Atlas / MCP servers / sardorbekr / App Store Connect

App Store ConnectBLOCK

mcp/sardorbekr/app-store-connect-7

A Model Context Protocol (MCP) server for Apple's App Store Connect API

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
94 53r · 32w · 9d
Transport
stdio
License
MIT
Stars
22
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/asc-mcp) [](https://opensource.org/licenses/MIT) [](https://nodejs.org)

A Model Context Protocol (MCP) server for Apple's App Store Connect API. Manage your iOS, macOS, tvOS, and visionOS apps directly from Claude, Cursor, or any MCP-compatible client.

Features

  • App Store Localizations - Full CRUD for version descriptions, keywords, and what's new
  • App Management - List and inspect apps across all platforms
  • Version Control - Create and manage app store versions
  • Beta Testing - Manage TestFlight groups and testers
  • Screenshot Management - Upload and organize app screenshots
  • Bundle ID Management - Full CRUD for bundle identifiers
  • Device Management - List and inspect registered devices
  • User Management - List and inspect team users
  • Build Management - List and inspect app builds
  • Category & Pricing - Browse categories, check pricing and availability
  • Pricing & PPP - Set per-territory pricing with Purchase Power Parity support
  • In-App Purchases - Create and manage one-time purchases (lifetime/non-consumable, consumable, non-renewing): metadata, localization, pricing & PPP, availability, and review submission (review-screenshot upload excluded)
  • Analytics Reports - Request and download app analytics reports (engagement, commerce, usage, performance)
  • Sales & Finance - Download sales, trends, and financial reports
  • Performance & Diagnostics - App/build power & performance metrics and diagnostic logs
  • Secure by Default - ES256 JWT auth with automatic token refresh, credential redaction in logs

Table of Contents

  • Quick Start
  • Installation
  • Configuration
  • [Available Tools](#available
Read from source at commit 94198312ae5fOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add asc-mcp -- npx -y [email protected]
03

Exposed tools (94)

53 read · 32 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
LifetimereadUnlock forever
UpdatedreadNew
add_beta_testerwriteAdd a new beta tester to a beta group by email address.
create_analytics_report_requestwriteCreate a new analytics report request for an app. Use ONGOING for continuous reports or ONE_TIME_SNAPSHOT for a single snapshot. Reports take time to generate after creation.
create_app_versionwriteCreate a new App Store version for an app.
create_bundle_idwriteRegister a new bundle ID in App Store Connect. The identifier must be unique and follow reverse-domain notation (e.g., com.example.app).
create_in_app_purchasewriteCreate a new in-app purchase. Defaults to NON_CONSUMABLE — a one-time
create_in_app_purchase_localizationwriteAdd a localized display name (and optional description) for an in-app purchase. At least one localization is required before submission.
create_promotional_offerwriteCreate a promotional offer for a subscription. Use offerMode FREE_TRIAL for a trial offer (no prices needed). Use PAY_AS_YOU_GO or PAY_UP_FRONT for discounted paid offers and supply prices per territory. The offerCode is the string customers redeem.
create_subscriptionwriteCreate a new auto-renewable subscription within a subscription group.
create_subscription_groupwriteCreate a new subscription group for an app. A subscription group must be created before adding individual subscriptions to it.
create_subscription_group_localizationwriteCreate a localization for a subscription group. Provides the localized group name shown to users on the App Store subscription management page.
create_subscription_localizationwriteCreate a localized name and description for a subscription in a specific locale.
create_subscription_pricewriteSet the price for a subscription in a specific territory. Use list_subscription_price_points to find the price point ID for the desired price tier. The price takes effect on startDate (or immediately if null).
create_version_localizationwriteCreate a new localization for an App Store version. Add descriptions, keywords, and other metadata in a specific locale.
delete_analytics_report_requestdestructiveDelete an analytics report request. This stops report generation and removes access to existing reports.
delete_bundle_iddestructiveDelete a bundle ID. Note: This cannot be undone and may affect apps using this bundle ID.
delete_in_app_purchasedestructiveDelete an in-app purchase. Only possible before it has been approved/sold.
delete_in_app_purchase_localizationdestructiveDelete an in-app purchase localization.
delete_promotional_offerdestructiveDelete a promotional offer from a subscription.
delete_subscriptiondestructiveDelete an auto-renewable subscription. Only subscriptions in MISSING_METADATA or DEVELOPER_REMOVED_FROM_SALE state can be deleted.
delete_subscription_localizationdestructiveDelete a localization for a subscription.
delete_version_localizationdestructiveDelete a version localization. Cannot delete the primary locale.
download_analytics_report_segmentreadDownload and parse an analytics report segment from its pre-signed URL. The segment data is gzip-compressed TSV. Returns parsed headers and rows (as key-value objects). Use list_analytics_report_segments to get the download URL first.
get_analytics_report_requestreadGet details of a specific analytics report request.
get_appreadGet detailed information about a specific app by its ID.
get_app_availabilityreadGet app availability information, including which territories the app is available in.
get_app_perf_metricsreadGet performance and power metrics for an app (e.g., launch time, memory, battery, hangs). Returns Xcode-style metrics data with values per device and percentile. Use this for app-level aggregate metrics across all builds.
get_app_price_schedulewriteGet the price schedule for an app, including pricing information.
get_app_versionreadGet detailed information about a specific app version.
get_buildreadGet details of a specific build.
get_build_perf_metricsreadGet performance and power metrics for a specific build. Same metric types as get_app_perf_metrics but scoped to a single build. Useful for comparing performance between builds.
get_bundle_idreadGet details of a specific bundle ID.
get_devicereadGet details of a specific registered device.
get_finance_reportreadDownload and parse a finance report from App Store Connect. Returns financial report data as structured rows.
get_in_app_purchasereadGet details of a specific in-app purchase, including its state and product ID.
get_in_app_purchase_availabilityreadGet the territory availability of an in-app purchase, including which territories it is available in.
get_in_app_purchase_price_point_equalizationsreadGet Apple
get_price_point_equalizationsreadGet Apple
get_sales_reportreadDownload and parse a sales report from App Store Connect. Returns tab-delimited report data as structured rows.
get_subscriptionreadGet details of a specific auto-renewable subscription by its ID.
get_subscription_availabilityreadGet the territory availability configuration for a subscription — shows which territories it is available in and whether it is automatically available in new territories.
get_subscription_groupreadGet details of a specific subscription group by its ID.
get_subscription_group_localizationreadGet a single subscription group localization by its ID. Returns the localized name, locale, custom app name, and description.
get_userreadGet details of a specific team user.
get_version_localizationreadGet detailed information about a specific version localization.
list_analytics_report_instancesreadList report instances (dated snapshots) for an analytics report. Each instance represents data for a specific processing date. Can filter by granularity (DAILY, WEEKLY, MONTHLY) and processing date.
list_analytics_report_requestsreadList all analytics report requests for an app. Shows whether each request is active or stopped due to inactivity.
list_analytics_report_segmentsreadList downloadable segments for a report instance. Each segment contains a URL for downloading the report data, along with its checksum and size.
list_analytics_reportsreadList analytics reports available for a report request. Can filter by category (APP_STORE_ENGAGEMENT, COMMERCE, APP_USAGE, FRAMEWORKS_USAGE, PERFORMANCE).
list_app_categoriesreadList all app categories available in the App Store. Can filter by platform.
list_app_info_localizationsreadList all localizations for an app info. Returns app name, subtitle, and privacy policy info for each locale.
list_app_infosreadList app info records for an app. Use this to get the appInfoId needed for localization operations.
list_app_price_pointsreadList available price points for an app. Each price point represents a possible price tier showing customer price and developer proceeds in local currency. Filter by territory to see prices for a specific country.
list_app_versionsreadList all App Store versions for an app. Can filter by platform and version state.
list_appsreadList all apps in your App Store Connect account. Returns app IDs, names, bundle IDs, and SKUs.
list_beta_groupsreadList all beta groups for an app. Returns group names, public link info, and settings.
list_beta_testersreadList all beta testers in a specific beta group.
list_buildsreadList all builds for an app.
list_bundle_idsreadList all bundle IDs registered in App Store Connect. Can filter by platform.
list_devicesreadList all registered devices in App Store Connect. Can filter by platform and status.
list_diagnostic_logsreadList diagnostic logs for a specific diagnostic signature. Returns individual log entries for a given performance issue. Use list_diagnostic_signatures first to get a signature ID.
list_diagnostic_signaturesreadList power and performance diagnostic signatures for a build. Signatures represent recurring performance issues (disk writes, hangs, slow launches) grouped by call stack. Use list_diagnostic_logs with a signature ID to get detailed logs.
list_in_app_purchase_localizationsreadList the localized display names and descriptions for an in-app purchase.
list_in_app_purchase_price_pointsreadList available price points for an in-app purchase, showing customer price and developer proceeds. Filter by territory to find a price point ID for set_in_app_purchase_price. Supports offset-based pagination.
list_in_app_purchase_priceswriteList the current per-territory prices set for an in-app purchase, with resolved customer price and territory. Returns developer-set (manual) prices by default; set includeAutomatic to also include Apple
list_in_app_purchasesreadList in-app purchases for an app. Covers one-time purchases — non-consumable (a
list_promotional_offer_priceswriteList the prices set for a promotional offer, with resolved price tier and territory details.
list_promotional_offersreadList all promotional offers configured for a subscription. Promotional offers target existing or previously subscribed customers via offer codes.
list_screenshot_setswriteList all screenshot sets for a version localization. Each set represents a different display type (device size).
list_screenshotswriteList all screenshots in a screenshot set.
list_subscription_group_localizationsreadList the localizations for a subscription group. These provide the localized name shown to users on the subscription management page.
list_subscription_groupsreadList all subscription groups for an app. Subscription groups contain auto-renewable subscriptions and define upgrade/downgrade relationships.
list_subscription_localizationsreadList all localizations (translated names and descriptions) for a subscription.
list_subscription_price_pointsreadList available price points for a subscription, showing customer price and developer proceeds. Optionally filter by territory. Use offset to paginate beyond the first 200 results.
list_subscription_priceswriteList the current prices set for a subscription, including price tier and territory details. Use this to read existing pricing before making changes.
list_subscriptionsreadList all auto-renewable subscriptions within a subscription group.
list_territoriesreadList all App Store territories (countries/regions) with their currencies. Useful for understanding which markets are available for pricing.
list_usersreadList all users in your App Store Connect team. Can filter by roles.
list_version_localizationsreadList all localizations for an App Store version. Returns description, keywords, what
remove_beta_testerdestructiveRemove a beta tester from a beta group.
set_in_app_purchase_availabilitywriteSet the territory availability of an in-app purchase. Set availableInNewTerritories to auto-enable future App Store territories, and optionally restrict to a specific list of territories.
set_subscription_availabilitywriteSet the territory availability for a subscription. Controls which countries/regions the subscription is available in, and whether it is automatically available in new territories Apple adds.
update_app_info_localizationwriteUpdate an app info localization. Use this to change app name, subtitle, or privacy policy URL for a locale.
update_bundle_idwriteUpdate a bundle ID
update_in_app_purchasewriteUpdate an in-app purchase
update_in_app_purchase_localizationwriteUpdate the display name or description of an in-app purchase localization.
update_promotional_offerwriteUpdate an existing promotional offer
update_subscriptionwriteUpdate the metadata of an existing auto-renewable subscription.
update_subscription_groupwriteUpdate the reference name of a subscription group.
update_subscription_group_localizationwriteUpdate an existing subscription group localization. Can update the group name, custom app name, or custom app description.
update_subscription_localizationwriteUpdate the localized name or description for a subscription localization.
update_version_localizationwriteUpdate an existing version localization. Only provided fields will be updated.
upload_screenshotwriteUpload a new screenshot to a screenshot set. Provide the local file path, and this tool will handle the multi-step upload process.
04

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (8)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
.env.example:15
# APP_STORE_CONNECT_P8_CONTENT="-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
README.md:185
"APP_STORE_CONNECT_P8_CONTENT": "-----BEGIN PRIVATE KEY-----\nMIGT...your key here...AB12\n-----END PRIVATE KEY-----"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
README.md:448
3. Ensure the file is a valid `.p8` from Apple (starts with `-----BEGIN PRIVATE KEY-----`)
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/auth.test.ts:26
privateKeyContent: "-----BEGIN PRIVATE KEY-----\nMOCK_KEY\n-----END PRIVATE KEY-----",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_analytics_report_request, delete_bundle_id, delete_in_app_purchase, delete_in_app_purchase_localization, delete_promotional_offer, delete_subscription, delete_subscription_localization, delete_
Why it matters. 9 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/tools/screenshots.tools.ts:185
const checksum = crypto.createHash("md5").update(fileBuffer).digest("base64");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/auth.test.ts:58
privateKeyPath: "../../../etc/passwd",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, jose, undici, zod, @biomejs/biome, @types/node, tsup, tsx
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 94198312ae5ffull audit observations/trust-audit/mcp-server/sardorbekr__app-store-connect-7.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0994198312ae5fBLOCKD66first audit
06

Questions

What is the App Store Connect MCP server?

A Model Context Protocol (MCP) server for Apple's App Store Connect API

What tools does App Store Connect expose?

94 in total: 53 read-only, 32 that write, and 9 that can delete or overwrite (delete_analytics_report_request, delete_bundle_id, delete_in_app_purchase, delete_in_app_purchase_localization, delete_promotional_offer). Every one is listed on this page with its risk.

Is App Store Connect safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does App Store Connect need?

It reads APP_STORE_CONNECT_KEY_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does App Store Connect run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as asc-mcp at 1.1.0.

How current is this page?

The grade is for one exact copy of the source (94198312ae5f), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement