
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
asc-mcp-server
Advanced tools
MCP server for Apple App Store Connect API — manage apps, builds, TestFlight, reviews and more
An MCP (Model Context Protocol) server that wraps Apple's App Store Connect API, giving AI assistants the ability to manage apps, builds, TestFlight, reviews, and more — right from your IDE.
.p8 private key file.claude mcp add appstore-connect \
--transport stdio \
--env ASC_KEY_ID=YOUR_KEY_ID \
--env ASC_ISSUER_ID=YOUR_ISSUER_ID \
--env ASC_PRIVATE_KEY_PATH=/absolute/path/to/AuthKey.p8 \
-- npx -y asc-mcp-server
Add to your claude_desktop_config.json:
| OS | Path |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json |
{
"mcpServers": {
"appstore-connect": {
"command": "npx",
"args": ["-y", "asc-mcp-server"],
"env": {
"ASC_KEY_ID": "YOUR_KEY_ID",
"ASC_ISSUER_ID": "YOUR_ISSUER_ID",
"ASC_PRIVATE_KEY_PATH": "/absolute/path/to/AuthKey.p8"
}
}
}
}
Add to .cursor/mcp.json in your project (or ~/.cursor/mcp.json for global):
{
"mcpServers": {
"appstore-connect": {
"command": "npx",
"args": ["-y", "asc-mcp-server"],
"env": {
"ASC_KEY_ID": "YOUR_KEY_ID",
"ASC_ISSUER_ID": "YOUR_ISSUER_ID",
"ASC_PRIVATE_KEY_PATH": "/absolute/path/to/AuthKey.p8"
}
}
}
}
Verify under Cursor Settings → MCP after restarting.
Add to ~/.gemini/antigravity/mcp_config.json (or via Agent pane → MCP Servers → Manage MCP Servers → View raw config):
{
"mcpServers": {
"appstore-connect": {
"command": "npx",
"args": ["-y", "asc-mcp-server"],
"env": {
"ASC_KEY_ID": "YOUR_KEY_ID",
"ASC_ISSUER_ID": "YOUR_ISSUER_ID",
"ASC_PRIVATE_KEY_PATH": "/absolute/path/to/AuthKey.p8"
}
}
}
}
Tip: Run
npx -y asc-mcp-serveronce in your terminal first so the package is cached — Antigravity's first-run timeout can otherwise cause the server to fail to start.
| Tool | Description |
|---|---|
list_apps | List all apps in your App Store Connect account |
get_app | Get details for a specific app |
list_builds | List builds, optionally filtered by app or state |
get_build | Get details for a specific build |
list_app_versions | List App Store versions for an app |
get_app_version | Get details for a specific version |
submit_for_review | Submit an app version for App Store review |
list_beta_groups | List TestFlight beta groups |
list_beta_testers | List TestFlight beta testers |
add_beta_tester | Add a tester to a beta group |
list_users | List team members |
list_devices | List registered devices |
list_bundle_ids | List bundle IDs |
list_customer_reviews | List customer reviews for an app |
respond_to_review | Respond to a customer review |
list_certificates | List signing certificates |
list_profiles | List provisioning profiles |
list_in_app_purchases | List in-app purchases for an app |
list_subscriptions | List subscription groups for an app |
get_sales_report | Download sales and financial reports |
MIT
FAQs
MCP server for Apple App Store Connect API — manage apps, builds, TestFlight, reviews and more
We found that asc-mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.