Hi Ashley & Josh.
We now have some much more specific diagnostic information from our developer which I hope will help identify the remaining issue.
1. Production iOS tokenisation is now working
Following your correction to our Production Application ID, the iOS app successfully tokenises a £2 Apple Pay transaction using:
sq0idp-mH0kidmo40W1RGlHahG5og
and successfully generates a Production nonce.
So thank you — the original invalid_application_id problem is resolved.
2. /v2/payments authentication fails
Our deployed Supabase function then calls:
POST https://connect.squareup.com/v2/payments
Square returns:
AUTHENTICATION_ERROR
UNAUTHORIZED
This request could not be authorized.
Supabase Request ID:
01a0ab25-6838-73ab-b22d-7d308cb12ba3
3. Most importantly — RetrieveTokenStatus also fails
Our developer has now tested Square’s RetrieveTokenStatus endpoint using the exact same Production Access Token currently stored and used by the deployed Supabase function.
It returns:
HTTP 401 Unauthorized
with:
AUTHENTICATION_ERROR
UNAUTHORIZED
This request could not be authorized.
The developer has confirmed that this test used the exact same token currently deployed in Supabase.
We have already copied/updated the Production Access Token and redeployed the Supabase function, but Square continues to reject it.
This therefore appears to have been narrowed down to Square not accepting the Production Access Token itself, rather than an issue with the Apple Pay integration or payment request.
Could you please check the Production credentials/application on Square’s side and advise why the Production Access Token is returning 401 Unauthorized even from RetrieveTokenStatus?
If the token needs to be regenerated/reissued or there is something that needs enabling/provisioning on Square’s side, please let us know exactly what action we need to take.
Production Application ID:
sq0idp-mH0kidmo40W1RGlHahG5og
Production Location ID:
L9TQB99P87QPN
For security reasons we obviously won’t post the Production Access Token publicly.
Many thanks.