Server-side SDK reliability
This page is the shared reliability contract for all backend / server SDKs (.NET, Go, PHP, Ruby, Java, Python, Rust, and Node). It is not .NET-specific.
Language-specific APIs, package versions, and code samples live under each SDK’s own docs (linked below). For browser and mobile SDKs, see Client-side reliability.
Which filters each SDK evaluates locally (versus the Definitions worker), and what happens for unknown filters, is documented in the SDK × filter matrix. Runtime version floors live on Support floors.
Shared contract
Every server SDK should:
- Verify raw signed bytes — persist the exact server
defsJSON and verify that payload. Never re-serialize typed models for signature checks. - Surface failures — report fetch, cache, storage, signature, and JWKS errors through an error callback and a last-error / debug surface.
- Keep last-known-good — after one successful load, transient refresh failures must not wipe in-memory flags.
- Clear caches — expose APIs to delete persisted feature and JWKS snapshots.
- Handle key rotation — on WebSocket
signing-key-updated, clear JWKS (and any JWKS snapshot), then refresh definitions. - Track revision — use
ETag/X-Definitions-Revisionfor conditional HTTP fetches. Revision is caching metadata, not part of the signature.
Raw-field names differ by language (SignedDefsJson, RawDefs,
signedDefsJson, signed_defs_json); the rule is the same: verify the exact
server bytes.
Choose your SDK
| SDK | Where to go |
|---|---|
| .NET | Reliability · Snapshot providers · Troubleshooting |
| Go | Snapshots · Signed definitions |
| PHP | Snapshot providers |
| Ruby | Configuration · Signed definitions · Live updates |
| Java | Caching · Signed definitions · Live updates |
| Python | Caching · Signed definitions · Live updates |
| Rust | Caching |
| Node | Node.js · Configuration · SDK × filter matrix |
Troubleshooting Invalid signature
Typical pattern: cold start logs Invalid signature, then a later HTTP
refresh succeeds and rewrites the snapshot.
Cause: older packages re-serialized stored feature models when verifying. Storage round-trips changed the signed JSON bytes.
Fix (any language):
- Upgrade to a package version that stores the raw signed defs field.
- Clear the persisted snapshot / cache once.
- Let the next successful refresh rewrite the snapshot from the definitions API.
.NET note: if typed Features and verified SignedDefsJson diverge in
storage, the .NET SDK refuses the load. Details and remediation:
.NET reliability and
Invalid signature on startup.