our server side validation followed the guidance to always allow sandbox receipts What do you mean by always allow sandbox receipts? I hope you don't mean that when you receipt a sandbox receipt, you always just accept the request? The page you linked to says: call the production URL https://buy.itunes.apple.com/verifyReceipt first and proceed to verify with the sandbox URL if you receive a 21007 status code. What exactly are you doing?
Topic:
App & System Services
SubTopic:
StoreKit
Tags: