
Research
Security News
The Landscape of Malicious Open Source Packages: 2025 Mid‑Year Threat Report
A look at the top trends in how threat actors are weaponizing open source packages to deliver malware and persist across the software supply chain.
asconnect is a Python wrapper around the Apple App Store Connect REST APIs.
This wrapper does not cover every API, but does cover the basics, including:
The package is available on PyPI, so you can run pip install asconnect
to get the latest version.
To begin, you need to generate a key, then get it's ID, the contents of the key itself, and the issuer ID.
Once you have those, you can create a new client by running:
client = asconnect.Client(key_id="...", key_contents="...", issuer_id="...")
Most operations require an app identifier. This is not the same as the bundle ID you choose, but is an ID generated by Apple. The easiest way to get this is to run this code:
app = client.app.get_from_bundle_id("com.example.my_bundle_id")
Uploading a build isn't technically part of the App Store Connect APIs, but a wrapper around altool is included to make things as easy as possible. Let's upload a build for your app:
client.build.upload(
ipa_path="/path/to/the/app.ipa",
platform=asconnect.Platform.ios,
)
And if you want to wait for your build to finish processing:
build = client.build.wait_for_build_to_process("com.example.my_bundle_id", build_number)
build_number
is the build number you gave your build when you created it. It's used by the app store to identify the build.
Let's take that build, create a new app store version and submit it,
# Create a new version
version = client.app.create_new_version(version="1.2.3", app_id=app.identifier)
# Set the build for that version
client.version.set_build(version_id=version.identifier, build_id=build.identifier)
# Submit for review
client.version.submit_for_review(version_id=version.identifier)
It's that easy. Most of the time at least. If you don't have previous version to inherit information from you'll need to do things like set screenshots, reviewer info, etc. All of which is possible through this library.
# Create a new version
version = client.app.create_new_version(version="1.2.3", app_id=app.identifier)
# Start a versions' phased release, the initial state of which is INACTIVE
phased_release = client.version.create_phased_release(version_id=version.identifier)
# Check on a phased release
phased_release = client.version.get_phased_release(version_id=version.identifier)
# Advance or modify a phased release
phased_release = client.version.patch_phased_release(phased_release_id=phased_release.identifier, phased_release_state=PhasedReleaseState.active)
phased_release = client.version.patch_phased_release(phased_release_id=phased_release.identifier, phased_release_state=PhasedReleaseState.pause)
phased_release = client.version.patch_phased_release(phased_release_id=phased_release.identifier, phased_release_state=PhasedReleaseState.complete)
# Delete
client.version.delete_phased_release(phased_release_id=phased_release.identifier)
For development asconnect
uses poetry
This project welcomes contributions and suggestions. Most contributions require you to agree to a Contributor License Agreement (CLA) declaring that you have the right to, and actually do, grant us the rights to use your contribution. For details, visit https://cla.opensource.microsoft.com.
When you submit a pull request, a CLA bot will automatically determine whether you need to provide a CLA and decorate the PR appropriately (e.g., status check, comment). Simply follow the instructions provided by the bot. You will only need to do this once across all repos using our CLA.
This project has adopted the Microsoft Open Source Code of Conduct. For more information see the Code of Conduct FAQ or contact opencode@microsoft.com with any additional questions or comments.
FAQs
A wrapper around the Apple App Store Connect APIs
We found that asconnect demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A look at the top trends in how threat actors are weaponizing open source packages to deliver malware and persist across the software supply chain.
Security News
ESLint now supports HTML linting with 48 new rules, expanding its language plugin system to cover more of the modern web development stack.
Security News
CISA is discontinuing official RSS support for KEV and cybersecurity alerts, shifting updates to email and social media, disrupting automation workflows.