The developer documentation for In App Purchasing talks about a method to use a server validation. In this case, My app will send a reciept from IAP to my server. I will then send that to Apple's server.
AppleProductionUrl = "https://buy.itunes.apple.com/verifyReceipt";
AppleTestUrl = "https://sandbox.itunes.apple.com/verifyReceipt";
What exactly does the Apple Server verify? Can I skip this and verify only on my server?
What analysis of the reciept must I do?
- Inspect bundle ID, check.
- Make sure the reciept instance isn't a replay (somehow)