# IAP Validation Android

**URL:** <https://forum.heroiclabs.com/t/iap-validation-android/4380>\
**Category:** Runtime Framework\
**Tags:** server-framework, lua\
**Created:** [September 24, 2023, 12:16am UTC](https://forum.heroiclabs.com/t/iap-validation-android/4380 "2023-09-24T00:16:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eatos](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/eatos/32/1656_2.png) [@Eatos](https://forum.heroiclabs.com/u/Eatos)\
**Post date:** [September 24, 2023, 12:16am UTC](https://forum.heroiclabs.com/t/iap-validation-android/4380/1 "2023-09-24T00:16:22Z")

</div>

Currently we are implementing IAP Validation through nakama on android and we are hitting problems with service account credentials.  
I wouldn’t write if the case is well known, but i have tried using a different service and different language and different framework and verification went smoothly.  
So using [GitHub - dotpot/InAppPy: Python In-app purchase validator for Apple AppStore and GooglePlay.](https://github.com/dotpot/InAppPy/tree/master) and a script in it I am able correctly to verify purchase using service account and verification when smoothly but what are differences.

1. For configuration of python services we had to:
  - 
    - Load account\_service\_json from file and send iit to its validator

  - Define package name

2. Its validator what it does next is checking validity of the service file and key using [oauth2client.service\_account module — oauth2client 4.1.2 documentation](https://oauth2client.readthedocs.io/en/latest/source/oauth2client.service_account.html)
3. Send recepit to validation which then validates based on product\_sku and purchase\_token and some rest params.

And here in this api validation works smoothly.

Following Nakama in-app guide we did setup everything correctly although i am not 100% sure is key correctly being read as api always fails there, it reports invalid api key file for service.

In console it is shown as:  
-----BEGIN PRIVATE KEY-----\nMIIEvQIBADANBgkqhki  
Litterly with newlines through the key.

Now question is: Where could be mistake?  
As all different third party services seams to work with service account and client email configured correctly?

## Any help is appreciated 🙂

Runtime Info:

1. Versions: Nakama {3.16.0}, {Docker}
2. Server Framework Runtime language: Lua

```auto
{code or log snippet}

```

---

<div class="post-metadata">

**Author:** ![Eatos](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/eatos/32/1656_2.png) [@Eatos](https://forum.heroiclabs.com/u/Eatos)\
**Post date:** [September 24, 2023, 3:40am UTC](https://forum.heroiclabs.com/t/iap-validation-android/4380/2 "2023-09-24T03:40:26Z")

</div>

Edit:

- Seams that problem is with how the backend reads service\_account.json and then do the rest of the magic.
- So currently in backend we tried to do verification with standard usage of function reference

```auto
purchase_validate_google(user_id, receipt)

```

With this api, it already expects that in config we have configured service client email, and service client private key.  
Both are entered. While using this api, the backend will return

```auto
google api invalid private key.

```

1. On 2nd tried, i tried to use already iap\_verifiy in Lua, and instead to use client email ,and private key from config, i base64 encoded whole file, then stored in localcache  
Upon calling verifying script i decode base64 and then i convert it to json, and from there i read information about client email, and client private key.  
And this managed to verify purchase.

2. I went back to

```auto
purchase_validate_google(user_id, receipt)

```

Since it has overloads for client email and client private key, and sent how i was reading it in case 2, and again it faild to do anything and error was api doesn’t exits at all o.O

---

<div class="post-metadata">

**Author:** ![sesposito](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/sesposito/32/2594_2.png) [@sesposito](https://forum.heroiclabs.com/u/sesposito)\
**Post date:** [September 25, 2023, 10:31am UTC](https://forum.heroiclabs.com/t/iap-validation-android/4380/3 "2023-09-25T10:31:28Z")

</div>

Please reach out at [support@heroiclabs.com](mailto:support@heroiclabs.com)

---

<div class="post-metadata">

**Author:** ![Eatos](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/eatos/32/1656_2.png) [@Eatos](https://forum.heroiclabs.com/u/Eatos)\
**Post date:** [September 27, 2023, 12:42pm UTC](https://forum.heroiclabs.com/t/iap-validation-android/4380/4 "2023-09-27T12:42:52Z")

</div>

I have sent email regarding this topic.
