> ## Documentation Index
> Fetch the complete documentation index at: https://memberful.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Build a custom app with Memberful

> Learn how to connect a custom app to Memberful for member sign-in and access to members-only content.

export const RelatedDocs = ({link1, link2, link3, link4, link5, link6, link7, link8, link9, link10, className = ""}) => {
  const links = [link1, link2, link3, link4, link5, link6, link7, link8, link9, link10].filter(Boolean);
  if (!links.length) return null;
  return <section className={`related-docs border dark:border-gray-700 rounded-2xl px-6 py-4 mt-6 ${className}`}>
      <p className="mb-2 font-medium">
        <strong>Related help docs:</strong>
      </p>
      <ul className="space-y-1 mb-1 mt-1">
        {links.map((link, index) => <li key={index}>
            <a href={link.url}>{link.label}</a>
          </li>)}
      </ul>
    </section>;
};

A custom app connected to Memberful lets members sign in and access members-only content. Purchases, renewals, plan changes, and billing happen on your website, where Memberful handles payments, subscriptions, and account management.

In this help article, we’ll explain how to connect your app and backend to Memberful, check membership access, and direct members to your website to manage their accounts.

## Plan your app experience

Memberful supports a consumption-only app: members use the app to access content they’ve purchased on your website. Memberful doesn’t process App Store or Google Play purchases.

Your app lets members:

* sign in through Memberful OAuth
* request members-only content from your backend
* view membership information, such as their plan name, renewal date, subscription status, and past-due warnings

Your app doesn’t include prices, checkout, payment processing, in-app purchases, or subscription management. Memberful doesn’t provide SDKs or components for managing subscriptions within an app. Checkout, plan changes, payment methods, cancellations, and billing use Memberful-hosted pages on your Memberful subdomain.

### How your app, backend, and Memberful work together

Each part has a different responsibility:

* **Memberful:** Stores membership data and processes payments. Members use your website to purchase and manage their subscriptions.
* **Your backend:** Checks which members can access which content and keeps a local copy of membership status.
* **Your app:** Authenticates members and requests content from your backend.

When a member requests protected content, your app sends their OAuth access token to your backend. Your backend uses the token to query the Member API, identify the member, and check whether their subscription includes the requested content. It returns the content if the member has access or rejects the request if they don’t.

Your backend also receives membership changes through webhooks and stores them locally, so it doesn’t need to query Memberful for every content request. Your backend controls access; the app connects directly to Memberful only for sign-in.

## Set up member sign-in

Go to **Settings** → **Custom applications** in the Memberful dashboard and create a [mobile application](/docs/api-reference/sign-in-for-apps-via-oauth#add-a-custom-application) to get your client ID.

Members sign in through OAuth 2.0 with PKCE. The sign-in page opens in a system browser view, so your app never sees or stores a member’s password.

After sign-in, your app receives:

* **Access token:** Used for API calls and valid for 15 minutes.
* **Refresh token:** Used for continued access and valid for one year.

For the complete sign-in flow, see [Sign members into applications via OAuth 2.0](/docs/api-reference/sign-in-for-apps-via-oauth).

<Callout icon="triangle-alert" color="#FFE044">
  If your website uses WordPress and opens website links in your app through universal links (iOS) or app links (Android), exclude URLs containing the `memberful_endpoint` query parameter from those rules. These URLs must open in the browser so Memberful can complete the WordPress sign-in. Otherwise, your app may receive a WordPress sign-in redirect instead of its expected OAuth callback.
</Callout>

## Check access and keep membership data current

Your backend uses Memberful’s APIs and webhooks to check access and keep its local membership data current.

| Integration | Data flow | Use |
| - | - | - |
| OAuth and Member API | Your app sends an OAuth token to your backend, which queries Memberful | Verify the member’s identity and membership status at sign-in or app launch |
| Webhooks | Memberful sends updates to your backend | Update local membership data when members subscribe, renew, change plans, or cancel |
| Admin API | Your backend queries Memberful | Backfill data, perform bulk operations, or look up members by email |

Use Member API queries and webhooks together. Webhooks keep a local copy of membership data current, while Member API queries verify status at key moments, such as sign-in, app launch, or after a webhook arrives. Most content requests can then use your local database.

Your backend defines the access rules: which members can see which content, whether a subscription is eligible, and what happens when a member cancels or a payment fails.

### Use plan identifiers and subscription status

In the Member API, `pass.id` identifies the plan and stays the same across price changes and promotions. Use `pass.id` to determine which content the subscription includes, rather than checking its price.

Also check the subscription’s `active` field:

* **`true`:** The subscription is currently valid, including during a trial or paid period.
* **`false`:** The subscription has ended.

For more detail, see [Memberful API](/docs/api-reference/memberful-api).

### Handle missed or out-of-order updates

Webhooks can fail or arrive out of order. Use them to keep your local data current, but verify critical access decisions against the live Member API when needed.

For setup guidance, see [Webhooks](/docs/api-reference/webhooks). For the available events, see [Webhook event reference](/docs/api-reference/webhook-event-reference).

<Callout icon="triangle-alert" color="#FFE044">
  Keep the Admin API on your backend. It can read and write every member’s data on your site and must not be exposed to your app.
</Callout>

## Let members manage their accounts on your website

Members use your website to:

* sign up and create an account
* complete checkout and payment
* renew an expired subscription
* switch plans or add another subscription
* update their payment card
* cancel their subscription
* change their name, email address, or password
* view billing history

Your app displays membership information without providing account or subscription management controls.

### Direct members to their account page

If store policies allow, link members to their account page:

`https://ACCOUNT-URL.memberful.com/account/`

Replace `ACCOUNT-URL` with your actual account URL subdomain, which you can find in Website → Settings.

Review Apple’s and Google’s current guidelines before submitting your app, including Apple’s External Link Account Entitlement requirements where applicable.

If store policies allow, you can also display the account URL for members to copy into a browser or tell them to manage their subscription on your website.

<Callout icon="info" color="#22E273">
  Members may need to sign in again when they open their account page, depending on whether the browser shares a session with the OAuth sign-in.
</Callout>

<RelatedDocs
  link1={{
url: "/api-reference/sign-in-for-apps-via-oauth/",
label: "Set up OAuth sign-in.",
}}
  link2={{
url: "/api-reference/memberful-api/",
label: "Query membership data.",
}}
  link3={{
url: "/api-reference/webhooks/",
label: "Set up webhooks.",
}}
  link4={{
url: "/member-interface/subscription/manage-their-subscriptions/",
label: "Understand how members manage subscriptions.",
}}
/>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.