npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@chrischall/app-store-connect-mcp

v1.2.1

Published

App Store Connect MCP server for Claude — apps, TestFlight, customer reviews, sales reports, and team users

Readme

App Store Connect MCP

CI license

A Model Context Protocol server that connects Claude to App Store Connect, giving you natural-language access to your apps, builds, TestFlight beta groups and testers, customer reviews, sales/finance reports, and team users.

[!WARNING] AI-developed project. This codebase was entirely built and is actively maintained by Claude Code. No human has audited the implementation. Review all code and tool permissions before use.

What you can do

Ask Claude things like:

  • "List my apps"
  • "Show me the latest builds for app 1234567890"
  • "Who hasn't accepted their TestFlight invitation?"
  • "Invite [email protected] to the External Beta group"
  • "Submit build 9876 for beta review"
  • "What's our average rating in Japan this month?"
  • "Respond to that 1-star review with an apology"
  • "Pull yesterday's daily sales report for vendor 80012345"
  • "Invite a new developer with App Manager role"

Requirements

Installation

Option A — npm

npx -y @chrischall/app-store-connect-mcp

Add to your Claude config (.mcp.json or Claude Desktop config):

{
  "mcpServers": {
    "app-store-connect": {
      "command": "npx",
      "args": ["-y", "@chrischall/app-store-connect-mcp"],
      "env": {
        "APP_STORE_CONNECT_KEY_ID": "ABC1234567",
        "APP_STORE_CONNECT_ISSUER_ID": "57246542-96fe-1a63-e053-0824d011072a",
        "APP_STORE_CONNECT_PRIVATE_KEY_PATH": "/absolute/path/to/AuthKey_ABC1234567.p8"
      }
    }
  }
}

Option B — from source

git clone https://github.com/chrischall/app-store-connect-mcp.git
cd app-store-connect-mcp
npm install
npm run build

Add to Claude Desktop config:

  • Mac: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json
{
  "mcpServers": {
    "app-store-connect": {
      "command": "node",
      "args": ["/absolute/path/to/app-store-connect-mcp/dist/bundle.js"],
      "env": {
        "APP_STORE_CONNECT_KEY_ID": "ABC1234567",
        "APP_STORE_CONNECT_ISSUER_ID": "57246542-96fe-1a63-e053-0824d011072a",
        "APP_STORE_CONNECT_PRIVATE_KEY_PATH": "/absolute/path/to/AuthKey_ABC1234567.p8"
      }
    }
  }
}

Getting an API key

  1. Sign in at App Store Connect → Users and Access → Integrations → App Store Connect API.
  2. Click + to generate a key. Pick a role appropriate to what you want Claude to do — Developer is enough for read-only browsing; App Manager for TestFlight management; Admin for user invites and most write operations.
  3. Download the .p8 file (you can only download it once) and note the Key ID and Issuer ID.
  4. Either point APP_STORE_CONNECT_PRIVATE_KEY_PATH at the saved .p8, or paste the PEM contents into APP_STORE_CONNECT_PRIVATE_KEY (newline-escaped is fine).

The key signs short-lived (20-minute) ES256 JWTs on demand. No external token storage; nothing is sent to anyone but Apple.

Tools

| Tool | What it does | | --- | --- | | list_apps | List apps in your account (filter by bundleId/name) | | get_app | Get a single app by ID | | list_app_store_versions | List App Store releases for an app | | get_app_infos | Age rating and store-state info for an app | | list_builds | Recent builds (newest first), filter by app/state/version | | get_build | Single build details | | list_beta_groups | TestFlight internal/external beta groups | | list_beta_testers | Beta testers, filter by app/group/email | | invite_beta_tester | Add a new tester, optionally to groups/builds | | delete_beta_tester | Remove a tester from your team | | add_testers_to_beta_group | Add existing testers to a group | | remove_testers_from_beta_group | Remove testers from a group | | submit_build_for_beta_review | Send a build for TestFlight beta review | | list_customer_reviews | App Store reviews, filter by rating/territory | | get_customer_review | Single review with developer response | | respond_to_review | Post or update a developer reply | | download_sales_report | Daily/weekly/monthly/yearly units & sales TSV | | download_finance_report | Region finance/proceeds TSV | | list_users | App Store Connect team users | | list_user_invitations | Pending team invitations | | invite_user | Invite a new team member with roles | | asc_healthcheck | Verify credentials and upstream reachability; reports failures as data, not exceptions |

Environment

| Variable | Required | Notes | | --- | --- | --- | | APP_STORE_CONNECT_KEY_ID | yes | 10-character Key ID (e.g. ABC1234567) | | APP_STORE_CONNECT_ISSUER_ID | yes | Team Issuer ID (UUID) | | APP_STORE_CONNECT_PRIVATE_KEY | one of | Full PEM contents of your .p8. Newline-escapes (\n) are accepted. | | APP_STORE_CONNECT_PRIVATE_KEY_PATH | one of | Absolute path to the .p8 file |

Confirmations

Every write (invite_beta_tester, delete_beta_tester, add_testers_to_beta_group, remove_testers_from_beta_group, submit_build_for_beta_review, respond_to_review, invite_user) asks you to confirm before anything is sent. A client that can show a confirmation prompt (Claude Code) shows one with the exact request. On a client that cannot, the first call sends nothing and returns a preview — method, path and the JSON body it will send — plus a confirmToken; only a repeat call with the same arguments and that token performs the write. A token is single-use, expires, and is refused if any argument changed since the preview.

| variable | default | | |---|---|---| | MCP_CONFIRM_MODE | ask-user | What a write does on a client that cannot show a confirmation prompt (claude.ai, Claude Desktop). ask-user: two steps — the first call does nothing and returns a preview plus a token, and the model must get your approval in chat before calling again with it. auto: the same two steps, but the model may use the token after reviewing the preview itself. refuse: writes are refused on such clients. A client that can show prompts (Claude Code) always gets the real prompt. An unrecognised value is treated as refuse. | | MCP_CONFIRM_TTL_SECONDS | 600 | How long a token stays valid. | | MCP_CONFIRM_SECRET | random per process | Signing key; set it only if tokens must survive a server restart. |

Development

npm install
npm test               # vitest run
npm run test:watch     # watch mode
npm run build          # tsc + esbuild bundle
npm run dev            # node --env-file=.env dist/index.js

Tests mock client.request / client.requestRaw; no real App Store Connect calls are made.

License

MIT