App Store ConnectBLOCK
A Model Context Protocol (MCP) server for Apple's App Store Connect API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/asc-mcp) [](https://opensource.org/licenses/MIT) [](https://nodejs.org)
A Model Context Protocol (MCP) server for Apple's App Store Connect API. Manage your iOS, macOS, tvOS, and visionOS apps directly from Claude, Cursor, or any MCP-compatible client.
Features
- App Store Localizations - Full CRUD for version descriptions, keywords, and what's new
- App Management - List and inspect apps across all platforms
- Version Control - Create and manage app store versions
- Beta Testing - Manage TestFlight groups and testers
- Screenshot Management - Upload and organize app screenshots
- Bundle ID Management - Full CRUD for bundle identifiers
- Device Management - List and inspect registered devices
- User Management - List and inspect team users
- Build Management - List and inspect app builds
- Category & Pricing - Browse categories, check pricing and availability
- Pricing & PPP - Set per-territory pricing with Purchase Power Parity support
- In-App Purchases - Create and manage one-time purchases (lifetime/non-consumable, consumable, non-renewing): metadata, localization, pricing & PPP, availability, and review submission (review-screenshot upload excluded)
- Analytics Reports - Request and download app analytics reports (engagement, commerce, usage, performance)
- Sales & Finance - Download sales, trends, and financial reports
- Performance & Diagnostics - App/build power & performance metrics and diagnostic logs
- Secure by Default - ES256 JWT auth with automatic token refresh, credential redaction in logs
Table of Contents
- Quick Start
- Installation
- Configuration
- [Available Tools](#available
94198312ae5fOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add asc-mcp -- npx -y [email protected]
Exposed tools (94)
53 read · 32 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Lifetime | read | Unlock forever |
Updated | read | New |
add_beta_tester | write | Add a new beta tester to a beta group by email address. |
create_analytics_report_request | write | Create a new analytics report request for an app. Use ONGOING for continuous reports or ONE_TIME_SNAPSHOT for a single snapshot. Reports take time to generate after creation. |
create_app_version | write | Create a new App Store version for an app. |
create_bundle_id | write | Register a new bundle ID in App Store Connect. The identifier must be unique and follow reverse-domain notation (e.g., com.example.app). |
create_in_app_purchase | write | Create a new in-app purchase. Defaults to NON_CONSUMABLE — a one-time |
create_in_app_purchase_localization | write | Add a localized display name (and optional description) for an in-app purchase. At least one localization is required before submission. |
create_promotional_offer | write | Create a promotional offer for a subscription. Use offerMode FREE_TRIAL for a trial offer (no prices needed). Use PAY_AS_YOU_GO or PAY_UP_FRONT for discounted paid offers and supply prices per territory. The offerCode is the string customers redeem. |
create_subscription | write | Create a new auto-renewable subscription within a subscription group. |
create_subscription_group | write | Create a new subscription group for an app. A subscription group must be created before adding individual subscriptions to it. |
create_subscription_group_localization | write | Create a localization for a subscription group. Provides the localized group name shown to users on the App Store subscription management page. |
create_subscription_localization | write | Create a localized name and description for a subscription in a specific locale. |
create_subscription_price | write | Set the price for a subscription in a specific territory. Use list_subscription_price_points to find the price point ID for the desired price tier. The price takes effect on startDate (or immediately if null). |
create_version_localization | write | Create a new localization for an App Store version. Add descriptions, keywords, and other metadata in a specific locale. |
delete_analytics_report_request | destructive | Delete an analytics report request. This stops report generation and removes access to existing reports. |
delete_bundle_id | destructive | Delete a bundle ID. Note: This cannot be undone and may affect apps using this bundle ID. |
delete_in_app_purchase | destructive | Delete an in-app purchase. Only possible before it has been approved/sold. |
delete_in_app_purchase_localization | destructive | Delete an in-app purchase localization. |
delete_promotional_offer | destructive | Delete a promotional offer from a subscription. |
delete_subscription | destructive | Delete an auto-renewable subscription. Only subscriptions in MISSING_METADATA or DEVELOPER_REMOVED_FROM_SALE state can be deleted. |
delete_subscription_localization | destructive | Delete a localization for a subscription. |
delete_version_localization | destructive | Delete a version localization. Cannot delete the primary locale. |
download_analytics_report_segment | read | Download and parse an analytics report segment from its pre-signed URL. The segment data is gzip-compressed TSV. Returns parsed headers and rows (as key-value objects). Use list_analytics_report_segments to get the download URL first. |
get_analytics_report_request | read | Get details of a specific analytics report request. |
get_app | read | Get detailed information about a specific app by its ID. |
get_app_availability | read | Get app availability information, including which territories the app is available in. |
get_app_perf_metrics | read | Get performance and power metrics for an app (e.g., launch time, memory, battery, hangs). Returns Xcode-style metrics data with values per device and percentile. Use this for app-level aggregate metrics across all builds. |
get_app_price_schedule | write | Get the price schedule for an app, including pricing information. |
get_app_version | read | Get detailed information about a specific app version. |
get_build | read | Get details of a specific build. |
get_build_perf_metrics | read | Get performance and power metrics for a specific build. Same metric types as get_app_perf_metrics but scoped to a single build. Useful for comparing performance between builds. |
get_bundle_id | read | Get details of a specific bundle ID. |
get_device | read | Get details of a specific registered device. |
get_finance_report | read | Download and parse a finance report from App Store Connect. Returns financial report data as structured rows. |
get_in_app_purchase | read | Get details of a specific in-app purchase, including its state and product ID. |
get_in_app_purchase_availability | read | Get the territory availability of an in-app purchase, including which territories it is available in. |
get_in_app_purchase_price_point_equalizations | read | Get Apple |
get_price_point_equalizations | read | Get Apple |
get_sales_report | read | Download and parse a sales report from App Store Connect. Returns tab-delimited report data as structured rows. |
get_subscription | read | Get details of a specific auto-renewable subscription by its ID. |
get_subscription_availability | read | Get the territory availability configuration for a subscription — shows which territories it is available in and whether it is automatically available in new territories. |
get_subscription_group | read | Get details of a specific subscription group by its ID. |
get_subscription_group_localization | read | Get a single subscription group localization by its ID. Returns the localized name, locale, custom app name, and description. |
get_user | read | Get details of a specific team user. |
get_version_localization | read | Get detailed information about a specific version localization. |
list_analytics_report_instances | read | List report instances (dated snapshots) for an analytics report. Each instance represents data for a specific processing date. Can filter by granularity (DAILY, WEEKLY, MONTHLY) and processing date. |
list_analytics_report_requests | read | List all analytics report requests for an app. Shows whether each request is active or stopped due to inactivity. |
list_analytics_report_segments | read | List downloadable segments for a report instance. Each segment contains a URL for downloading the report data, along with its checksum and size. |
list_analytics_reports | read | List analytics reports available for a report request. Can filter by category (APP_STORE_ENGAGEMENT, COMMERCE, APP_USAGE, FRAMEWORKS_USAGE, PERFORMANCE). |
list_app_categories | read | List all app categories available in the App Store. Can filter by platform. |
list_app_info_localizations | read | List all localizations for an app info. Returns app name, subtitle, and privacy policy info for each locale. |
list_app_infos | read | List app info records for an app. Use this to get the appInfoId needed for localization operations. |
list_app_price_points | read | List available price points for an app. Each price point represents a possible price tier showing customer price and developer proceeds in local currency. Filter by territory to see prices for a specific country. |
list_app_versions | read | List all App Store versions for an app. Can filter by platform and version state. |
list_apps | read | List all apps in your App Store Connect account. Returns app IDs, names, bundle IDs, and SKUs. |
list_beta_groups | read | List all beta groups for an app. Returns group names, public link info, and settings. |
list_beta_testers | read | List all beta testers in a specific beta group. |
list_builds | read | List all builds for an app. |
list_bundle_ids | read | List all bundle IDs registered in App Store Connect. Can filter by platform. |
list_devices | read | List all registered devices in App Store Connect. Can filter by platform and status. |
list_diagnostic_logs | read | List diagnostic logs for a specific diagnostic signature. Returns individual log entries for a given performance issue. Use list_diagnostic_signatures first to get a signature ID. |
list_diagnostic_signatures | read | List power and performance diagnostic signatures for a build. Signatures represent recurring performance issues (disk writes, hangs, slow launches) grouped by call stack. Use list_diagnostic_logs with a signature ID to get detailed logs. |
list_in_app_purchase_localizations | read | List the localized display names and descriptions for an in-app purchase. |
list_in_app_purchase_price_points | read | List available price points for an in-app purchase, showing customer price and developer proceeds. Filter by territory to find a price point ID for set_in_app_purchase_price. Supports offset-based pagination. |
list_in_app_purchase_prices | write | List the current per-territory prices set for an in-app purchase, with resolved customer price and territory. Returns developer-set (manual) prices by default; set includeAutomatic to also include Apple |
list_in_app_purchases | read | List in-app purchases for an app. Covers one-time purchases — non-consumable (a |
list_promotional_offer_prices | write | List the prices set for a promotional offer, with resolved price tier and territory details. |
list_promotional_offers | read | List all promotional offers configured for a subscription. Promotional offers target existing or previously subscribed customers via offer codes. |
list_screenshot_sets | write | List all screenshot sets for a version localization. Each set represents a different display type (device size). |
list_screenshots | write | List all screenshots in a screenshot set. |
list_subscription_group_localizations | read | List the localizations for a subscription group. These provide the localized name shown to users on the subscription management page. |
list_subscription_groups | read | List all subscription groups for an app. Subscription groups contain auto-renewable subscriptions and define upgrade/downgrade relationships. |
list_subscription_localizations | read | List all localizations (translated names and descriptions) for a subscription. |
list_subscription_price_points | read | List available price points for a subscription, showing customer price and developer proceeds. Optionally filter by territory. Use offset to paginate beyond the first 200 results. |
list_subscription_prices | write | List the current prices set for a subscription, including price tier and territory details. Use this to read existing pricing before making changes. |
list_subscriptions | read | List all auto-renewable subscriptions within a subscription group. |
list_territories | read | List all App Store territories (countries/regions) with their currencies. Useful for understanding which markets are available for pricing. |
list_users | read | List all users in your App Store Connect team. Can filter by roles. |
list_version_localizations | read | List all localizations for an App Store version. Returns description, keywords, what |
remove_beta_tester | destructive | Remove a beta tester from a beta group. |
set_in_app_purchase_availability | write | Set the territory availability of an in-app purchase. Set availableInNewTerritories to auto-enable future App Store territories, and optionally restrict to a specific list of territories. |
set_subscription_availability | write | Set the territory availability for a subscription. Controls which countries/regions the subscription is available in, and whether it is automatically available in new territories Apple adds. |
update_app_info_localization | write | Update an app info localization. Use this to change app name, subtitle, or privacy policy URL for a locale. |
update_bundle_id | write | Update a bundle ID |
update_in_app_purchase | write | Update an in-app purchase |
update_in_app_purchase_localization | write | Update the display name or description of an in-app purchase localization. |
update_promotional_offer | write | Update an existing promotional offer |
update_subscription | write | Update the metadata of an existing auto-renewable subscription. |
update_subscription_group | write | Update the reference name of a subscription group. |
update_subscription_group_localization | write | Update an existing subscription group localization. Can update the group name, custom app name, or custom app description. |
update_subscription_localization | write | Update the localized name or description for a subscription localization. |
update_version_localization | write | Update an existing version localization. Only provided fields will be updated. |
upload_screenshot | write | Upload a new screenshot to a screenshot set. Provide the local file path, and this tool will handle the multi-step upload process. |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (8)
# APP_STORE_CONNECT_P8_CONTENT="-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----"
"APP_STORE_CONNECT_P8_CONTENT": "-----BEGIN PRIVATE KEY-----\nMIGT...your key here...AB12\n-----END PRIVATE KEY-----"
3. Ensure the file is a valid `.p8` from Apple (starts with `-----BEGIN PRIVATE KEY-----`)
privateKeyContent: "-----BEGIN PRIVATE KEY-----\nMOCK_KEY\n-----END PRIVATE KEY-----",
delete_analytics_report_request, delete_bundle_id, delete_in_app_purchase, delete_in_app_purchase_localization, delete_promotional_offer, delete_subscription, delete_subscription_localization, delete_
const checksum = crypto.createHash("md5").update(fileBuffer).digest("base64");privateKeyPath: "../../../etc/passwd",
@modelcontextprotocol/sdk, jose, undici, zod, @biomejs/biome, @types/node, tsup, tsx
Gates applied: critical_finding, no_behavioural_pass.
94198312ae5ffull audit observations/trust-audit/mcp-server/sardorbekr__app-store-connect-7.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 94198312ae5f | BLOCK | D | 66 | first audit |
Questions
What is the App Store Connect MCP server?
A Model Context Protocol (MCP) server for Apple's App Store Connect API
What tools does App Store Connect expose?
94 in total: 53 read-only, 32 that write, and 9 that can delete or overwrite (delete_analytics_report_request, delete_bundle_id, delete_in_app_purchase, delete_in_app_purchase_localization, delete_promotional_offer). Every one is listed on this page with its risk.
Is App Store Connect safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does App Store Connect need?
It reads APP_STORE_CONNECT_KEY_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does App Store Connect run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as asc-mcp at 1.1.0.
How current is this page?
The grade is for one exact copy of the source (94198312ae5f), read on 2026-10-09. The repository is watched and re-audited when it changes.