Amazon Developer

as

Settings
Sign out
Notifications
Alexa
Amazon Appstore
Ring
AWS
Documentation
Support
Contact Us
My Cases
Develop
Test
Publish
Monetize
Engage users
Device specifications
Resources

Use Real-Time Notifications

Real-Time Notifications (RTN) are server-to-server messages that tell your app's back-end server about in-app purchase events as they happen. This page describes how to register and authenticate an endpoint in the Developer Console, change or delete an endpoint, and process the messages Amazon sends.

Set up Real-Time Notifications

To register a new endpoint, Amazon sends a confirmation message containing a confirmation token to that endpoint. You copy the token from the message and paste it into the Confirmation token field in the console to complete setup. A new endpoint must be authenticated before it can receive notifications.

To set up RTN in the Developer Console

  1. Sign in to the Developer Console.
  2. From the top navigation bar, select My Apps.
  3. Find your app in the list, select the menu icon , and then select App Services.
  4. In the Real-Time Notifications section, choose Add an Endpoint.
  5. Enter your app's HTTPS endpoint in the URL for Appstore notifications field, and then choose Submit.
  6. Retrieve the confirmation token from the confirmation message that Amazon sends to your endpoint.
  7. Paste the token into the Confirmation token field, and then choose Confirm.

The token is valid for 48 hours from the time the notification is sent. If the token expires or the confirmation message doesn't arrive, see Resend an expired or missing token. After you submit a valid token, the endpoint status becomes Verified and starts receiving notifications.

Upgrade a legacy endpoint

A legacy endpoint is an endpoint that already receives notifications but predates authenticated setup and needs to be confirmed. To upgrade a legacy endpoint, you must authenticate it by requesting a fresh confirmation token and submitting it. Authenticating a legacy endpoint causes no disruption. The endpoint keeps receiving notifications throughout, and it changes to authenticated only after you confirm the token.

To authenticate a legacy endpoint

  1. Sign in to the Developer Console.
  2. From the top navigation bar, select My Apps.
  3. Find your app in the list, select the menu icon , and then select App Services.
  4. In the Real-Time Notifications section, find the endpoint with the banner that asks you to authenticate it.
  5. Choose Resend to send a fresh confirmation token to the endpoint.
  6. Retrieve the confirmation token from the confirmation message that Amazon sends to your endpoint.
  7. Paste the token into the Confirmation token field, and then choose Confirm.

The token is valid for 48 hours from the time the notification is sent. If the token expires, see Resend an expired or missing token. After you submit a valid token, the endpoint status changes to Verified.

Resend an expired or missing token

A confirmation token is valid for 48 hours from the time the notification is sent. If the token expires or the confirmation message doesn't arrive, request a new token. This applies to both new endpoints under verification and legacy endpoints awaiting authentication.

To request a new confirmation token

  1. Sign in to the Developer Console.
  2. From the top navigation bar, select My Apps.
  3. Find your app in the list, select the menu icon , and then select App Services.
  4. In the Real-Time Notifications section, find the endpoint awaiting authentication.
  5. Choose Resend to send a new confirmation message with a new token.
  6. Retrieve the new token from the confirmation message that Amazon sends to your endpoint.
  7. Paste the token into the Confirmation token field, and then choose Confirm.

Change the RTN endpoint

Change your RTN endpoint when you need to move notifications to a different HTTPS URL. You keep receiving notifications on your current endpoint until the new one is confirmed, so there's no gap in delivery.

To change an RTN endpoint

  1. Sign in to the Developer Console.
  2. From the top navigation bar, select My Apps.
  3. Find your app in the list, select the menu icon , and then select App Services.
  4. In the Real-Time Notifications section, choose Add an Endpoint, and then choose Edit.
  5. Choose Add a new URL, or choose an endpoint that you registered previously.
  6. Choose Submit.
  7. Retrieve the confirmation token from the confirmation message that Amazon sends to your new endpoint.
  8. Paste the token into the Confirmation token field, and then choose Confirm.

The status of the new endpoint is under verification until you submit a valid confirmation token. You keep receiving Real-Time Notifications on the previous endpoint until the new endpoint is confirmed. The token is valid for 48 hours from the time the notification is sent. If the token expires or the confirmation message doesn't arrive, see Resend an expired or missing token.

After you submit a valid token, the new endpoint status changes to Verified and starts receiving notifications.

Delete an RTN endpoint

Delete an RTN endpoint when you no longer want to receive notifications at that URL.

To delete an RTN endpoint

  1. Sign in to the Developer Console.
  2. From the top navigation bar, select My Apps.
  3. Find your app in the list, select the menu icon , and then select App Services.
  4. In the Real-Time Notifications section, choose Add an Endpoint, and then choose Edit.
  5. Find the appropriate URL and choose Remove.
  6. Select Remove on the confirmation dialog.

Check the status of your endpoint

You can check the status of your endpoint in the Real-Time Notifications section of the Developer Console.

To view your endpoint status

  1. Sign in to the Developer Console.
  2. From the top navigation bar, select My Apps.
  3. Find your app in the list, select the menu icon , and then select App Services.
  4. Go to the Real-Time Notifications section and review any messages. To see your registered endpoint and its status, choose Add an Endpoint.

The Developer Console shows the status of your endpoint and might include messages about actions required. The following table describes reference states for an endpoint and how they appear in the console.

Reference state Description What you see in the console
Active (Unauthenticated) Legacy endpoint that receives notifications but hasn't completed confirmation-token authentication.

Pending action: Authenticate endpoint as described in Upgrade a legacy endpoint.
  • Banner prompting you to authenticate the endpoint
  • Confirmation token field available (use Resend to get a token)
  • Indication that the URL is receiving Real-Time Notifications
Under Verification New or changed endpoint that is awaiting confirmation. The URL doesn't receive notifications until you enter the confirmation token.

Pending action: Submit the confirmation token received at your endpoint.
  • Banner indicating a verification request was sent to your endpoint
  • Confirmation token field available
  • URL marked as under verification
  • Indication that the URL is not receiving Real-Time Notifications
Active (Authenticated) Endpoint that has completed confirmation-token authentication and receives notifications.
  • URL marked as Verified
  • Indication that the URL is receiving Real-Time Notifications

Processing notification messages

To prevent spoofing attacks, you must validate the Amazon signature to verify the authenticity of the message. For more information, see Verifying the signatures of Amazon SNS messages.

If you are using an Amazon AWS SDK, then the processing of HTTPS POST and signature validation is handled for you.

If you don't use an Amazon AWS SDK, follow the guidelines for parsing Amazon SNS message formats to handle the HTTPS POST request, and the signature validation steps described in Verifying the signatures of Amazon SNS messages.

RTN confirmation message

When you register or change an endpoint, Amazon sends a confirmation message containing a confirmation token to that endpoint. To confirm the endpoint, retrieve the token from the message and paste it into the Confirmation token field in the Developer Console. For the complete flow, see Set up Real-Time Notifications. For an example confirmation message, see Confirmation message.

The token is valid for 48 hours from the time the notification is sent. If the token expires or the confirmation message doesn't arrive, see Resend an expired or missing token.

Notification

Your endpoint needs to return a 200 response code status to the POST request. If your server can't be reached, or returns a 4xx code, the message will not be retried.

If your endpoint does not respond within the timeout limit of 15 seconds or returns a response outside of 200-4xx code, the message delivery is considered a failed attempt and will be retried.


Last updated: Oct 08, 2026