What a push token is and how it appears
A push token is a string the operating system assigns to a particular installation of an app on a
device. The token carries no personal data — it is an opaque identifier meaningful only to the push
platform’s infrastructure.
How the token is obtained:
- The app calls the notification permission API.
- The person grants consent (opt-in).
- The OS registers the app with APNs (iOS) or FCM (Android) and returns a token.
- The app sends the token to the backend, where it is stored as a delivery address.
APNs token (iOS): a 64-character hexadecimal string
FCM token (Android): a long Base64 string, roughly 150+ characters
The token lifecycle
Tokens are not permanent. They are invalidated in these situations:
| Event | Behaviour |
|---|---|
| App reinstall | A new token; the old one goes stale |
| Device factory reset | A new token |
| Apple ID change (iOS) | A new token |
| Permission revoked by the person | The token stays in the database but nothing is delivered |
| Long inactivity (FCM) | FCM may reissue the token |
Important: the backend must process the push platforms’ responses about invalid tokens and
delete them from the database. Accumulated stale tokens are the leading cause of a low delivery
rate.
Managing tokens on the backend
The baseline requirements:
- Store the tuple
(userId, token, platform, created_at, updated_at). - When a new token arrives for a userId, replace the old one — a person can have several devices, so
several tokens are acceptable, but with deduplication. - Delete tokens returning
UnregisteredorInvalidTokendelivery errors on a regular schedule. - At sign-out, delete or deactivate the token so that the next person using the device does not
receive someone else’s notifications.
Tokens and push campaign analytics
How precisely tokens are managed feeds straight into the metrics:
- Delivery rate = delivered / sent. A large share of stale tokens understates it.
- Click-through rate = clicks / delivered. Careless token management distorts the denominator.
- Audience reach — measured as valid tokens divided by the app’s MAU. A typical opt-in rate:
40–60% on iOS, 70–90% on Android.