API KEY

App Store Connect MCP server, with a policy gate.

Connect App Store Connect to your agents with the .p8 key held server-side — not pasted into an agent's JSON config — reads free, and writes behind per-purpose grants.

Your agents connect tohttps://app.gentkey.com/mcpclaude.ai (web & mobile) · Claude Code · Cursor · any MCP client
ACCESS MODEL

What’s free, what needs a grant.

Reads: Apps, builds, TestFlight groups and testers, customer reviews, and sales and analytics reports work with no grant.

Writes: TestFlight tester changes, build distribution, and App Review submissions require explicit grants, attributed per agent.

GrantWhat it governs
app-store-connect.readApps, builds, TestFlight, reviews, sales and analytics reports — on by default
app-store-connect.write.testerAdding and removing TestFlight testers
app-store-connect.write.betaDistributing builds to TestFlight groups and expiring builds
app-store-connect.write.reviewSubmitting an App Store version for App Review
SETUP

Connect once, use everywhere.

Sign in at gentkey.com, add App Store Connect (api key), then point each client at your endpoint. Every client completes a standard OAuth flow and lands in your Gentkey — your connections, nobody else’s.

claude.ai (web & mobile)

  1. Settings → Connectors
  2. Add custom connector
  3. Paste https://app.gentkey.com/mcp and finish the OAuth prompt

Claude Code

claude mcp add --transport http \
  gentkey https://app.gentkey.com/mcp

Cursor

// .cursor/mcp.json
{
  "mcpServers": {
    "gentkey": { "url": "https://app.gentkey.com/mcp" }
  }
}
IN PRACTICE

Things agents do with App Store Connect here.

  • What's the crash-free rate on the latest build?
  • Summarize this week's customer reviews and flag the angry ones.
  • Add beta-tester@example.com to the external TestFlight group.
  • How did downloads trend after the last release?
SECURITY

Custody, gating, and audit — built in.

aes-256-gcm

The model never sees a credential

Your App Store Connect key is encrypted at rest and injected server-side at call time. Your stored credential never enters a context window.

grants

Writes need a grant

Anything that changes state needs a capability you granted explicitly — revoke it and the next call is denied.

audit_log

A trail you can act on

Every decision is attributed to the agent that made it — allowed, denied, or denied by constraint.

FAQ

Fair questions.

Where does my App Store Connect API key live?

Encrypted at rest on Gentkey's server (AES-256-GCM) and used only at call time. The usual alternative — a .p8 private key pasted into an MCP server's local JSON config — leaves Apple credentials in plaintext on every machine an agent runs on.

What happens when an agent calls a App Store Connect write tool it hasn't been granted?

The call is denied at the gateway — nothing reaches App Store Connect — and the denial is recorded in the audit log along with the grant that would have authorized it, so you can decide deliberately instead of finding out later.

Where are my credentials stored?

Encrypted at rest (AES-256-GCM) on Gentkey's server and injected server-side at call time. No credential you store with Gentkey ever enters a model's context window or an agent's config file.

Can I use this from claude.ai's free plan?

Yes — and it's the strongest case for a gateway: free claude.ai accounts currently get a single custom connector, so pointing that one slot at Gentkey puts every connector you've linked behind it.

How do I revoke an agent's access?

Revoke the grant (the next write is denied) or revoke the agent's tokens entirely in one click. Other agents and their grants are untouched — no shared key to rotate.

Is Gentkey affiliated with App Store Connect?

No. Gentkey is an independent MCP gateway. Trademarks belong to their owners; where an official App Store Connect MCP server exists, Gentkey proxies it and adds custody, gating, and audit on top.

Cut App Store Connect a smaller key.

Sign in, connect App Store Connect, and grant your first scoped capability in under a minute.