Appstore Connect (mgcrea) MCP Server

@mgcrea/mcp-appstore-connect npm v0.23.0 Source verified

Published by mgcrea — publish provenance cryptographically ties this package to that repository. That is proof of origin, not an official vendor package.

Model Context Protocol server for the Apple App Store Connect API

Trust grade
A
97/100
Last scanned get badge →
Trust
A · 97/100
Adoption risk for you: the threat score, then adjusted down for blast radius, publisher verification and how much the scan could see. Deterministic; every point is auditable.
Capability
Moderate
Blast radius if it went rogue — what the server’s tools could reach. Independent of trust.
Coverage
Source
How much the scan could actually inspect. Shallow coverage is stated, never hidden.
Share this Trust Score
𝕏 Share LinkedIn Reddit
A Why this grade threat 100 − adoption risk = 97/100

The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.

1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:

The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.

2. Client adoption risk — 100 − 3 = 97. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:

PointsAdoption-risk factor
−3 capability blast radius (moderate) — client exposure if the model is manipulated

Capability observations and info notes are shown under Findings but never scored. Open any row's finding below for the file, line and evidence behind a deduction.

Findings 0

✓ No findings. The scan raised nothing on this surface — see Coverage for how deep it could look.

Tools 87

Each tool and what it can reach — statically extracted from the published source.

  • app_store_connect_download_analytics_report_segmentingests untrusted input
  • app_store_connect_download_certificateingests untrusted input
  • app_store_connect_download_finance_reportingests untrusted input
  • app_store_connect_download_sales_reportingests untrusted input
  • app_store_connect_get_analytics_statusingests untrusted input
  • app_store_connect_get_appingests untrusted input
  • app_store_connect_list_analytics_report_instancesingests untrusted input
  • app_store_connect_list_analytics_report_requestsingests untrusted input
  • app_store_connect_list_analytics_report_segmentsingests untrusted input
  • app_store_connect_list_certificatesingests untrusted input
Show 77 more tools ↓
  • app_store_connect_list_live_versionsingests untrusted input
  • app_store_connect_add_tester_to_groupno sensitive capability
  • app_store_connect_apply_listingno sensitive capability
  • app_store_connect_auth_statusno sensitive capability
  • app_store_connect_cancel_review_submissionno sensitive capability
  • app_store_connect_create_analytics_report_requestno sensitive capability
  • app_store_connect_create_beta_groupno sensitive capability
  • app_store_connect_create_bundle_idno sensitive capability
  • app_store_connect_create_certificateno sensitive capability
  • app_store_connect_create_iap_localizationno sensitive capability
  • app_store_connect_create_versionno sensitive capability
  • app_store_connect_delete_iap_localizationno sensitive capability
  • app_store_connect_delete_screenshotno sensitive capability
  • app_store_connect_delete_screenshot_setno sensitive capability
  • app_store_connect_disable_capabilityno sensitive capability
  • app_store_connect_enable_capabilityno sensitive capability
  • app_store_connect_export_listingno sensitive capability
  • app_store_connect_get_age_rating_declarationno sensitive capability
  • app_store_connect_get_analytics_reportno sensitive capability
  • app_store_connect_get_app_info_localizationno sensitive capability
  • app_store_connect_get_app_price_scheduleno sensitive capability
  • app_store_connect_get_app_store_review_detailno sensitive capability
  • app_store_connect_get_bundle_idno sensitive capability
  • app_store_connect_get_iap_availabilityno sensitive capability
  • app_store_connect_get_iap_price_scheduleno sensitive capability
  • app_store_connect_get_iap_review_screenshotno sensitive capability
  • app_store_connect_get_in_app_purchaseno sensitive capability
  • app_store_connect_get_screenshotno sensitive capability
  • app_store_connect_get_vendor_numberno sensitive capability
  • app_store_connect_get_versionno sensitive capability
  • app_store_connect_get_version_localizationno sensitive capability
  • app_store_connect_invite_beta_testerno sensitive capability
  • app_store_connect_list_analytics_reportsno sensitive capability
  • app_store_connect_list_app_categoriesno sensitive capability
  • app_store_connect_list_app_info_localizationsno sensitive capability
  • app_store_connect_list_app_infosno sensitive capability
  • app_store_connect_list_app_price_pointsno sensitive capability
  • app_store_connect_list_appsno sensitive capability
  • app_store_connect_list_beta_feedbackno sensitive capability
  • app_store_connect_list_beta_groupsno sensitive capability
  • app_store_connect_list_beta_testersno sensitive capability
  • app_store_connect_list_buildsno sensitive capability
  • app_store_connect_list_bundle_idsno sensitive capability
  • app_store_connect_list_customer_reviewsno sensitive capability
  • app_store_connect_list_devicesno sensitive capability
  • app_store_connect_list_iap_localizationsno sensitive capability
  • app_store_connect_list_iap_price_pointsno sensitive capability
  • app_store_connect_list_in_app_purchasesno sensitive capability
  • app_store_connect_list_review_submissionsno sensitive capability
  • app_store_connect_list_screenshot_setsno sensitive capability
  • app_store_connect_list_screenshotsno sensitive capability
  • app_store_connect_list_usersno sensitive capability
  • app_store_connect_list_version_localizationsno sensitive capability
  • app_store_connect_list_versionsno sensitive capability
  • app_store_connect_register_deviceno sensitive capability
  • app_store_connect_release_versionno sensitive capability
  • app_store_connect_remove_tester_from_groupno sensitive capability
  • app_store_connect_remove_version_from_submissionno sensitive capability
  • app_store_connect_reorder_screenshotsno sensitive capability
  • app_store_connect_revoke_certificateno sensitive capability
  • app_store_connect_set_app_categoriesno sensitive capability
  • app_store_connect_set_app_priceno sensitive capability
  • app_store_connect_set_app_store_review_detailno sensitive capability
  • app_store_connect_set_iap_availabilityno sensitive capability
  • app_store_connect_set_in_app_purchase_priceno sensitive capability
  • app_store_connect_set_version_buildno sensitive capability
  • app_store_connect_submit_in_app_purchase_for_reviewno sensitive capability
  • app_store_connect_submit_version_for_reviewno sensitive capability
  • app_store_connect_update_age_rating_declarationno sensitive capability
  • app_store_connect_update_appno sensitive capability
  • app_store_connect_update_app_info_localizationno sensitive capability
  • app_store_connect_update_iap_localizationno sensitive capability
  • app_store_connect_update_in_app_purchaseno sensitive capability
  • app_store_connect_update_versionno sensitive capability
  • app_store_connect_update_version_localizationno sensitive capability
  • app_store_connect_upload_iap_review_screenshotno sensitive capability
  • app_store_connect_upload_screenshotno sensitive capability

What this scan could not see

Versions 10

Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.

VersionScoreFindingsEngineScanned
v0.23.0 latest A 97/100 0 1.13.0 2026-09-07
v0.22.4 A 97/100 0 1.13.0 2026-09-06
v0.22.3 A 97/100 0 1.13.0 2026-09-04
v0.22.2 A 97/100 0 1.13.0 2026-09-01
v0.22.0 A 97/100 0 1.13.0 2026-08-31
Show 5 more versions ↓
v0.21.0 A 97/100 0 1.13.0 2026-08-30
v0.20.0 A 97/100 0 1.13.0 2026-08-28
v0.19.0 A 97/100 0 1.13.0 2026-08-27
v0.18.0 A 97/100 0 1.12.1 2026-08-20
v0.16.0 A 97/100 0 1.12.1 2026-08-19

Embed this score

Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.

MCP Trust Score: A · 97/100
Markdown (GitHub README)
[![MCP Trust Score](https://mcptrustchecker.com/registry/mgcrea-mcp-appstore-connect/badge.svg)](https://mcptrustchecker.com/registry/mgcrea-mcp-appstore-connect)
HTML
<a href="https://mcptrustchecker.com/registry/mgcrea-mcp-appstore-connect"><img src="https://mcptrustchecker.com/registry/mgcrea-mcp-appstore-connect/badge.svg" alt="MCP Trust Score" height="20"></a>
Prefer shields.io styling? Point it at https://mcptrustchecker.com/registry/mgcrea-mcp-appstore-connect/badge.json via https://img.shields.io/endpoint?url=…

Verify this score yourself

The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.

npx mcptrustchecker scan @mgcrea/mcp-appstore-connect --online

Use the free API → How scoring works

Other implementations of Appstore Connect 6

Independent packages implementing the same tool, scanned with the same engine. Compare all 7 side by side →

More in Business & CRM