All packsPlay Billing MachinerySolve
google play billing client side entitlement refund bug
The client is a cache. The server is the only entitlement authority.
A refunded purchase leaves the local Purchase object still saying PURCHASED -- unlocking a feature client-side passes every test an agent writes, until the first refund (decision 1).
This is one of the things Play Billing Machinery already handles. Sell subscriptions in your Android app on the Billing Library version Google requires from 31 August 2026.
Is this you?
Unlocking a feature the moment BillingClient reports a completed purchase passes every test an agent thinks to write: the purchase flow completes, the feature unlocks, green. It fails on the first refund, because a refunded user's local Purchase object still reports PURCHASED -- nothing client-side ever learns the money came back.
Why this one is easy to get wrong
queryPurchasesAsync and the PurchasesUpdatedListener genuinely do carry a PURCHASED state, so reading it directly to gate a feature looks like using the API as designed. The gap only appears after a refund, cancellation, or chargeback happens somewhere else entirely -- an event the client was never told about and has no reason to re-check for.
What you get instead
Decision 1 makes the server the sole entitlement authority: purchases.subscriptionsv2.get is the only source of truth, and a client-reported Purchase may narrow the UI (show a spinner) but never widen it beyond what the server last said. EntitlementTest.serverStateWinsOverLocalPurchase is the test whose only job is to fail if someone reintroduces client-side unlocking.
Source: ARCHITECTURE.md decision 1 — checkable in the pack you receive
How you actually use this
You don’t install a library or wire up an SDK. Your own coding agent builds the code in your project, and you keep it — no runtime dependency on us.
Step 1
Download and unzip
You get a folder: the docs that tell an agent what to build, a starting skeleton, and the test suite that decides when it's done.
Step 2
Open it in Claude Code or Cursor
Point your coding agent at the folder. Nothing to install, no account with us, no API key.
Step 3
Paste one prompt
The pack contains the exact prompt. Paste it as your first message and leave it alone — it works through the build itself, choosing a cheaper or stronger model per task.
Step 4
Run ./verify.sh
One command. It prints a pass or fail for every check. Green means the build is done — the same script we ran to produce the receipt on this page.
Typical build: about 33 minutes of your agent working, mostly unattended. Then you integrate the working module into your app the way you would any code you’d written yourself.
Why you can believe this
3 of 3 runs passedWe ran this pack from an empty folder 3 times and published exactly what happened — every check, the model, the token cost, the wall time. Not a testimonial, and not our opinion: the same verify.sh you run yourself. Read the full receipt →