Production invalid_application_id with iOS In-App Payments SDK 1.6.7

Hi Square team,

We have a production-only issue with the iOS In-App Payments SDK.

Sandbox works correctly, but Production returns invalid_application_id during payment token generation.

We are using SquareInAppPaymentsSDK 1.6.7, SquareBuyerVerificationSDK 1.6.7 and react-native-square-in-app-payments 2.0.1.

Our Production Application ID has been checked and is correct. Our Apple Pay Merchant ID is configured in the Square Production dashboard and the production certificate shows as Valid.

The payment token request is generated internally by the native Square SDK. Our application is not manually calling Square’s payment token endpoint.

Both Apple Pay and card entry fail before a payment token reaches our backend.

Sandbox works but Production fails with invalid_application_id.

Could a Square Developer Advocate please check whether our Production application is correctly provisioned for production tokenisation?

Thank you.

Additional confirmation: the merchant Square account is active and is successfully processing live card-terminal payments today. Square Virtual Terminal is also enabled with no activation or verification warnings. Therefore this does not appear to be caused by the merchant account being inactive.

Hey @caffesabrina! Do you mind sharing your application ID here? Happy to take a look. Please make sure you’re sharing the application ID (typically beginning with the sq0idp-... prefix) and not your access token.

Hi Josh, thanks for taking a look.
The Production Application ID is:
sq0idp-mH0kidmo40W1RGIHahG5og

Sandbox works correctly, but Production is returning invalid_application_id during token generation.

Hi Josh, just to save some time and you having to come back for further information, here are the full details we’ve established so far:

Production Application ID: sq0idp-mH0kidmo40W1RGIHahG5og

Production Location ID: L9TQB99P87QPN

SquareInAppPaymentsSDK: 1.6.7
SquareBuyerVerificationSDK: 1.6.7
React Native wrapper: react-native-square-in-app-payments 2.0.1

Apple Pay Merchant ID: merchant.co.uk.caffesabrina.app

In Square Developer Dashboard → Production → Apple Pay → iOS, the certificate for this Merchant ID shows Valid.

Sandbox works correctly. Production does not.

In Production, Square’s native SDK returns:
invalid_application_id

The /v2/payment-tokens request is made internally by the compiled SquareInAppPaymentsSDK.xcframework. Our application is not manually calling that endpoint.

Our React Native layer calls SQIPApplePay.requestApplePayNonce() for Apple Pay and SQIPCardEntry.startCardEntryFlow() for card entry.

The failure occurs during token/nonce generation, before our backend receives a token, so no CreatePayment request is subsequently made.

We’ve also confirmed the Square merchant account itself is active — Caffè Sabrina is successfully processing live card-terminal payments.

We’ve checked the Production Application ID, Production environment, Merchant ID and Apple Pay certificate and haven’t found a mismatch.

If possible, could you check on Square’s side whether this Production Application ID is correctly provisioned/recognised by the production In-App Payments tokenisation service?

Are you available to help please?

Hi Square Developer Team,

Could another Square Developer Advocate or Solutions Engineer please assist with this case?

Josh kindly responded and asked for our Production Application ID so that he could take a look. We provided this, together with the full technical information requested, but unfortunately we haven’t received any further assistance and this issue is still completely blocking our Production payments.

We have now been waiting several days and have exhausted the troubleshooting available to us.

Sandbox works correctly, but Production tokenisation through SquareInAppPaymentsSDK 1.6.7 returns invalid_application_id.

Our Square merchant account is active and processing live card-terminal payments, the Production Application ID has been verified, and our Production Apple Pay Merchant ID and certificate are valid.

At this stage we specifically need someone at Square to check whether our Production Application ID is correctly provisioned/recognised by Square’s production tokenisation service.

If Josh isn’t currently available, could another member of the Square Developer team please take ownership of this or escalate it to the In-App Payments engineering team?

This is now holding up the launch of our app’s payment functionality, so we’d be extremely grateful for some assistance.

Thank you.

Apologies for the delay here working through this still and will provide a more detailed update to you by the end of the day today.

Thanks so much, I really appreciate the update :+1:

Thanks for your patience! It looks like you just have a typo in your app ID! Lowercase "l"s and capital "I"s render almost identically in most fonts, so a side-by-side visual check won’t catch it — which explains why your verification came up clean.

Please copy the application ID directly from Developer Console → your application → Credentials → Production using copy/paste rather than retyping, and confirm the string in your build matches byte-for-byte. Worth checking any .env file, native config, and build-time variables, since the value may have been transcribed at any of those points.

This also explains the sandbox/production split: your sandbox ID is a separate string that was presumably copied cleanly, so only the production path fails.

If tokenization still returns invalid_application_id after correcting it, let me know and we’ll pull the raw response from the nonce service.

Your correct app ID is sq0idp-mH0kidmo40W1RGlHahG5og

Hi Ashley,

Just an update — unfortunately we’re still receiving the Production authentication error after correcting the Application ID.

The original invalid_application_id issue is now resolved. Tokenisation succeeds and we’re receiving the cnon: nonce.

The failure now occurs when our Supabase backend sends the payment to:

POST https://connect.squareup.com/v2/payments

Square returns:

AUTHENTICATION_ERROR
UNAUTHORIZED
This request could not be authorized.

Our developer has redeployed the Supabase function and updated the Production Access Token again, but the same error persists.

I’ve attached a screenshot from today’s test.

Could you please check the request/API side from Square’s end and tell us exactly why the authentication is being rejected?

Production Location ID:
L9TQB99P87QPN

We won’t post the Production Access Token publicly, but we’re happy to provide any request ID, timestamp or other diagnostic information you need to trace it.

Thanks again.

Hi Ashley & Josh.

We now have some much more specific diagnostic information from our developer which I hope will help identify the remaining issue.

1. Production iOS tokenisation is now working

Following your correction to our Production Application ID, the iOS app successfully tokenises a £2 Apple Pay transaction using:

sq0idp-mH0kidmo40W1RGlHahG5og

and successfully generates a Production nonce.

So thank you — the original invalid_application_id problem is resolved.

2. /v2/payments authentication fails

Our deployed Supabase function then calls:

POST https://connect.squareup.com/v2/payments

Square returns:

AUTHENTICATION_ERROR
UNAUTHORIZED
This request could not be authorized.

Supabase Request ID:
01a0ab25-6838-73ab-b22d-7d308cb12ba3

3. Most importantly — RetrieveTokenStatus also fails

Our developer has now tested Square’s RetrieveTokenStatus endpoint using the exact same Production Access Token currently stored and used by the deployed Supabase function.

It returns:

HTTP 401 Unauthorized

with:

AUTHENTICATION_ERROR
UNAUTHORIZED
This request could not be authorized.

The developer has confirmed that this test used the exact same token currently deployed in Supabase.

We have already copied/updated the Production Access Token and redeployed the Supabase function, but Square continues to reject it.

This therefore appears to have been narrowed down to Square not accepting the Production Access Token itself, rather than an issue with the Apple Pay integration or payment request.

Could you please check the Production credentials/application on Square’s side and advise why the Production Access Token is returning 401 Unauthorized even from RetrieveTokenStatus?

If the token needs to be regenerated/reissued or there is something that needs enabling/provisioning on Square’s side, please let us know exactly what action we need to take.

Production Application ID:
sq0idp-mH0kidmo40W1RGlHahG5og

Production Location ID:
L9TQB99P87QPN

For security reasons we obviously won’t post the Production Access Token publicly.

Many thanks.