Union: requires Apple's EU external purchase entitlement (the StoreKit External Purchases or Offers Entitlement from October 1, 2026) and DMA compliance.
  • Japan: allowed under the Mobile Software Competition Act, following Apple's Japan-specific entitlement requirements.
  • South Korea is not supported (Apple requires a native, non-web-view flow through an approved Korean PSP).

On other storefronts, digital goods sold inside the iOS app must use Apple in-app purchase (StoreKit). Review Apple's region-specific entitlements before enabling Dodo checkout for a storefront; unsupported flows can get the app rejected.

Common mistakes

Embedding the API key in the app

Never include your API key in the app binary or client-side code. Always create checkout sessions on your backend.

typescript
// WRONG
const client = new DodoPayments({
  bearerToken: 'dodo_live_abc123...',  // Never hardcode
});

// CORRECT
const client = new DodoPayments({
  bearerToken: process.env.DODO_PAYMENTS_API_KEY,  // Backend only
});
Trusting the mobile SDK result

The SDK result is informational. Always verify server-side before granting access.

typescript
// WRONG
if (result.status === 'succeeded') {
  grantAccess();  // No verification
}

// CORRECT
if (result.status === 'succeeded') {
  const verified = await verifyPaymentOnBackend(result.paymentId);
  if (verified) {
    grantAccess();
  }
}
Forgetting URL scheme registration

If you don't register the custom URL scheme, the app won't receive the return callback and checkout will appear to hang.

  • React Native: Use the Expo plugin or manually register in Info.plist and AndroidManifest.xml.
  • Flutter: Register in both Info.plist and AndroidManifest.xml.
  • iOS: Add CFBundleURLTypes to Info.plist and forward URLs to DodoCheckout.handleOpenURL.
  • Android: Set manifestPlaceholders["dodoCallbackScheme"]; the SDK supplies the intent filter.
Not handling all result statuses

Always handle all five statuses: succeeded, failed, cancelled, pending, and expired. Each requires different UX.

typescript
// WRONG
if (result.status === 'succeeded') {
  showSuccess();
}

// CORRECT
switch (result.status) {
  case 'succeeded':
    showSuccess();
    break;
  case 'failed':
    showFailure();
    break;
  case 'cancelled':
  case 'pending':
    // Unknown outcome - reconcile, never show a failure
    reconcileAbandonedSession();
    break;
  case 'expired':
    showExpired();
    break;
}
Ignoring abandoned sessions

If the app crashes or is backgrounded during checkout, the session is abandoned. Always check for and recover abandoned sessions on app startup.

typescript
// WRONG
// No recovery logic

// CORRECT: reconcile on launch and after every cancelled/pending result,
// and clear the record only once the backend reports a final outcome.
await reconcileAbandonedSession(); // defined in references/react-native.md

Package names

Use @dodopayments/react-native-checkout for React Native and dodopayments_checkout for Flutter. The similarly named @dodopayments/react-native and dodo_payments_flutter packages do not exist.

Resources

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in plugins/dodopayments/dodo-agent-plugin/skills/mobile-checkout of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • references/android.md
  • references/flutter.md
  • references/ios.md
  • references/react-native.md

Open the folder on GitHubat commit 9e7b281

Compare with similar skills

Mobile Checkout next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mobile Checkout compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mobile Checkout this skillhashgraph-online/awesome-codex-plugins1.3k—~2.5kAutomated safety check: PassApache-2.0
SimdeckNativeScript/SimDeck152—~3.6kAutomated safety check: PassMIT
Detour Onboardingsoftware-mansion-labs/skills291—~2.8kAutomated safety check: PassNone
Revyl CLI Auth BypassRevylAI/revyl-cli522—~2.5kAutomated safety check: PassNone
Oma Mobilefirst-fluke/oh-my-agent1.3k—~1.6kAutomated safety check: PassMIT
Debugging SurveysPostHog/posthog40k—~7.1kAutomated safety check: PassCustom licence

Similar skills

  • Simdeck

    NativeScript/SimDeck

    A skill your agent uses for simulator lifecycle, app install/launch, live viewing, UI inspection, touch/keyboard automation, screenshots, recordings, logs, pasteboard, hardware controls, and…

    152 GitHub stars~3.6k tokensUpdated 27 days ago
    MobileAuto-check passed
  • Detour Onboarding

    software-mansion-labs/skills

    Complete onboarding guide for developers who are new to Detour, the open-source deferred deep linking SDK by Software Mansion.

    291 GitHub stars~2.8k tokensUpdated 11 days ago
    MobileAuto-check passed
  • Revyl CLI Auth Bypass

    RevylAI/revyl-cli

    Set up test-only auth bypass for Revyl runs across Expo, React Native, native iOS, native Android, and Flutter apps.

    522 GitHub stars~2.5k tokensUpdated today
    MobileAuto-check passed
  • Oma Mobile

    first-fluke/oh-my-agent

    Mobile specialist for Flutter, React Native, and cross-platform mobile development.

    1.3k GitHub stars~1.6k tokensUpdated today
    MobileAuto-check passed
  • Debugging Surveys

    PostHog/posthog

    Official

    Diagnose PostHog Surveys configuration and responses across all five SDKs (web/posthog-js, iOS, Android, Flutter, React Native).

    40k GitHub stars~7.1k tokensUpdated today
    MobileAuto-check passed
  • Migrate To Detour

    software-mansion-labs/skills

    A skill your agent uses when the user mentions migrating deep links, switching away from Branch or AppsFlyer, replacing their deep linking SDK, setting up Detour deep linking for the first time, or…

    291 GitHub stars~3.9k tokensUpdated 11 days ago
    MobileAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 714 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.3k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.3k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.3k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.3k GitHub stars~618 tokensUpdated today
    Auto-check passed

Categories

Questions about Mobile Checkout

What does Mobile Checkout do?

Dodo Payments in-app checkout for React Native, Flutter, native iOS, and Android using SFSafariViewController or Chrome Custom Tabs. Mobile Checkout is an agent skill from hashgraph-online/awesome-codex-plugins. Dodo Payments in-app checkout for React Native, Flutter, native iOS, and Android using SFSafariViewController or Chrome Custom Tabs.

When should I use Mobile Checkout?

Mobile Checkout fits situations like: A mobile app must open a backend-created checkout session; handle deep link; custom URL scheme returns; recover abandoned checkouts.

How do I install Mobile Checkout in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill mobile-checkout -a claude-code`. Or copy the skill folder (plugins/dodopayments/dodo-agent-plugin/skills/mobile-checkout in hashgraph-online/awesome-codex-plugins) into .claude/skills/mobile-checkout in your project. Claude Code loads it when a task matches its description.

How do I install Mobile Checkout in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill mobile-checkout -a codex`. Or copy the skill folder (plugins/dodopayments/dodo-agent-plugin/skills/mobile-checkout in hashgraph-online/awesome-codex-plugins) into .agents/skills/mobile-checkout in your project. Codex loads it when a task matches its description.

Can I use Mobile Checkout in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill mobile-checkout -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mobile-checkout, .gemini/skills/mobile-checkout, .github/skills/mobile-checkout and .opencode/skills/mobile-checkout in your project.

What does Mobile Checkout need to run?

Going by SKILL.md and its folder, Mobile Checkout needs credentials named DODO_PAYMENTS_API_KEY. Our summary lists: A credential in DODO_PAYMENTS_API_KEY.

Does Mobile Checkout access the network?

SKILL.md names 2 domains. As links in the text: docs.dodopayments.com and pub.dev. This is read from the text; nothing was executed.

Is Mobile Checkout safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mobile Checkout use?

Mobile Checkout is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mobile Checkout use?

About 2.5k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to Mobile Checkout?

Skills that share tags, products or a category with Mobile Checkout: Simdeck (NativeScript/SimDeck, 152 stars), Detour Onboarding (software-mansion-labs/skills, 291 stars), Revyl CLI Auth Bypass (RevylAI/revyl-cli, 522 stars) and Oma Mobile (first-fluke/oh-my-agent, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mobile Checkout?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,255 GitHub stars. The repository holds 714 skills in this directory. The repository was last updated on October 9, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.