RevenueCat

In-app subscriptions and purchases across the App Store and Play Store.

adds it to an existing project · no account needed
Currentas published in v1.5.1

The rule

This is the whole text, exactly as your agent receives it. Nothing is held back for the paid tier.

Access checks

  • Check entitlements, never product identifiers:
ts
  const isPro = info.entitlements.active['pro'] !== undefined;

Hardcoding a product id means every pricing change needs an app update.

  • Ask the SDK, do not trust local state. getCustomerInfo() is the source of truth; cached flags go stale after a refund, a cancellation or an expiry.
  • Access checks live in one service. Components ask that service, never the SDK.

Configuration

  • Purchases.configure() runs exactly once, at startup, before any other call.
  • Each platform gets its own public SDK key via Platform.select.
  • The secret API key is server-side only. It must never appear in the app, in an EXPO_PUBLIC_* variable, or in this repository.

Purchases

  • userCancelled is not an error. Check it before reporting or logging:
ts
  catch (error) {
    if (error.userCancelled) return;
    report(error);
  }
  • Restore purchases must be reachable from the UI. Apple rejects apps without it, and users need it after reinstalling.
  • Call Purchases.logIn(userId) after sign-in so entitlements follow the account rather than the device.

Never

  • Never grant access based on a local flag alone.
  • Never assume a purchase succeeded without checking the returned customerInfo.
  • Never put purchase logic in a component.
  • Never expect this to work in Expo Go — it is a native module, so it needs a development build.

6 formats, one per tool

Each tab is the file that tool actually reads, at the path it actually looks in. Knowing where each one looks is most of the work of supporting it.

.cursor/rules/revenuecat.mdchand-written
---
description: RevenueCat and in-app purchase conventions
globs: ["src/services/payments/**", "src/features/**/subscription*/**"]
alwaysApply: false
---

# RevenueCat

## Access checks

- Check **entitlements**, never product identifiers:

  ```ts
  const isPro = info.entitlements.active['pro'] !== undefined;
  ```

  Hardcoding a product id means every pricing change needs an app update.

- Ask the SDK, do not trust local state. `getCustomerInfo()` is the source of
  truth; cached flags go stale after a refund, a cancellation or an expiry.
- Access checks live in one service. Components ask that service, never the SDK.

## Configuration

- `Purchases.configure()` runs exactly once, at startup, before any other call.
- Each platform gets its own public SDK key via `Platform.select`.
- The **secret** API key is server-side only. It must never appear in the app,
  in an `EXPO_PUBLIC_*` variable, or in this repository.

## Purchases

- `userCancelled` is not an error. Check it before reporting or logging:

  ```ts
  catch (error) {
    if (error.userCancelled) return;
    report(error);
  }
  ```

- Restore purchases must be reachable from the UI. Apple rejects apps without
  it, and users need it after reinstalling.
- Call `Purchases.logIn(userId)` after sign-in so entitlements follow the
  account rather than the device.

## Never

- Never grant access based on a local flag alone.
- Never assume a purchase succeeded without checking the returned
  `customerInfo`.
- Never put purchase logic in a component.
- Never expect this to work in Expo Go — it is a native module, so it needs a
  development build.

Hand-written by the module author, frontmatter and all. It is the source the four derived formats are rendered from, so a correction lands here first.

What else this module writes

The rule is one file of several. Selecting RevenueCat contributes all of this too — merged with every other module you pick, with conflicts resolved rather than duplicated.

Environment
EXPO_PUBLIC_REVENUECAT_IOS_KEYrequiredPublic SDK key for the iOS app, from the RevenueCat dashboard.
EXPO_PUBLIC_REVENUECAT_ANDROID_KEYrequiredPublic SDK key for the Android app.
REVENUECAT_SECRET_KEYoptionalServer-side REST API key. Never ship this in the app.
Dependencies
react-native-purchases^10.6.0
Folders
src/features/subscriptions/screens/src/features/subscriptions/components/src/hooks/payments/src/services/payments/
Checklists
checklists/payments.md

Advisory history

Every time this rule turned out to be wrong, and what we did about it.

No corrections yet

This rule has been accurate since it was published. That is a fact about the rule, not a promise about the future — which is the whole reason this section exists.

Pro tells you the day a correction lands that affects a repo you actually have.

See what Pro adds →

Rules people add alongside this one

Put this rule in a real project

The wizard picks the rest of the stack with you, writes all 6 formats, and leaves a manifest so check can tell you when any of it drifts.