Safely handle web subscription?

shen_ming
Contributor
Contributor

Hi.

I can got subscription_id after I login in and subscription a plan.

But at server side , I only have a subscription id  to use  the api

 

https://developer.paypal.com/docs/subscriptions/full-integration/subscription-management/#show-subsc...

 

to check the subscription valid?

 

Is there some thing like apple or google, the web result (paypal's response) have something token along with subscription id  then 

server-side can check more?

 

Because I  wonder some bad man can just steal some valid subscription id . The server side can't distinguish the 

subscription id belong to the user?

 

 

 

 

Login to Me Too
0 REPLIES 0

Haven't Found your Answer?

It happens. Hit the "Login to Ask the community" button to create a question for the PayPal community.