Skip to content

Venmo app-switch: payment succeeds but the Venmo app never returns to the merchant app (Android v5, sandbox) #1715

Description

@zxx0712

Summary

On Android, using the modular v5 Venmo SDK, the Venmo sandbox app completes the payment (user authorizes successfully) but never returns to the merchant app. Instead it stays inside the Venmo app and lands on its own feed/TabCentral. The merchant app therefore never receives the return, handleReturnToApp only ever sees NoResult, and no nonce is produced.

Crucially, at app-switch time the Venmo app logs every incoming query parameter of the Braintree checkout URL as invalid:

W LHT:F:FTM: Invalid Incoming Query Param: x-success
W LHT:F:FTM: Invalid Incoming Query Param: x-error
W LHT:F:FTM: Invalid Incoming Query Param: x-cancel
W LHT:F:FTM: Invalid Incoming Query Param: x-source
W LHT:F:FTM: Invalid Incoming Query Param: braintree_merchant_id
W LHT:F:FTM: Invalid Incoming Query Param: braintree_access_token
W LHT:F:FTM: Invalid Incoming Query Param: braintree_environment
W LHT:F:FTM: Invalid Incoming Query Param: resource_id
W LHT:F:FTM: Invalid Incoming Query Param: braintree_sdk_data
W LHT:F:FTM: Invalid Incoming Query Param: customerClient

SDK version

  • com.braintreepayments.api:venmo:5.32.0 (also card/paypal/google-pay/data-collector 5.32.0)

Environment

  • Reproduced on multiple physical devices: Pixel 7a (Android 13), Samsung S23 (Android 14), Samsung Galaxy Z Fold / other (Android 15), Samsung S21 Ultra (Android 11).
  • Venmo sandbox app com.venmo.sandbox, versionName 26.19.0, installed via Firebase App Distribution, logged in with a sandbox Venmo test account.
  • Braintree sandbox merchant with a Venmo Merchant Profile Enabled (profile id present and matching braintree_merchant_id in the app-switch URL).

Steps to reproduce

  1. Integrate v5 Venmo per the docs: VenmoClient(context, clientToken, appLinkReturnUrl, "${packageName}.braintree"), create the launcher in Activity.onCreate, call handleReturnToApp in onResume.
  2. In checkout, call createPaymentAuthRequest → launcher.launch(...).
  3. The app switches to the Venmo sandbox app (https://venmo.com/go/checkout?x-success=...&braintree_merchant_id=...).
  4. Authorize / complete the payment in the Venmo app (payment succeeds).
  5. Tap Done.

Expected

Per the docs ("A successful app switch will always return a nonce for a test user named VenmoJoe"), after a successful authorization the Venmo app should return to the merchant app via the x-success return URL, producing a payment method nonce.

Actual

  • Venmo app logs all query params as Invalid Incoming Query Param (see above).
  • After payment success, the only ActivityManager: START intents are Venmo's own (com.venmo.sandbox/...TabCentralActivity, .../NavigationHostContainer). There is zero START intent pointing back to the merchant app — no https App Link and no custom scheme.
  • On the merchant side, handleReturnToApp sees NoResult and activity.intent.data == null, i.e. no return intent was ever delivered.

Notes / things already verified on the merchant side

  • Integration matches the official VenmoClient.kt / VenmoLauncher.kt source (URL construction and BrowserSwitchClient-based launch are unchanged).
  • The app-switch URL is standard (https://venmo.com/go/checkout + the 10 params above).
  • Both return-link types were observed and both fail identically:
    • App Link (https) on Android 11 / API 30 — x-success=https://<merchant-domain>/braintree-payments/success
    • Custom scheme on Android 12+ / API 31+ — x-success=<pkg>.braintree://x-callback-url/vzero/auth/venmo/success
  • The custom scheme is registered in the manifest and resolves uniquely to the merchant activity (verified with am start); the App Link domain is verified (pm get-app-links) with a correct assetlinks.json.
  • The reason API 31+ emits scheme vs API 30 emits App Link is resolveActivity(MATCH_DEFAULT_ONLY) returning ResolverActivity on Android 12+ when a browser is also installed — but this is orthogonal: both return types are rejected by the Venmo app the same way.

Questions

  1. Why does the Venmo sandbox app flag every Braintree app-switch query parameter as Invalid Incoming Query Param?
  2. Is com.venmo.sandbox 26.19.0 compatible with the v5 SDK's app-switch parameters, or is a different sandbox build required?
  3. Is there any additional Braintree Control Panel / merchant-profile / sandbox-app pairing step required for the Android sandbox app to honor the return URL and switch back?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions