App Store Connect MCP server

Give your agent scoped tools for the app stores

AppStore Copilot is a remote MCP server for app-store operations. It lets a compatible agent inspect and prepare work through a reviewed public tool surface without placing store private keys or service-account files in the conversation.

Remote MCPDiscoverable

appstorecopilot

https://appstorecopilot.com/api/mcp

OAuth 2.1 · project scoped

Dry run · human approval

01

One remote endpoint, bounded authority

An agent can be useful only if it can reach the real project safely. AppStore Copilot provides a remote MCP endpoint, OAuth and scoped credential paths, project selection, rate limits, idempotency, and a public capability manifest.

Internal administration and provider operations are excluded from public discovery. Read, write, asset generation, and publishing authority remain distinct so a connection does not become permission to change everything.

  • Remote MCP endpoint at appstorecopilot.com/api/mcp
  • OAuth 2.1 and scoped project authorization
  • Reviewed tool descriptions, schemas, and safety annotations
  • Durable tasks for longer generation and publishing work
  • Explicit approval before live store mutations
02

Credentials stay out of the chat

The secure setup flow handles App Store Connect keys, Google Play service accounts, API keys, and one-time pairing material outside the agent conversation. Tools receive only the authority needed for the selected project and operation.

Store metadata, screenshot text, URLs, and provider responses are treated as untrusted data. Instructions embedded in that content do not broaden the agent’s authority.

03

Designed for discovery and inspection

Agents and directories can read the public MCP discovery file, capability manifest, OAuth resource metadata, llms.txt summary, and human setup guide before a customer connects an account. The actual tool list remains the source of truth after authentication.

The workflow

01

Discover the server

Read the public MCP metadata, capabilities, authorization endpoints, and agent guide.

02

Authorize a project

Use the secure onboarding or OAuth flow to grant the agent a bounded project scope.

03

Inspect before writing

List the current store state and prepare a dry run or proposal for the requested work.

04

Approve the mutation

Authorize the exact publish task only after reviewing its scope and proposed changes.

Questions

What teams ask first.

What is an App Store Connect MCP server?
It is a server that exposes app-store operations as tools an MCP-compatible AI agent can inspect and call. AppStore Copilot adds project scoping, secure authorization, and approval controls around those tools.
Which AI agents can connect to AppStore Copilot?
Any client that supports the required remote MCP and authorization flow can connect. The public setup guides cover ChatGPT, Claude, Codex, Cursor, and compatible agent clients.
Do I paste my App Store Connect private key into ChatGPT or Claude?
No. Store credentials and pairing codes belong in AppStore Copilot’s secure setup flow, not in the AI conversation.

Give the agent a project. Keep the final say.

Connect one app, run the first audit, and review every live-store change before it ships.

Start free