Skip to content

Integration guidelines for mobile apps

These guidelines apply to the xMoney native mobile SDKs, Inline Checkout in a WebView, and Hosted Checkout in a WebView.

App Store guidelines

App stores have specific rules for in-app payment processing.

iOS (Apple App Store)

  • External payment providers are generally permitted for physical goods and services.
  • Digital goods and services may require Apple's in-app purchase system.
  • Check the current App Review Guidelines, especially the Payments section.

Android (Google Play Store)

  • External payment methods are generally permitted for physical goods and services.
  • Digital goods and services may require Google Play Billing.
  • Review the current Google Play Payments policy.

Store rules vary by product and region and can change. Review the current policy for every market where you distribute your app.

Security best practices

Native clients are not trusted server environments. An app can contain the xMoney publishable key (pk_test_... or pk_live_...), but it must never contain a private or secret API key.

Use a backend service to:

  • Build order details from trusted product and pricing data.
  • Sign the order payload with the xMoney private key.
  • Return only payload and checksum to the app.
  • Receive webhooks and expose a trusted order-status endpoint to the app.
  • Validate every amount, currency, customer, and order identifier sent by the client.

Native SDK card fields collect PAN and CVV in SDK-owned native views. In React Native, raw card data does not cross the JavaScript bridge. Do not log payment payloads, wallet tokens, or SDK results that may contain customer or transaction data.

Native app lifecycle and 3DS

The SDK handles 3DS presentation and payment-state transitions. Issuer authentication may temporarily show web content or move the shopper to another app.

  • Keep the checkout screen and current PaymentIntent alive while a payment is processing.
  • Do not start a second payment while the SDK reports processing.
  • Restore surrounding checkout state if the operating system recreates the screen.
  • Treat PaymentResult as a client signal and confirm the final status on your backend.
  • Request a newly signed order after a complete, failed, or post-submit canceled result.

For WebView integrations, preserve the WebView instead. See Mobile WebView integration.

React Native and Expo

The React Native SDK requires React Native 0.76 or later with New Architecture. Expo projects must use the xMoney config plugin and create a native development or production build. Expo Go does not include the native xMoney modules and is not supported.

Handling webhooks

Mobile applications cannot receive webhooks directly, and payment status may not be final when the shopper returns to the app.

  1. Configure xMoney webhooks and any backUrl to point to your backend.
  2. Store the latest trusted transaction status on the backend.
  3. Let the app poll your status endpoint or notify it with a silent push.
  4. Fulfill the order only after server-side confirmation.