OneShot

All packsPlay Billing MachinerySolve

pub/sub push endpoint authentication oidc jwt verification

Pub/Sub doesn't verify who owns your push URL. The OIDC token is the only gate.

Anyone who learns a Pub/Sub push endpoint's URL can POST to it -- the OIDC bearer token is the entire authentication boundary, and it has to be verified in a specific order (decision 8).

This is one of the things Play Billing Machinery already handles. Sell subscriptions in your Android app on the Billing Library version Google requires from 31 August 2026.

Buy for $1493 of 3 clean-room builds passed · full refund if it fails on your machine

Is this you?

Google's own docs state Pub/Sub "doesn't require proof of ownership for push subscription URL domains" -- there's nothing stopping an attacker who discovers the endpoint from posting a forged notification body directly. Verifying the JWT in the wrong order, or verifying it loosely, opens algorithm-confusion and issuer-spoofing paths that a superficially working integration never exercises.

Why this one is easy to get wrong

A shared-secret query parameter or a basic signature check feels like sufficient protection for an internal-looking webhook URL, and the endpoint "works" the moment a real Google notification hits it -- there's no negative test forcing a forged request through the same code path unless the pack builds one deliberately.

What you get instead

Decision 8 pins the check order: pin alg to RS256 before touching any key (killing alg:none and HMAC-confusion attacks first), resolve kid, verify the signature, then check iss, aud, the push service account's email plus email_verified, and exp -- deliberately without a tight freshness check, since Google's own docs say push tokens may legitimately be up to an hour old. A ?token= shared secret is explicitly named as an insufficient legacy pattern that leaks into logs.

Source: ARCHITECTURE.md decision 8 — checkable in the pack you receive

How you actually use this

You don’t install a library or wire up an SDK. Your own coding agent builds the code in your project, and you keep it — no runtime dependency on us.

  1. Step 1

    Download and unzip

    You get a folder: the docs that tell an agent what to build, a starting skeleton, and the test suite that decides when it's done.

  2. Step 2

    Open it in Claude Code or Cursor

    Point your coding agent at the folder. Nothing to install, no account with us, no API key.

  3. Step 3

    Paste one prompt

    The pack contains the exact prompt. Paste it as your first message and leave it alone — it works through the build itself, choosing a cheaper or stronger model per task.

  4. Step 4

    Run ./verify.sh

    One command. It prints a pass or fail for every check. Green means the build is done — the same script we ran to produce the receipt on this page.

Typical build: about 33 minutes of your agent working, mostly unattended. Then you integrate the working module into your app the way you would any code you’d written yourself.

Why you can believe this

3 of 3 runs passed

We ran this pack from an empty folder 3 times and published exactly what happened — every check, the model, the token cost, the wall time. Not a testimonial, and not our opinion: the same verify.sh you run yourself. Read the full receipt →

Buy for $14914-day refund if verify.sh fails →

Related problems