One remote endpoint, bounded authority
An agent can be useful only if it can reach the real project safely. AppStore Copilot provides a remote MCP endpoint, OAuth and scoped credential paths, project selection, rate limits, idempotency, and a public capability manifest.
Internal administration and provider operations are excluded from public discovery. Read, write, asset generation, and publishing authority remain distinct so a connection does not become permission to change everything.
- Remote MCP endpoint at appstorecopilot.com/api/mcp
- OAuth 2.1 and scoped project authorization
- Reviewed tool descriptions, schemas, and safety annotations
- Durable tasks for longer generation and publishing work
- Explicit approval before live store mutations