{"_id":"@emre-koc/appstore-connect-mcp","name":"@emre-koc/appstore-connect-mcp","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@emre-koc/appstore-connect-mcp","version":"0.1.0","description":"Secure, local-only stdio MCP server for the App Store Connect API","type":"module","main":"dist/index.js","types":"dist/index.d.ts","bin":{"appstore-connect-mcp":"dist/index.js"},"scripts":{"build":"tsc -p tsconfig.build.json && node scripts/set-executable.mjs","check":"tsc -p tsconfig.json --noEmit","test":"node --import tsx --test tests/**/*.test.ts","test:dist":"node scripts/dist-smoke.mjs","test:coverage":"node --import tsx --experimental-test-coverage --test tests/**/*.test.ts","prepack":"npm run check && npm test && npm run build"},"engines":{"node":">=22.0.0"},"dependencies":{"@modelcontextprotocol/sdk":"1.29.0","zod":"4.4.3"},"devDependencies":{"@types/node":"26.1.1","tsx":"4.23.1","typescript":"7.0.2"},"overrides":{"@hono/node-server":"2.0.11"},"license":"MIT","sideEffects":false,"repository":{"type":"git","url":"git+https://github.com/emre-koc/appstore-connect-mcp.git"},"bugs":{"url":"https://github.com/emre-koc/appstore-connect-mcp/issues"},"homepage":"https://github.com/emre-koc/appstore-connect-mcp#readme","publishConfig":{"access":"public"},"keywords":["app-store-connect","mcp","model-context-protocol","stdio","apple"],"gitHead":"61090e25f8a2ca65ebe78eab1cf292c0bc0fc284","_id":"@emre-koc/appstore-connect-mcp@0.1.0","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-PKZ5Natfa2a06xCz5ApCqhYAlWI5OEuae/bovYYPkza7ZHN8hPbIBb+TVF59fzLymkUyFYLuMJ+CFpKjCg4G3Q==","shasum":"8c6250132fd0b488c4ee126af06ff73487e840ea","tarball":"https://registry.npmjs.org/@emre-koc/appstore-connect-mcp/-/appstore-connect-mcp-0.1.0.tgz","fileCount":28,"unpackedSize":124453,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIB95MRyOxLHONlEWVFqque+LFzr1UjbMIJnRz150NAovAiEA63V04oRnIwluq+nUJSIzZNxwGl3VZgedlcsx5ceA4ZI="}]},"_npmUser":{"name":"emrekoc","email":"emrekoch@gmail.com"},"directories":{},"maintainers":[{"name":"emrekoc","email":"emrekoch@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/appstore-connect-mcp_0.1.0_1785236322309_0.5001448806585433"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-28T10:58:42.128Z","0.1.0":"2026-07-28T10:58:42.452Z","modified":"2026-07-28T10:58:42.673Z"},"maintainers":[{"name":"emrekoc","email":"emrekoch@gmail.com"}],"description":"Secure, local-only stdio MCP server for the App Store Connect API","homepage":"https://github.com/emre-koc/appstore-connect-mcp#readme","keywords":["app-store-connect","mcp","model-context-protocol","stdio","apple"],"repository":{"type":"git","url":"git+https://github.com/emre-koc/appstore-connect-mcp.git"},"bugs":{"url":"https://github.com/emre-koc/appstore-connect-mcp/issues"},"license":"MIT","readme":"# App Store Connect MCP\n\n[![npm version](https://img.shields.io/npm/v/@emre-koc/appstore-connect-mcp)](https://www.npmjs.com/package/@emre-koc/appstore-connect-mcp)\n[![License: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n\nA secure, local-only Model Context Protocol server for Apple's App Store Connect API.\n\n- **Transport:** stdio only — no HTTP listener, OAuth, Auth0, telemetry, or hosted relay.\n- **Credentials:** short-lived ES256 JWTs generated from a local mode-`600` `.p8` file.\n- **Network:** authenticated API calls are fixed to `https://api.appstoreconnect.apple.com`.\n- **Scope:** optional app-resource-ID allowlist, required whenever mutations are enabled.\n- **Mutations:** disabled by default and require an exact operation-specific confirmation phrase.\n- **API basis:** Apple App Store Connect OpenAPI specification **4.4.1**, downloaded from Apple's official documentation on 2026-07-26.\n\n> This project is independent and is not affiliated with or endorsed by Apple Inc.\n\n## Quick start\n\n**One-command installer** (auto-detects your coding agent):\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/emre-koc/appstore-connect-mcp/main/install.sh | bash\n```\n\nOr install manually:\n\n```bash\n# Install globally\nnpm install -g @emre-koc/appstore-connect-mcp\n\n# Or run without installing\nnpx @emre-koc/appstore-connect-mcp --env-file=~/.config/appstore-connect-mcp/env\n```\n\nList your apps (safe read-only call — no mutations):\n\n```bash\nnpx @emre-koc/appstore-connect-mcp --env-file=~/.config/appstore-connect-mcp/env \\\n  --tool=list_apps\n```\n\n## Requirements\n\n- Node.js 22 or newer\n- An App Store Connect API key with only the role needed for the tools you intend to use\n- The original `.p8` private key downloaded from App Store Connect\n\n## Security first\n\nThis server can access unpublished app data and, when explicitly enabled, change App Store Connect resources. Before using it:\n\n- create a dedicated, least-privileged App Store Connect API key;\n- keep the `.p8` key outside the repository with exact mode `600`;\n- configure `ASC_ALLOWED_APP_IDS` even for read-only use;\n- leave `ASC_ENABLE_MUTATIONS=false` unless performing a planned change;\n- review the [threat model](docs/THREAT-MODEL.md) and [security policy](SECURITY.md).\n\nNo App Store Connect credentials are needed to build or run the test suite.\n\n## Install from source\n\n```bash\ngit clone https://github.com/emre-koc/appstore-connect-mcp.git\ncd appstore-connect-mcp\nnpm ci --ignore-scripts\nnpm run check\nnpm test\nnpm run build\n```\n\nDependencies and transitive security overrides are pinned in `package-lock.json`.\n\n## Credentials\n\nDo **not** put credentials in this repository. Create a private configuration directory:\n\n```bash\nmkdir -p ~/.config/appstore-connect-mcp\ncp /secure/location/AuthKey_EXAMPLE.p8 ~/.config/appstore-connect-mcp/AuthKey_EXAMPLE.p8\nchmod 600 ~/.config/appstore-connect-mcp/AuthKey_EXAMPLE.p8\ncp .env.example ~/.config/appstore-connect-mcp/env\nchmod 600 ~/.config/appstore-connect-mcp/env\n```\n\nEdit `~/.config/appstore-connect-mcp/env` locally. Never paste its contents into an issue, commit, chat, or log.\n\nRequired variables:\n\n```dotenv\nASC_KEY_ID=YOUR_KEY_ID\nASC_ISSUER_ID=YOUR_ISSUER_ID\nASC_PRIVATE_KEY_PATH=/absolute/path/to/AuthKey_YOUR_KEY_ID.p8\n```\n\nRecommended read-only app scoping:\n\n```dotenv\nASC_ALLOWED_APP_IDS=123456789\nASC_ENABLE_MUTATIONS=false\n```\n\n`ASC_ALLOWED_APP_IDS` uses App Store Connect **resource IDs**, not bundle IDs or public numeric App Store IDs. Use `list_apps` once with mutations disabled to discover the correct ID.\n\n## Hermes configuration\n\nUse Node's built-in `--env-file` support so credentials stay out of Hermes YAML. Resolve both paths locally with `command -v node` and `pwd`; MCP client configuration requires absolute paths and does not expand `~`:\n\n```yaml\nmcp_servers:\n  appstore_connect:\n    command: \"/absolute/path/to/node\"\n    args:\n      - \"--env-file=/absolute/path/to/appstore-connect-mcp-env\"\n      - \"/absolute/path/to/appstore-connect-mcp/dist/index.js\"\n    connect_timeout: 30\n    timeout: 120\n    sampling:\n      enabled: false\n```\n\nRestart Hermes after adding the configuration. Tools appear with the `mcp_appstore_connect_` prefix.\n\n## Claude Code\n\n```bash\nclaude mcp add appstore-connect -- node --env-file=~/.config/appstore-connect-mcp/env dist/index.js\n```\n\nOr add directly to `~/.claude.json` or `.claude/settings.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"appstore-connect\": {\n      \"command\": \"node\",\n      \"args\": [\n        \"--env-file=/absolute/path/to/env\",\n        \"/absolute/path/to/appstore-connect-mcp/dist/index.js\"\n      ]\n    }\n  }\n}\n```\n\nRestart Claude Code or run `/mcp` to verify the server loaded. Tools appear without a prefix — use them directly in conversation.\n\n## Codex CLI\n\n```bash\ncodex mcp add -s user appstore-connect -- node --env-file=~/.config/appstore-connect-mcp/env dist/index.js\n```\n\nOr in `~/.codex/config.toml`:\n\n```toml\n[mcp_servers.appstore-connect]\ncommand = \"node\"\nargs = [\"--env-file=/absolute/path/to/env\", \"/absolute/path/to/appstore-connect-mcp/dist/index.js\"]\n```\n\nRestart Codex after adding. Tools appear as `mcp__appstore_connect__<tool_name>`.\n\n## OpenCode\n\n```bash\nopencode mcp add appstore-connect -- node --env-file=~/.config/appstore-connect-mcp/env dist/index.js\n```\n\nOr in `~/.config/opencode/config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"appstore-connect\": {\n      \"command\": \"node\",\n      \"args\": [\n        \"--env-file=/absolute/path/to/env\",\n        \"/absolute/path/to/appstore-connect-mcp/dist/index.js\"\n      ]\n    }\n  }\n}\n```\n\nRestart OpenCode or switch sessions. Tools are available as regular MCP tools.\n\n## Configuration reference\n\n| Variable | Required | Purpose |\n|---|---:|---|\n| `ASC_KEY_ID` | Yes | App Store Connect API key ID |\n| `ASC_ISSUER_ID` | Yes | App Store Connect API issuer ID |\n| `ASC_PRIVATE_KEY_PATH` | Yes | Absolute path to the mode-`600` `.p8` key file |\n| `ASC_ALLOWED_APP_IDS` | Recommended | Comma-separated App Store Connect app resource IDs; mandatory for mutations |\n| `ASC_ENABLE_MUTATIONS` | No | Defaults to disabled; only the exact string `true` enables writes |\n| `ASC_VENDOR_NUMBER` | No | Reserved for future sales/finance report tools |\n\n## Mutation safety\n\nMutations require all three safeguards:\n\n1. `ASC_ENABLE_MUTATIONS=true` in the private local environment file.\n2. A nonempty `ASC_ALLOWED_APP_IDS` allowlist.\n3. The exact confirmation phrase in the tool call:\n\n```text\nEXECUTE <operation_name> FOR <app_resource_id>\n```\n\nExample:\n\n```text\nEXECUTE create_in_app_purchase_v2 FOR 123456789\n```\n\nKeep mutations disabled for normal inspection. Enable them only for a planned change, restart the MCP process, execute the change, then disable them again.\n\n## Tools\n\n### Read-only\n\n- `asc_status`\n- `list_apps`, `get_app`\n- `list_builds`, `get_build`\n- `list_app_store_versions`, `get_app_store_version`\n- `list_version_localizations`\n- `list_in_app_purchases_v2`, `get_in_app_purchase_v2`\n- `list_in_app_purchase_versions`\n- `list_in_app_purchase_version_localizations`\n- `list_in_app_purchase_price_points`\n- `get_in_app_purchase_price_schedule`\n- `get_in_app_purchase_availability`\n- `list_territories`\n- `list_beta_groups`\n- `list_review_submissions`\n\n### Mutating\n\n- `create_app_store_version`, `update_app_store_version`\n- `attach_build_to_version`\n- `create_version_localization`, `update_version_localization`\n- `create_in_app_purchase_v2`, `update_in_app_purchase_v2`\n- `create_in_app_purchase_version`\n- `create_in_app_purchase_localization_v2`\n- `create_in_app_purchase_availability`\n- `create_in_app_purchase_price_schedule`\n- `create_in_app_purchase_review_item`\n- `create_beta_group`, `create_beta_tester`\n- `add_beta_testers_to_group`, `add_builds_to_beta_group`\n- `create_review_submission`, `submit_review_submission`\n\n## Current IAP workflow\n\nApple's 4.4.1 API separates the IAP resource, editable version/localizations, availability, pricing, and unified review submission:\n\n1. `list_apps` — obtain and allowlist the app resource ID.\n2. `create_in_app_purchase_v2` — create the product (`NON_CONSUMABLE`, `CONSUMABLE`, or `NON_RENEWING_SUBSCRIPTION`).\n3. `create_in_app_purchase_version` — create the editable IAP version.\n4. `create_in_app_purchase_localization_v2` — attach name/description to that version.\n5. `list_in_app_purchase_price_points` — select Apple's price-point resource ID for a territory.\n6. `create_in_app_purchase_price_schedule` — set the base territory and manual price.\n7. `create_in_app_purchase_availability` — choose territories.\n8. Add required review media in App Store Connect until the local asset-upload tool is released.\n9. `create_review_submission` — create the app's unified review submission.\n10. `create_in_app_purchase_review_item` — add the verified IAP version to that submission.\n11. `submit_review_submission` only after reviewing every submission item in App Store Connect.\n\nThe server uses V2 IAP creation/update and V2 localization creation. Localization listing is version-scoped through `/v1/inAppPurchaseVersions/{id}/localizations`, and review uses unified `reviewSubmissionItems`; the deprecated parent-scoped localization and standalone IAP-submission workflows are not exposed. Price schedules and availability remain on Apple's current V1 create endpoints because that is what OpenAPI 4.4.1 defines.\n\n## Development\n\n```bash\nnpm test\nnpm run test:coverage\nnpm run check\nnpm run build\nnpm audit --omit=dev\nnpm pack --dry-run\n```\n\nSee:\n\n- [API coverage](docs/API-COVERAGE.md)\n- [Threat model](docs/THREAT-MODEL.md)\n- [Security policy](SECURITY.md)\n- [Contributing](CONTRIBUTING.md)\n\n## Official sources\n\n- [App Store Connect API](https://developer.apple.com/documentation/appstoreconnectapi)\n- [Official OpenAPI specification](https://developer.apple.com/sample-code/app-store-connect/app-store-connect-openapi-specification.zip)\n- [Generating tokens for API requests](https://developer.apple.com/documentation/appstoreconnectapi/generating-tokens-for-api-requests)\n- [API release notes](https://developer.apple.com/documentation/appstoreconnectapi/app-store-connect-api-release-notes)\n- [Identifying rate limits](https://developer.apple.com/documentation/appstoreconnectapi/identifying-rate-limits)\n\n## License\n\nMIT. See [LICENSE](LICENSE).\n","readmeFilename":"README.md","_rev":"1-e973ee50087740118da61cde80feb3fd"}