Plan your app experience
Memberful supports a consumption-only app: members use the app to access content they’ve purchased on your website. Memberful doesn’t process App Store or Google Play purchases. Your app lets members:- sign in through Memberful OAuth
- request members-only content from your backend
- view membership information, such as their plan name, renewal date, subscription status, and past-due warnings
How your app, backend, and Memberful work together
Each part has a different responsibility:- Memberful: Stores membership data and processes payments. Members use your website to purchase and manage their subscriptions.
- Your backend: Checks which members can access which content and keeps a local copy of membership status.
- Your app: Authenticates members and requests content from your backend.
Set up member sign-in
Go to Settings → Custom applications in the Memberful dashboard and create a mobile application to get your client ID. Members sign in through OAuth 2.0 with PKCE. The sign-in page opens in a system browser view, so your app never sees or stores a member’s password. After sign-in, your app receives:- Access token: Used for API calls and valid for 15 minutes.
- Refresh token: Used for continued access and valid for one year.
If your website uses WordPress and opens website links in your app through universal links (iOS) or app links (Android), exclude URLs containing the
memberful_endpoint query parameter from those rules. These URLs must open in the browser so Memberful can complete the WordPress sign-in. Otherwise, your app may receive a WordPress sign-in redirect instead of its expected OAuth callback.Check access and keep membership data current
Your backend uses Memberful’s APIs and webhooks to check access and keep its local membership data current.
Use Member API queries and webhooks together. Webhooks keep a local copy of membership data current, while Member API queries verify status at key moments, such as sign-in, app launch, or after a webhook arrives. Most content requests can then use your local database.
Your backend defines the access rules: which members can see which content, whether a subscription is eligible, and what happens when a member cancels or a payment fails.
Use plan identifiers and subscription status
In the Member API,pass.id identifies the plan and stays the same across price changes and promotions. Use pass.id to determine which content the subscription includes, rather than checking its price.
Also check the subscription’s active field:
true: The subscription is currently valid, including during a trial or paid period.false: The subscription has ended.
Handle missed or out-of-order updates
Webhooks can fail or arrive out of order. Use them to keep your local data current, but verify critical access decisions against the live Member API when needed. For setup guidance, see Webhooks. For the available events, see Webhook event reference.Keep the Admin API on your backend. It can read and write every member’s data on your site and must not be exposed to your app.
Let members manage their accounts on your website
Members use your website to:- sign up and create an account
- complete checkout and payment
- renew an expired subscription
- switch plans or add another subscription
- update their payment card
- cancel their subscription
- change their name, email address, or password
- view billing history
Direct members to their account page
If store policies allow, link members to their account page:https://ACCOUNT-URL.memberful.com/account/
Replace ACCOUNT-URL with your actual account URL subdomain, which you can find in Website → Settings.
Review Apple’s and Google’s current guidelines before submitting your app, including Apple’s External Link Account Entitlement requirements where applicable.
If store policies allow, you can also display the account URL for members to copy into a browser or tell them to manage their subscription on your website.
Members may need to sign in again when they open their account page, depending on whether the browser shares a session with the OAuth sign-in.