App Store ConnectBLOCK
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for interacting with the App Store Connect API. This server provides tools for managing apps, beta testers, bundle IDs, devices, app metadata, and capabilities in App Store Connect.
[](https://cursor.com/install-mcp?name=app-store-connect&config=JTdCJTIyY29tbWFuZCUyMiUzQSUyMm5weCUyMC15JTIwYXBwc3RvcmUtY29ubmVjdC1tY3Atc2VydmVyJTIyJTdE)
Overview
The App Store Connect MCP Server is a comprehensive tool that bridges the gap between AI and Apple's App Store Connect ecosystem. Built on the Model Context Protocol (MCP), this server enables developers to interact with their App Store Connect data directly through conversational AI, making app management, beta testing, and analytics more accessible than ever.
Key Benefits:
- 🤖 AI-Powered App Management: Use natural language to manage your iOS and macOS apps
- 📊 Comprehensive Analytics: Access detailed app performance, sales, and user engagement data
- 👥 Streamlined Beta Testing: Efficiently manage beta groups and testers
- 🌍 Localization Management: Update app descriptions, keywords, and metadata across all languages
- 🔧 Developer Tools Integration: List Xcode project schemes and integrate with development workflows
- 🔐 Secure Authentication: Uses official App Store Connect API with JWT authentication
- 🚀 Real-time Data: Access up-to-date information directly from Apple's systems
Who This Is For:
- iOS/macOS developers managing apps in App Store Connect
- Development teams coordinating beta testing programs
- Product managers analyzing app performance and user engagement
- Marketing teams managing app metadata and localizations
- DevOps engineers automating app store workflows
- Anyone looking to streamline their Apple developer experience
This server transforms complex App Store Connect operations into simple conversational commands, whether
14e830b9eb58OBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add appstore-connect-mcp-server --env APP_STORE_CONNECT_KEY_ID=${APP_STORE_CONNECT_KEY_ID} -- npx -y [email protected]{
"mcpServers": {
"appstore-connect-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"APP_STORE_CONNECT_KEY_ID": "${APP_STORE_CONNECT_KEY_ID}"
}
}
}
}Exposed tools (27)
19 read · 7 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_tester_to_group | write | Add a new tester to a beta group |
create_analytics_report_request | write | Create a new analytics report request for an app |
create_app_store_version | write | Create a new app store version for an app |
create_bundle_id | write | Register a new bundle ID for app development |
disable_bundle_capability | write | Disable a capability for a bundle ID |
download_analytics_report_segment | read | Download data from an analytics report segment URL |
download_finance_report | read | Download finance reports for a specific region |
download_sales_report | read | Download sales and trends reports |
enable_bundle_capability | write | Enable a capability for a bundle ID |
get_app_info | read | Get detailed information about a specific app |
get_app_store_version_localization | read | Get detailed information about a specific app store version localization |
get_beta_feedback_screenshot | read | Get detailed information about a specific beta feedback screenshot submission. By default, downloads and returns the screenshot image. |
get_bundle_id_info | read | Get detailed information about a specific bundle ID |
list_analytics_report_segments | read | Get segments for a specific analytics report (contains download URLs) |
list_analytics_reports | read | Get available analytics reports for a specific report request |
list_app_store_version_localizations | read | Get all localizations for a specific app store version |
list_app_store_versions | read | Get all app store versions for a specific app |
list_apps | read | Get a list of all apps in App Store Connect |
list_beta_feedback_screenshots | read | List all beta feedback screenshot submissions for an app. This includes feedback with screenshots, device information, and tester comments. You can identify the app using either appId or bundleId. |
list_beta_groups | read | Get a list of all beta groups (internal and external) |
list_bundle_ids | read | Find and list bundle IDs that are registered to your team |
list_devices | read | Get a list of all devices registered to your team |
list_group_testers | read | Get a list of all testers in a specific beta group |
list_schemes | read | List all available schemes in an Xcode project or workspace |
list_users | read | Get a list of all users registered on your App Store Connect team |
remove_tester_from_group | destructive | Remove a tester from a beta group |
update_app_store_version_localization | write | Update a specific field in an app store version localization |
Trust audit
BLOCKgrade F · trust 29/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
var deprecatedfn = new Function('fn', 'log', 'deprecate', 'message', 'site','return function (' + args + ') {' +bound = Function('binder', 'return function (' + joiny(boundArgs, ',') + '){ return binder.apply(this,arguments); }')(binder);if (options.unix === false) { // this branch is for exec()exec(string: string): RegExpExecArray | null;
request ~ requests
request ~ requests
.DS_Store
bare-fs.bare
bare-fs.bare
bare-fs.bare
bare-fs.bare
node_modules/.bin/prebuild-install
node_modules/.bin/rc
node_modules/.bin/resolve
node_modules/.bin/semver
node_modules/.bin/shjs
* console.log(myURL.password);
testProxyUrl(env, '', 'http://10.0.0.1/');
testProxyUrl(env, '', 'http://10.0.0.1:80/');
testProxyUrl(env, '', 'http://10.0.0.1:1337/');
testProxyUrl(env, '', 'http://10.0.0.2/');
"chars": "€پ‚ƒ„...†‡ˆ‰ٹ‹Œچژڈگ‘’“”•–—کTMڑ›œں ،¢£¤¥¦§ ̈©ھ«¬® ̄°±23 ́μ¶· ̧1؛»1⁄41⁄23⁄4؟ہءآأؤإئابةتثجحخدذرزسشصض×طظعغـفقكàلâمنهوçèéêëىيîïًٌٍَôُِ÷ّùْûüے"
"chars": "«»...“”�•‘’� กขฃคฅฆงจฉชซฌญฎฏฐฑฒณดตถทธนบปผฝพฟภมยรฤลฦวศษสหฬอฮฯะัาําิีึืฺุู–—฿เแโใไๅๆ็่้๊๋์ํTM๏๐๑๒๓๔๕๖๗๘๙®©����"
remove_tester_from_group
Gates applied: no_behavioural_pass.
14e830b9eb58full audit observations/trust-audit/mcp-server/joshuarileydev__app-store-connect.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 14e830b9eb58 | BLOCK | F | 29 | first audit |
Questions
What tools does App Store Connect expose?
27 in total: 19 read-only, 7 that write, and 1 that can delete or overwrite (remove_tester_from_group). Every one is listed on this page with its risk.
Is App Store Connect safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (29/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does App Store Connect need?
It reads APP_STORE_CONNECT_KEY_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does App Store Connect run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as appstore-connect-mcp-server at 1.1.2.
How current is this page?
The grade is for one exact copy of the source (14e830b9eb58), read on 2026-10-03. The repository is watched and re-audited when it changes.