NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #3980 most downloaded on Packagist
Pure-PHP library that allows managing customer transactions using the App Store Server API and handling server-to-server notifications using the App Store Server Notifications V2
Last release 17 days ago
20 Sep 2026
Release timing varies
gaps range from 1 weeks to 6 months
Most releases are documented
notes for 35 of 45 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
45 releases · first in 2022
DecodedRealtimeRequestBody::getMillisecondsSinceSigned(), getSecondsSinceSigned() and isExpired() introduced — allow checking how long ago the App Sto
IMPROVEMENTS:
DecodedRealtimeRequestBody::getMillisecondsSinceSigned(), getSecondsSinceSigned() and isExpired() introduced — allow checking how long ago the App Store signed the request and whether it has exceeded a given TTLBUGFIX:
DecodedRealtimeRequestBody: locale property and getLocale() renamed to userLocale / getUserLocale()Retention Messaging API support added to AppStoreServerAPI: uploadImage(), deleteImage(), getImageList(), uploadMessage(), deleteMessage(), getMessage
IMPROVEMENTS:
AppStoreServerAPI: uploadImage(), deleteImage(), getImageList(), uploadMessage(), deleteMessage(), getMessageList(), configureDefaultMessage(), getDefaultMessage(), deleteDefaultMessage(), configureRealtimeUrl(), getRealtimeUrl(), deleteRealtimeUrl()UploadImageRequest, DeleteImageRequest, GetImageListRequest, UploadMessageRequest, DeleteMessageRequest, GetMessageListRequest, ConfigureDefaultMessageRequest, GetDefaultMessageRequest, DeleteDefaultMessageRequest, ConfigureRealtimeUrlRequest, GetRealtimeUrlRequest, DeleteRealtimeUrlRequestImageRequestBody, UploadMessageRequestBody, DefaultConfigurationRequestBody, UploadImageQueryParams, RealtimeUrlRequestBodyGetImageListResponse, GetMessageListResponse, DefaultConfigurationResponse, RealtimeUrlResponse (and their item classes GetImageListResponseItem, GetMessageListResponseItem)AbstractRequest::HTTP_METHOD_DELETE introducedOne column per quarter.
…to match what the endpoint actually expects (breaking change if you call this method using a named argument)
IMPROVEMENTS:
ResponseBodyV2::createFromSignedPayload() introduced — decodes a signedPayload JWT directly instead of requiring it to be wrapped into a fake raw notification JSON first; NotificationHistoryResponseItem now uses it internallylint-74 .. lint-85 targets added (lint against PHP 7.4 through 8.5), plus composer, stan, and test shortcutsBUGFIX:
AppStoreServerAPIInterface was missing the getTransactionHistoryV2() and setAppAccountToken() declarations even though AppStoreServerAPI already implemented both — interface updated to matchsetAppAccountToken(): parameter (and underlying request URL placeholder) renamed from $transactionId to $originalTransactionId to match what the endpoint actually expects (breaking change if you call this method using a named argument)JWT::verifyX509Chain(): throws a proper exception when the x5c certificate chain doesn't contain exactly 3 certificates, instead of triggering an Undefined array key warning (which could previously surface as an uncaught TypeError further down)JWTCreationException::__construct(): implicit nullable parameter deprecation fixed (Throwable $previous = null → ?Throwable $previous = null)Added DecodedRealtimeRequestBody
IMPROVEMENTS:
DecodedRealtimeRequestBodyRealtimeResponseBodycomposer.json : autoload-dev PSR-4 namespace fixed
BUGFIX:
composer.json: autoload-dev PSR-4 namespace fixedAbstractRequestQueryParams::getQueryString() integer values handling fixedGetTransactionHistoryQueryParams::getQueryString()IMPROVEMENTS:
setAppAccountToken() support added to AppStoreServerAPISetAppAccountTokenRequest, UpdateAppAccountTokenRequestBodyProper handling of failed HTTP requests added
IMPROVEMENTS:
StoreKit2Transaction and StoreKit2AppTransaction introduced
StoreKit2Transaction and StoreKit2AppTransaction introducedIntroduced new field to TransactionInfo : offerPeriod
IMPROVEMENTS:
TransactionInfo: offerPeriodNew notificationType = ONE_TIME_CHARGE in ResponseBodyV2
IMPROVEMENTS:
notificationType = ONE_TIME_CHARGE in ResponseBodyV2TransactionInfo::getAppTransactionId() make it public (silly bug)
BUGFIX:
TransactionInfo::getAppTransactionId() make it public (silly bug)Introduced new field to TransactionInfo : appTransactionId
IMPROVEMENTS:
TransactionInfo: appTransactionIdRenewalInfo: appAccountToken, appTransactionId, currency, eligibleWinBackOfferIds, offerDiscountType, offerPeriod, renewalPriceCalling sendConsumptionInformation() w/o passing optional parameter refundPreference results in fatal error
BUGFIX:
sendConsumptionInformation() w/o passing optional parameter refundPreference results in fatal errorIMPROVEMENTS:
AbstractRequestParamsBag classBUGFIX:
sendConsumptionInformation() w/o passing optional parameter refundPreference results in fatal error (kudos to @javiermarinros)IMPROVEMENTS:
AbstractRequestParamsBag classAbstractRequestParamsBag::isValueMatchingPropValues() fixed (double negation if value is an array)
BUGFIX:
AbstractRequestParamsBag::isValueMatchingPropValues() fixed (double negation if value is an array)AbstractRequestQueryParams::getQueryString() fixed (bool values are now explicitly converted to strings)BUGFIX:
AbstractRequestParamsBag::isValueMatchingPropValues() fixed (double negation if value is an array, kudos to @neoighodaro)AbstractRequestQueryParams::getQueryString() fixed (bool values are now explicitly converted to strings, kudos to @neoighodaro)New field consumptionRequestReason added to AppMetadata
IMPROVEMENTS:
consumptionRequestReason added to AppMetadatarefundPreference (and corresponding constants) added to ConsumptionRequestBody (kudos to @sedlak477)In-app purchase history V2 support added (kudos to @anegve)
IMPROVEMENTS:
Default TTL for payload introduced and set to 5 min. Previous value of 1 hour (which is the maximum) seems to be the cause of failed responses in some
BUGFIX:
Nullable properties now are NOT converted to empty int/bool/float/string in AppMetadata, RenewalInfo, ResponseBodyV2, TransactionInfo, kudos to @dbrkv
IMPROVEMENTS:
Now the response content of the HTTP response is available in HTTPRequestFailed exception using getResponseText() method, kudos to @soxft for pointing
IMPROVEMENTS:
HTTPRequestFailed exception using getResponseText() method, kudos to @soxft for pointing this outHandle empty response headers in case if HTTP request to the API fails (and it fails regularly, kudos to Apple)
BUGFIX:
If the certificate string already has a prefix, there is no need to add it
BUGFIX:
Treat "202 Accepted" as successful response (App Store returns it on "Send consumption information" request), kudos to @teanooki for pointing this out
BUGFIX:
TransactionInfo: price, currency, and offerDiscountType from App Store Server API version 1.10
IMPROVEMENTS:
New fields implemented
TransactionInfo: price, currency, and offerDiscountType from App Store Server API version 1.10Logic issue in PageableResponse, after fixing syntax issue in 3.5.1
BUGFIX:
3.5.1Syntax issue in PageableResponse for PHP 7.4, kudos to @JamieSTV
BUGFIX:
Extend a Subscription Renewal Date
IMPROVEMENTS:
Missing endpoints added:
TransactionInfo: storefront, storefrontId, and transactionReason are now nullable and null by default, in order to be compatible with old notification
BUGFIX:
TransactionInfo: storefront, storefrontId, and transactionReason are now nullable and null by default, in order to be compatible with old notificationsRenewalInfo: renewalDate is now null by default, in order to be compatible with old notificationsResponse\NotificationHistoryResponse: paginationToken presence in response is now optionalNew notificationType/subtype in ResponseBodyV2
IMPROVEMENTS:
notificationType/subtype in ResponseBodyV2ASN1SequenceOfInteger: multiple 00 bytes in the beginning of integer numbers handled when parsing HEX signature representation
BUGFIX:
00 bytes in the beginning of integer numbers handled when parsing HEX signature representationAppMetadata: bundleId, bundleVersion, renewalInfo, transactionInfo and status now are NULL by default (to prevent Typed property ... must not be acces
BUGFIX:
AppMetadata: bundleId, bundleVersion, renewalInfo, transactionInfo and status now are NULL by default (to prevent Typed property ... must not be accessed before initialization error)IMPROVEMENTS: - New field implemented - AppMetadata: status
IMPROVEMENTS:
AppMetadata: statusTransactionInfo: storefront, storefrontId, transactionReason
IMPROVEMENTS:
RenewalInfo: renewalDateTransactionInfo: storefront, storefrontId, transactionReasonResponseBodyV2: createFromRawNotification() fix, now it checks incoming notification to be not only a valid JSON, but also to be an array
BUGFIX:
ResponseBodyV2: createFromRawNotification() fix, now it checks incoming notification to be not only a valid JSON, but also to be an arrayASN1SequenceOfInteger: math fixes
BUGFIX:
ASN1SequenceOfInteger: math fixesStatusResponse: data array initialization with []IMPROVEMENTS:
HTTPRequest: PUT method added; HTTP method and URL added to HTTPRequestFailed exception messageJWT: additional information in exception messageMath bug fixed in ASN1SequenceOfInteger. In rare cases signature was calculated in a wrong way which led to Wrong signature exception in JWT::verifySi
BUGFIX:
ASN1SequenceOfInteger. In rare cases signature was calculated in a wrong way which led to Wrong signature exception in JWT::verifySignatureAPIClientInterface -> AppStoreServerAPIInterface
BREAKING CHANGES:
APIClient -> AppStoreServerAPIAPIClientInterface -> AppStoreServerAPIInterfaceNotification\ResponseBodyV2 -> ResponseBodyV2JWT -> Util\JWTRequest\GetTransactionHistory -> Request\GetTransactionHistoryRequestRequest\RequestTestNotification -> Request\RequestTestNotificationRequestRequest\GetTransactionHistoryQueryParams -> RequestQueryParams\GetTransactionHistoryQueryParamsEnvironmentgetTransactionHistory() method signature changed: it no longer expects for QueryParams instance as a second arguments, now it expects array insteadAppStoreServerAPI (previously APIClient) constructor signature changed:
$environment argument type changed from int to string$keyId and $key arguments swappedIMPROVEMENTS:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →