App Store ConnectCAUTION
Code Mode MCP server for App Store Connect — 923 endpoints through 2 tools
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
923 endpoints. 2 tools. The spec IS the implementation.
[](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io) [](https://opensource.org/licenses/MIT) [](https://developer.apple.com/app-store-connect/api/)
The Problem
Traditional MCP servers wrap each API endpoint as a separate tool. Apple's App Store Connect API has 923 endpoints. That means 923 tool definitions, ~100K+ context tokens, and a new release every time Apple adds an endpoint.
The Solution
Code Mode: 2 tools replace 923.
The LLM writes the query. The spec IS the implementation. Adding endpoints = Apple updates their spec. Zero code changes on our side.
Traditional MCP: 923 endpoints → 923 tools → ~100K tokens → constant maintenance Code Mode: 923 endpoints → 2 tools → ~1K tokens → zero maintenance
Quick Start
1. Get App Store Connect credentials
- Go to App Store Connect → Users and Access → Integrations → Keys
- Click "+" to generate a new key (Admin or Finance role)
- Download the
.p8file (only downloadable once!) - Note your Key ID and Issuer ID
2. Install via Claude Code
claude mcp add appstore-connect -s user \ -e APP_STORE_KEY_ID=YOUR_KEY_ID \ -e APP_STORE_ISSUER_ID=YOUR_ISSUER_ID \ -e APP_STORE_P8_PATH=/absolute/path/to/AuthKey_XXXXXXXXXX.p8 \ -e APP_STORE_VENDOR_NUMBER=YOUR_VENDOR_NUMBER \ -- npx -y @trialanderror-ai/
2143a5356273OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add appstore-connect-mcp --env APP_STORE_KEY_ID=${APP_STORE_KEY_ID} -- npx -y @trialanderror-ai/[email protected]{
"mcpServers": {
"appstore-connect-mcp": {
"command": "npx",
"args": [
"-y",
"@trialanderror-ai/[email protected]"
],
"env": {
"APP_STORE_KEY_ID": "${APP_STORE_KEY_ID}"
}
}
}
}Exposed tools (3)
1 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
execute | write | Write JavaScript to call the App Store Connect API. Authentication is automatic (JWT injected). **Before using this tool**, load the companion cookbook at \ |
search | write | Write JavaScript to explore the App Store Connect API specification (${this.spec.pathCount} endpoints, ${this.spec.schemaCount} schemas, API v${this.spec.info.version}). **Before using this tool**, load the companion cookbook at \ |
test_connection | read | Test connection to App Store Connect API and show server info |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
console.log(`Token length: ${token.length} characters`);console.log(`\n⏰ Token expires at: ${expDate.toLocaleString()}`);@modelcontextprotocol/sdk, axios, dotenv, jsonwebtoken, @types/jsonwebtoken, @types/node, tsx, typescript
src/spec/openapi.json
- **Admin** for full access
Gates applied: no_behavioural_pass.
2143a5356273full audit observations/trust-audit/mcp-server/trialanderrorai__app-store-connect-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2143a5356273 | CAUTION | B | 89 | first audit |
Questions
What is the App Store Connect MCP server?
Code Mode MCP server for App Store Connect — 923 endpoints through 2 tools
What tools does App Store Connect expose?
3 in total: 1 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is App Store Connect safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does App Store Connect need?
It reads APP_STORE_KEY_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does App Store Connect run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @trialanderror-ai/appstore-connect-mcp at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (2143a5356273), read on 2026-10-08. The repository is watched and re-audited when it changes.