Overview

asc-mcp is a Swift-based MCP server that connects a local macOS MCP client to the App Store Connect API. It exposes 502 tools across 33 App Store tool domains + 2 core domains, enabling you to automate iOS and macOS release workflows through natural language.

Configuration examples are included for Codex, Claude Code, Claude Desktop, Gemini CLI, VS Code with GitHub Copilot, Continue, Cursor, and Devin Desktop (formerly Windsurf). Client configuration is documented; release CI verifies installation, MCP initialization, and tool discovery on macOS rather than launching every third-party client.

New here? Follow the Quick Start. The remaining sections are reference material for advanced configuration, tool selection, and contributors.

Key capabilities

  • Release and metadata — versions, localizations, builds, review submissions, phased rollout, and Xcode Cloud
  • TestFlight and uploads — beta groups, testers, feedback, recruitment, build delivery, processing, and export compliance
  • Monetization — in-app purchases, subscriptions, pricing, availability, offer codes, and promotional offers
  • Marketing — screenshots, previews, custom product pages, product page optimization, and promoted purchases
  • Accounts and provisioning — multiple App Store Connect teams, users, bundle IDs, devices, certificates, profiles, and capabilities
  • Feedback and operations — customer reviews, webhooks, accessibility declarations, analytics, metrics, and diagnostics
  • Safer automation — read-only mode, confirmation safeguards, strict pagination, and mutation recovery guidance
  • Auditable API coverage — a versioned Apple OpenAPI contract and release-time drift checks

Platform Support

asc-mcp is a local stdio server: the MCP client starts it on the same computer. A client being available on Linux or Windows does not make this Swift server cross-platform.

Environment Status Notes
macOS 15.6+ with Xcode 26.x Recommended Release CI specifically uses GitHub's macOS 15 runner with Xcode 26.2
macOS 14.0-15.5 Declared deployment target only Build and runtime are unverified; a separately installed Swift 6.2+ toolchain may be needed
Linux Not supported yet Porting work and Linux CI are not complete
Windows Not supported Current source dependencies and Swift MCP stdio transport are not Windows-compatible

See Apple's Xcode system requirements for the macOS versions supported by each Xcode release.

Web and cloud sessions do not automatically inherit a local MCP configuration. Run the MCP client locally on a compatible Mac, or use a client feature that explicitly keeps execution on that Mac.

Quick Start

The recommended setup stores App Store Connect credentials once in a private local file. MCP clients then need only the path to the asc-mcp executable.

1. Install asc-mcp

brew install mint
mint install zelentsov-dev/[email protected]
~/.mint/bin/asc-mcp --version

2. Create an App Store Connect API key

  1. Open App Store Connect → Users and Access → Integrations → Team Keys.
  2. Generate a key with the least-privileged role that covers your workflow. App Manager or Admin is needed only when the corresponding operations require it.
  3. Download the .p8 file. Apple allows it to be downloaded only once.
  4. Copy the Key ID and Issuer ID.

3. Save the credentials locally

Create private configuration directories, then move the downloaded .p8 file into ~/.keys/. Replace the source path and filename in the second command:

mkdir -p ~/.config/asc-mcp ~/.keys
chmod 700 ~/.config/asc-mcp ~/.keys
mv /path/to/downloaded/AuthKey_XXXXXXXXXX.p8 ~/.keys/

Create ~/.config/asc-mcp/companies.json:

{
  "companies": [
    {
      "id": "my-company",
      "name": "My Company",
      "key_id": "XXXXXXXXXX",
      "issuer_id": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
      "key_path": "/Users/you/.keys/AuthKey_XXXXXXXXXX.p8"
    }
  ]
}

Replace /Users/you with your actual home-directory path. Keep both files outside the repository and restrict access:

chmod 600 ~/.config/asc-mcp/companies.json
chmod 600 /Users/you/.keys/AuthKey_XXXXXXXXXX.p8

[!CAUTION] Never commit companies.json, a .p8 key, or raw credentials to Git. Revoke the App Store Connect key immediately if it is exposed.

4. Connect your MCP client

Choose one client. You do not need to configure every client.

Codex

codex mcp add asc-mcp -- ~/.mint/bin/asc-mcp
codex mcp list

Claude Code

claude mcp add \
  --transport stdio \
  --scope user \
  asc-mcp \
  -- ~/.mint/bin/asc-mcp

claude mcp get asc-mcp
claude mcp list

For Claude Desktop, Gemini CLI, VS Code, Continue, Cursor, and Devin Desktop, use the ready-to-copy examples in MCP Client Setup.

5. Try it

Restart a GUI client after changing its configuration, open its MCP tool list, and ask:

List my App Store Connect apps.

If the connection or request fails, see Troubleshooting.

Installation

Mint on macOS (recommended)

Mint installs the pinned release from source and keeps the executable at ~/.mint/bin/asc-mcp.

brew install mint
mint install zelentsov-dev/[email protected]

Update or reinstall the pinned release:

mint install zelentsov-dev/[email protected] --force

Stable users should install a version tag. Installing main or develop is intended only for maintainers and pre-release testing.

Build from source

Use Xcode 26.x on a compatible macOS version, or install a standalone Swift 6.2+ toolchain.

git clone https://github.com/zelentsov-dev/asc-mcp.git
cd asc-mcp
swift build -c release

The executable is .build/release/asc-mcp. If you copy it elsewhere, also copy the adjacent resource bundle:

cp .build/release/asc-mcp /usr/local/bin/asc-mcp
cp -R .build/release/asc-mcp_asc-mcp.bundle /usr/local/bin/

The bundle contains the versioned OpenAPI operation contract used by release checks.

Upgrading from an older release

Version 4.1 keeps every existing tool name, required input, projection key, and array shape. Xcode Cloud read tools now reject undocumented arguments and validate returned links, paging, relationship lineage, and included resources more strictly. New *Present projection fields distinguish Apple-omitted arrays from present empty arrays while legacy array fields remain arrays. Newly exposed nested *_limit inputs must be paired with their matching include value, and continuation calls must repeat the original request scope unchanged. The new product and workflow delete tools default to a safe preview and require the latest preview receipt plus exact inventory confirmation before permanent deletion.

Version 4 keeps every existing tool name and worker filter, but destructive Marketing and review-attachment calls now require an exact confirmation ID before any Apple request:

Existing tool New required confirmation
custom_pages_delete confirm_page_id
ppo_delete_experiment confirm_experiment_id
promoted_delete confirm_promoted_purchase_id
review_attachments_delete confirm_attachment_id
screenshots_delete_set, screenshots_delete_preview_set confirm_set_id
screenshots_delete confirm_screenshot_id
screenshots_delete_preview confirm_preview_id

ppo_update_experiment also requires confirm_experiment_id when state is supplied. Calls that update only name or traffic proportion remain unchanged. After an unknown or committed_unverified mutation result, use the returned inspection action before retrying.

Remove undocumented top-level arguments from existing Marketing and review-attachment calls. Version 4 rejects unknown keys before any network request instead of silently ignoring them.

Configuration

Credentials

The default ~/.config/asc-mcp/companies.json file shown in the Quick Start is recommended because it works consistently for terminal and GUI clients without duplicating secrets in every client configuration.

For multiple companies, add more entries:

{
  "companies": [
    {
      "id": "my-company",
      "name": "My Company",
      "key_id": "XXXXXXXXXX",
      "issuer_id": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
      "key_path": "/Users/you/.keys/AuthKey_XXXXXXXXXX.p8",
      "vendor_number": "YOUR_VENDOR_NUMBER"
    },
    {
      "id": "client-company",
      "name": "Client Company",
      "key_id": "YYYYYYYYYY",
      "issuer_id": "yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyyyy",
      "key_path": "/Users/you/.keys/AuthKey_YYYYYYYYYY.p8"
    }
  ]
}

vendor_number is required only for analytics_sales_report, analytics_financial_report, and analytics_app_summary. Find it in App Store Connect → Sales and Trends → Reports.

Environment variables are useful for automation, but GUI apps launched from Finder may not inherit your shell environment. The file-based setup above is simpler for most users.

Single company:

export ASC_KEY_ID=XXXXXXXXXX
export ASC_ISSUER_ID=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
export ASC_PRIVATE_KEY_PATH=/Users/you/.keys/AuthKey_XXXXXXXXXX.p8
export ASC_COMPANY_NAME="My Company"                 # optional
export ASC_VENDOR_NUMBER=YOUR_VENDOR_NUMBER          # optional, analytics only

Multiple companies:

export ASC_COMPANY_1_NAME="My Company"
export ASC_COMPANY_1_KEY_ID=XXXXXXXXXX
export ASC_COMPANY_1_ISSUER_ID=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
export ASC_COMPANY_1_KEY_PATH=/Users/you/.keys/AuthKey_XXXXXXXXXX.p8

export ASC_COMPANY_2_NAME="Client Company"
export ASC_COMPANY_2_KEY_ID=YYYYYYYYYY
export ASC_COMPANY_2_ISSUER_ID=yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyyyy
export ASC_COMPANY_2_KEY_PATH=/Users/you/.keys/AuthKey_YYYYYYYYYY.p8

Numbering starts at 1. Each consecutive entry must provide both ASC_COMPANY_{N}_KEY_ID and ASC_COMPANY_{N}_ISSUER_ID; scanning stops at the first missing pair.

The server resolves credentials in this order:

  1. --companies /absolute/path/to/companies.json
  2. Constructor parameter for programmatic embedding
  3. ASC_MCP_COMPANIES=/absolute/path/to/companies.json
  4. Default configuration file locations, including ~/.config/asc-mcp/companies.json
  5. ASC_COMPANY_1_KEY_ID and the other numbered multi-company variables
  6. ASC_KEY_ID, ASC_ISSUER_ID, and a private-key variable for one company

MCP Client Setup

All examples below assume a Mint installation and the recommended companies.json credential file. Replace /Users/you with your actual home-directory path. GUI clients generally require an absolute executable path.

Client Configuration scope Notes
Codex User config by CLI; optional trusted-project config Shared by local Codex clients on the same Mac
Claude Code user, local, or project scope user is simplest for a personal App Store utility
Claude Desktop User-level desktop config Restart after editing
Gemini CLI User settings Local stdio server
VS Code with GitHub Copilot User profile or .vscode/mcp.json Confirm server trust on first start
Continue Workspace .continue/mcpServers/ Separate from native VS Code MCP configuration
Cursor User or project mcp.json Use an absolute command path
Devin Desktop (formerly Windsurf) User MCP config Keep no more than 100 active tools

Recommended CLI registration:

codex mcp add asc-mcp -- ~/.mint/bin/asc-mcp
codex mcp list
codex mcp get asc-mcp --json

The same local MCP configuration is shared by Codex clients on that Mac. The user configuration is $CODEX_HOME/config.toml, which defaults to ~/.codex/config.toml:

[mcp_servers.asc-mcp]
command = "/Users/you/.mint/bin/asc-mcp"
startup_timeout_sec = 20
tool_timeout_sec = 60
enabled = true

For a project-specific setup, place the same table in .codex/config.toml; Codex loads project configuration only after the project is trusted. If you use shell credentials instead of companies.json, explicitly forward them:

env_vars = ["ASC_KEY_ID", "ASC_ISSUER_ID", "ASC_PRIVATE_KEY_PATH"]

Restart a GUI client after changing the configuration, then use its MCP view or /mcp to confirm that asc-mcp is active. See the official Codex MCP documentation.

Register once for all local projects:

claude mcp add \
  --transport stdio \
  --scope user \
  asc-mcp \
  -- ~/.mint/bin/asc-mcp

claude mcp get asc-mcp
claude mcp list

Use --scope local for only the current project or --scope project to create a shared .mcp.json. Project servers require trust approval. Never place raw App Store Connect credentials in a committed .mcp.json.

Claude stores user and local MCP entries in ~/.claude.json; .claude/settings.json is not the global MCP registry. Use /mcp inside Claude Code to inspect or reconnect the server. See the official Claude Code MCP documentation.

Add the server to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "asc-mcp": {
      "command": "/Users/you/.mint/bin/asc-mcp"
    }
  }
}

Quit and reopen Claude Desktop after saving the file.

Add the server to ~/.gemini/settings.json:

{
  "mcpServers": {
    "asc-mcp": {
      "command": "/Users/you/.mint/bin/asc-mcp"
    }
  }
}

The default Gemini MCP timeout is intentionally retained. See the official Gemini CLI MCP documentation.

Run MCP: Add Server from the Command Palette and choose the user profile for a personal setup. For a workspace setup, create .vscode/mcp.json:

{
  "servers": {
    "asc-mcp": {
      "type": "stdio",
      "command": "/Users/you/.mint/bin/asc-mcp"
    }
  }
}

Confirm that you trust the local server when VS Code first starts it. Do not commit user-specific paths or secrets in a shared workspace file. See the official VS Code MCP documentation.

Continue does not use .vscode/mcp.json. Create .continue/mcpServers/asc-mcp.json in the workspace:

{
  "mcpServers": {
    "asc-mcp": {
      "command": "/Users/you/.mint/bin/asc-mcp"
    }
  }
}

MCP tools are available in Continue agent mode. See the official Continue MCP documentation.

Use ~/.cursor/mcp.json for all projects or .cursor/mcp.json for one project:

{
  "mcpServers": {
    "asc-mcp": {
      "command": "/Users/you/.mint/bin/asc-mcp"
    }
  }
}

Restart or refresh the MCP server from Cursor settings after editing the file. See the official Cursor MCP documentation.

Add the server to ~/.codeium/windsurf/mcp_config.json. This example enables a 72-tool release subset, below Cascade's 100-tool limit:

{
  "mcpServers": {
    "asc-mcp": {
      "command": "/Users/you/.mint/bin/asc-mcp",
      "args": [
        "--workers",
        "apps,builds,export_compliance,versions,reviews"
      ]
    }
  }
}

You can also disable individual tools in the client. Server-side worker filtering is recommended because it keeps the active catalog predictable. See the official Devin Desktop MCP documentation.

[!IMPORTANT] command must point to the real executable. GUI clients often do not inherit shell aliases, PATH changes, or environment variables. Use an absolute path and prefer the default companies.json credential file.

Worker Filtering

The server exposes 502 tools across 33 App Store tool domains + 2 core domains. Some MCP clients impose a tool limit; Cascade in Devin Desktop currently allows 100 active tools. Use the 35 --workers filter keys to enable only the workers you need:

# Only load apps, builds, and version lifecycle tools
asc-mcp --workers apps,builds,versions

# App Store release preparation subset (99 tools, including always-on and build sub-workers)
asc-mcp --workers apps,accessibility,builds,export_compliance,versions,app_info,screenshots

# TestFlight review helpers can be loaded separately (49 tools)
asc-mcp --workers apps,builds,beta_app,pre_release

# Monetization focus
asc-mcp --workers apps,iap,subscriptions,pricing,promoted,review_submissions

company and auth workers are always enabled regardless of the filter (they provide core multi-account and authentication functionality).

When builds is enabled, it automatically includes build_processing and build_beta sub-workers.

Read-Only Mode

Use --read-only when you want safe inspection without App Store Connect mutations:

asc-mcp --read-only
asc-mcp --read-only --workers apps,builds,reviews,analytics

In this mode, read tools such as *_list, *_get, *_search, *_status, *_verify, *_parse, *_triage, auth_*, analytics, and metrics remain available. Tools that can create, update, upload, submit, release, delete, revoke, clear, cancel, or otherwise mutate App Store Connect are blocked before their worker handler runs. company_switch remains available because it changes only the local active company context.

OpenAPI Contract and Drift Tooling

Use the operation-contract command to compare the actual credential-free WorkerManager catalog with the semantic manifest and the pinned Apple App Store Connect OpenAPI specification. The production manifest records exact Apple operationId, HTTP method, path, invocation-scoped input bindings, typed fixed values, response lineage, local workflows, implementation state, deprecated aliases, and deliberately deferred operations. The command does not load App Store Connect credentials or start the MCP server.

rm -rf /tmp/asc-openapi
mkdir -p /tmp/asc-openapi
curl -L --fail -o /tmp/asc-openapi/spec.zip \
  https://developer.apple.com/sample-code/app-store-connect/app-store-connect-openapi-specification.zip
spec_entry="$(unzip -Z1 /tmp/asc-openapi/spec.zip | grep -E '(^|/)openapi\.oas[^/]*\.json$')"
test "$(echo "$spec_entry" | grep -c .)" -eq 1
unzip -p /tmp/asc-openapi/spec.zip "$spec_entry" > /tmp/asc-openapi/openapi.oas.json

swift run asc-mcp openapi-contract-check \
  --spec /tmp/asc-openapi/openapi.oas.json \
  --json-output /tmp/asc-openapi/operation-contract.json \
  --markdown-output /tmp/asc-openapi/operation-contract.md \
  --strict

The manifest is pinned to Apple API 4.4.1 by version, SHA-256, path count, and operation count. It currently maps 476 Apple operations, explicitly defers 424, and scopes out 363, covering all 1,263 operations without overlap. CI fails when the Apple document changes, a mapped operation moves or disappears, a public tool or worker drifts from the manifest, an input field loses its binding, response lineage becomes invalid, or a deferred decision expires. Unexposed optional Apple parameters are warnings so they remain visible in the generated backlog.

Manifest schema v2 also accounts for every optional Apple query and request-body input as publicly bound, internally controlled, intentionally omitted with a reviewed reason, or still unclassified. The checked-in optionalInputCoveragePin records the exact current totals and a SHA-256 digest of the sorted input identities and dispositions; --strict rejects a missing pin or any count- or identity-level drift. The pin makes phased remediation auditable and regression-safe, but it is not a claim that every optional Apple input is already public. The v4.1.3 pin is 2,905 total: 1,122 bound, 40 internally controlled, 1,743 intentionally omitted, and 0 unclassified. Its identity SHA-256 is c975f4e4eebb62ec87864a73fbf72bb8841f644108e54e6ffb25168bcf2a2766.

--strict is the merge- and tag-time release gate. Every declared target or broken tool remains an error in reports, and a regression test pins their exact state. The current baseline has no target or broken implementations and no implementation drift, so any implementation that leaves asBuilt, any structural contract error, or any optional-input coverage drift blocks both merges and releases. --structural-strict remains available only for local phased remediation work.

This gate proves operation identity, top-level MCP field ownership, required Apple inputs, typed internal values, and response source/pointer lineage. Full MCP type/enum/range parity and complete typed response schemas remain separate optimization phases; the current mapping status is 469 partial and 33 deprecated.

The older openapi-coverage command remains available for the high-level domain report in ASC-OPENAPI-COVERAGE-GENERATED.md. The operation contract is the authoritative release gate.

Available worker names:

Worker Prefix Tools Description
company company_ 3 Multi-account management
auth auth_ 4 JWT token tools
apps apps_ 10 App listing, metadata, localizations, search keyword IDs
accessibility accessibility_ 6 App Store accessibility declarations
webhooks webhooks_ 11 Webhook notifications, delivery diagnostics, and receiver helpers
xcode_cloud xcode_cloud_ 42 Xcode Cloud products, workflow management, build runs, artifacts, issues, test results, and SCM
builds builds_ 4 Build management
build_uploads build_uploads_ 10 Build upload parents, files, safe transfers, and recovery
build_processing builds_get_processing_*, builds_update_encryption, builds_check_readiness 4 Build states, encryption
export_compliance export_compliance_ 11 Encryption declarations, document uploads, build linkage, readiness
build_beta builds_*_beta_*, individual tester build tools 11 TestFlight localizations, notifications
versions app_versions_ 17 Version lifecycle, age ratings, submit, release
reviews reviews_ 8 Customer reviews and responses
beta_groups beta_groups_ 15 TestFlight groups and public-link recruitment criteria
beta_feedback beta_feedback_ 8 TestFlight feedback screenshots, crash submissions, crash logs
beta_testers beta_testers_ 12 Tester management
iap iap_ 59 In-app purchases, versioned metadata, pricing, availability, offer codes, review assets
subscriptions subscriptions_ 99 Subscription and group versions, pricing, plan availability, offers, assets
sandbox sandbox_ 3 Sandbox testers
beta_app beta_app_ 10 Beta app localizations and review
pre_release pre_release_ 3 Pre-release versions
beta_license beta_license_ 3 Beta license agreements
provisioning provisioning_ 17 Bundle IDs, devices, certificates
app_info app_info_ 10 App info, categories, EULA
pricing pricing_ 9 Territories, pricing
users users_ 10 Team members, roles
app_events app_events_ 9 In-app events, localizations
analytics analytics_ 11 Sales/financial reports, analytics
screenshots screenshots_ 19 Screenshots, previews, sets, and verified ordering
custom_pages custom_pages_ 17 Custom product pages, versions, localizations, and search keywords
ppo ppo_ 15 Product page optimization experiments, treatments, and localizations
promoted promoted_ 10 Promoted in-app purchases and verified ordering
review_attachments review_attachments_ 4 App Store review attachments
review_submissions review_submissions_ 9 Generic App Store review submissions and submission items
metrics metrics_ 9 Performance metrics, diagnostics, and TestFlight usage metrics

Tool Catalog Size

When an MCP client eagerly loads every tool definition, the approximate schema footprint is:

Configuration Tools ~Tokens
All workers (default) 502 ~60,000
Release workflow: apps,builds,export_compliance,versions,reviews ~72 ~8,900
Monetization: apps,iap,subscriptions,pricing 184 ~21,100
TestFlight: apps,builds,beta_groups,beta_testers ~63 ~7,100
Marketing: apps,screenshots,custom_pages,ppo,promoted ~78 ~8,800
--workers apps 17 ~2,100

Heaviest workers: Subscriptions (99 tools), InAppPurchases (59 tools), Xcode Cloud (42 tools), Screenshots (19 tools), Provisioning (17 tools).

Exact cost depends on the MCP host's serialization, tokenizer, and tool-discovery strategy. Modern clients may defer schemas until they are needed. Use --workers when the client enforces a tool limit or when you want a smaller, more focused catalog.

Available Tools

502 tools organized across 33 App Store tool domains + 2 core domains (use the 35 --workers filter keys — see Worker Filtering):

Tool Description
company_list List all configured companies
company_switch Switch active company for API operations
company_current Get current active company info
Tool Description
auth_generate_token Generate JWT token for API access
auth_validate_token Locally validate a standard team-key JWT: ES256 signature, configured kid/iss, App Store Connect audience, issued-at and expiration claims, and the 20-minute maximum lifetime. This makes no Apple API call and does not prove server acceptance.
auth_refresh_token Force refresh JWT token
auth_token_status Get JWT token cache status
Tool Description
apps_list List all applications with filtering
apps_get_details Get detailed app information
apps_search Search apps by name or Bundle ID
apps_list_versions List all versions with states
apps_get_metadata Get localized metadata for a version
apps_list_search_keywords List canonical App Store search keyword IDs for custom-page targeting
apps_update_metadata Update metadata (What's New, description, etc.)
apps_list_localizations List localizations with content status
apps_create_localization Create a new localization for a version
apps_delete_localization Delete a localization from a version
Tool Description
accessibility_list List accessibility declarations for an app
accessibility_get Get one accessibility declaration
accessibility_create Create a declaration for a device family
accessibility_update Update support flags or publish a declaration
accessibility_delete Delete a declaration
accessibility_list_relationships List declaration relationship IDs for an app
Tool Description
webhooks_list List webhooks for an app
webhooks_get Get a webhook by ID
webhooks_create Create a webhook configuration
webhooks_update Update webhook fields
webhooks_delete Delete a webhook
webhooks_list_deliveries List delivery attempts
webhooks_redeliver Redeliver an existing delivery
webhooks_ping Send a test ping
webhooks_verify_signature Verify x-apple-signature against the exact raw payload body
webhooks_parse_payload Parse and normalize a raw webhook notification payload
webhooks_triage_event Produce an actionable triage plan for webhook events or delivery failures
Tool Description
xcode_cloud_products_list List Xcode Cloud products
xcode_cloud_products_get Get an Xcode Cloud product
xcode_cloud_products_delete Preview or permanently delete an Xcode Cloud product with confirmation safeguards
xcode_cloud_app_product_get Get the Xcode Cloud product associated with an app
xcode_cloud_product_app_get Get the app associated with an Xcode Cloud product
xcode_cloud_product_primary_repositories_list List primary repositories attached to a product
xcode_cloud_product_additional_repositories_list List additional repositories attached to a product
xcode_cloud_product_workflows_list List workflows for a product
xcode_cloud_product_build_runs_list List build runs for a product
xcode_cloud_workflows_get Get a workflow
xcode_cloud_workflows_create Create an Xcode Cloud workflow
xcode_cloud_workflows_update Update an Xcode Cloud workflow
xcode_cloud_workflows_delete Preview or permanently delete a workflow with confirmation safeguards
xcode_cloud_workflow_repository_get Get the repository used by a workflow
xcode_cloud_workflow_build_runs_list List build runs for a workflow
xcode_cloud_build_runs_get Get a build run
xcode_cloud_build_runs_start Start or rebuild an Xcode Cloud build
xcode_cloud_build_run_actions_list List build actions for a run
xcode_cloud_build_run_builds_list List App Store Connect builds created by a run
xcode_cloud_actions_get Get a build action
xcode_cloud_action_build_run_get Get the build run that owns a build action
xcode_cloud_action_artifacts_list List artifacts for an action
xcode_cloud_action_issues_list List issues for an action
xcode_cloud_action_test_results_list List test results for an action
xcode_cloud_artifacts_get Get an artifact
xcode_cloud_issues_get Get an issue
xcode_cloud_test_results_get Get a test result
xcode_cloud_xcode_versions_list List available Xcode versions
xcode_cloud_xcode_versions_get Get an Xcode version
xcode_cloud_xcode_version_macos_versions_list List macOS versions compatible with an Xcode version
xcode_cloud_macos_versions_list List available macOS versions
xcode_cloud_macos_versions_get Get a macOS version
xcode_cloud_macos_version_xcode_versions_list List Xcode versions compatible with a macOS version
xcode_cloud_scm_providers_list List SCM providers
xcode_cloud_scm_providers_get Get an SCM provider
xcode_cloud_scm_provider_repositories_list List repositories for an SCM provider
xcode_cloud_scm_repositories_list List SCM repositories
xcode_cloud_scm_repositories_get Get an SCM repository
xcode_cloud_scm_repository_git_references_list List repository git references
xcode_cloud_scm_repository_pull_requests_list List repository pull requests
xcode_cloud_scm_git_references_get Get a git reference
xcode_cloud_scm_pull_requests_get Get a pull request
Tool Description
beta_feedback_list_crashes List beta crash feedback submissions
beta_feedback_get_crash Get one beta crash feedback submission
beta_feedback_get_crash_log Read crash log for a submission
beta_feedback_get_crash_log_by_id Read crash log by crash log ID
beta_feedback_delete_crash Delete a beta crash feedback submission
beta_feedback_list_screenshots List beta screenshot feedback submissions
beta_feedback_get_screenshot Get one beta screenshot feedback submission
beta_feedback_delete_screenshot Delete a beta screenshot feedback submission
Tool Description
builds_list List builds with processing states
builds_get Get detailed build information
builds_find_by_number Find build by version number
builds_list_for_version Get builds for specific app version
Tool Description
build_uploads_list List an app's Build Upload parents with filters, sparse fields, includes, and strict pagination
build_uploads_get Get one Build Upload with processing diagnostics and optional included resources
build_uploads_create Create a Build Upload parent without replaying an ambiguous POST
build_uploads_delete Delete a Build Upload parent after exact ID confirmation
build_uploads_list_files List file reservations under one Build Upload with strict pagination
build_uploads_get_file Get one Build Upload File and its delivery state
build_uploads_reserve_file Reserve one exact file without replaying an ambiguous POST
build_uploads_commit_file Commit checksum or uploaded-state changes with omission and null preserved separately
build_uploads_upload_file Transfer a new or existing reservation from an immutable local snapshot
build_uploads_upload Run parent creation, reservation, transfer, commit, and processing reconciliation

Compound uploads retain the same lowercase MD5 fingerprint from reservation through recovery. Explicit resume and recovered-continuation instructions carry expected_md5; the next invocation verifies a fresh immutable snapshot against it before any Apple request or transfer. An existing reservation already marked UPLOAD_COMPLETE or COMPLETE is accepted only when Apple's sourceFileChecksums.file MD5 matches that snapshot; missing, unsupported, or mismatched evidence is retained for inspection without another transfer, commit, or delete. Presigned operations retry only when their method is PUT; redirects, POST, and unknown methods are not replayed. If an ambiguous create is uniquely recovered, the workflow stops and returns its resource ID for explicit continuation. Transfer credentials stay redacted unless include_sensitive_details is explicitly enabled on a direct read.

Tool Description
builds_get_processing_state Get current processing state
builds_update_encryption Set encryption compliance
builds_get_processing_status Get detailed processing status
builds_check_readiness Check if build is ready for submission
Tool Description
export_compliance_list_declarations List an app's encryption declarations with strict pagination
export_compliance_get_declaration Get one declaration without deprecated document URL fields
export_compliance_create_declaration Create an encryption declaration questionnaire for an app
export_compliance_create_document Reserve, transfer, commit, and poll a document from one immutable local snapshot
export_compliance_get_document Get safe delivery metadata without signed URLs, tokens, or upload headers
export_compliance_update_document Apply a low-level nullable checksum or uploaded-state patch
export_compliance_upload_document Resume an AWAITING_UPLOAD reservation with exact bytes and its lowercase MD5 receipt
export_compliance_inspect_document Inspect document presence and classify its delivery state
export_compliance_get_build_declaration Get the declaration currently attached to a build
export_compliance_attach_build_declaration Attach an approved declaration and verify the relationship
export_compliance_check_release_readiness Evaluate only the build's export-compliance release gate
Tool Description
builds_get_beta_detail Get TestFlight configuration for build
builds_update_beta_detail Update TestFlight settings
builds_set_beta_localization Set What's New for TestFlight
builds_list_beta_localizations List all TestFlight localizations
builds_get_beta_groups Get beta groups for a build
builds_get_beta_testers Get individual testers for a build
builds_send_beta_notification Send notification to beta testers
builds_add_to_beta_groups Add build to beta groups
builds_add_individual_testers Add individual testers to a build
builds_remove_individual_testers Remove individual testers from a build
builds_list_individual_testers List individual testers assigned to a build
Tool Description
beta_groups_list List TestFlight beta groups for an app
beta_groups_create Create a new beta group
`beta_groups_update