mcp-appstore-reviews
README.md
# mcp-appstore-reviews
A small, **reviews-only** MCP server for the Apple App Store, backed by the
[App Store Connect API](https://developer.apple.com/documentation/appstoreconnectapi).
It lets an agent read customer reviews and publish or delete developer responses —
and deliberately nothing else.
## Why so narrow?
The capability boundary *is* the trust guarantee. This server exposes only the
three review tools below. There is intentionally **no** build, release,
submission, pricing, in-app-purchase, certificate, profile, or beta-tester tool,
so the App Store Connect key you give it can't be used to do any of those things.
Scope the key itself narrowly too (the **Customer Support** role is enough).
It is also **dependency-free** — pure Node 18+ (`fetch` + built-in `crypto`),
no third-party packages — so there is no supply chain to audit beyond this one
file (`index.mjs`).
## Tools
| Tool | Description |
| --- | --- |
| `list_reviews` | List reviews for an app (newest first by default), including any existing developer response and its id. Filters: `territory`, `rating`, `sort` (`recent`/`favorable`/`critical`), `limit`. |
| `respond_to_review` | Publish a developer response to a review (`reviewId`, `responseBody`). |
| `delete_review_response` | Delete a developer response by its `responseId` (from `list_reviews`). |
## Authentication
Create an App Store Connect API key (Users and Access → Integrations → App Store
Connect API). Two kinds of key work:
- **Team key** — needs the **Customer Support** role (enough to manage reviews
without Admin's broader powers), but only an Admin can generate it. Supply the
Issuer ID along with the Key ID and `.p8`.
- **Individual key** — any user can generate their own (no Admin needed) and it
inherits that user's permissions. It has **no Issuer ID**: leave
`APP_STORE_CONNECT_ISSUER_ID` unset and supply just the Key ID and `.p8`.
Then provide:
| Env var | What |
| --- | --- |
| `APP_STORE_CONNECT_ISSUER_ID` | Issuer ID shown at the top of the Integrations page — **team keys only**; omit for individual keys |
| `APP_STORE_CONNECT_KEY_ID` | Key ID of the API key |
| `APP_STORE_CONNECT_PRIVATE_KEY_PATH` | Path to the downloaded `.p8` private key file |
The private key is read only to sign a short-lived ES256 JWT for Apple; it is
never logged, copied, or sent anywhere but Apple's API.
## Run
```bash
# stdio MCP server
APP_STORE_CONNECT_ISSUER_ID=... \
APP_STORE_CONNECT_KEY_ID=... \
APP_STORE_CONNECT_PRIVATE_KEY_PATH=/path/to/AuthKey_XXXX.p8 \
npx -y github:ForgeHQ-Agents/mcp-appstore-reviews
```
The agent passes the app's numeric App Store ID as `appId` (find it in App Store
Connect → your app → App Information, or in the app's App Store URL).
## Test
```bash
npm test # node --test, zero dependencies
```
## License
MIT
TDQS
A4.6/5.0
Scored across 3 tools
Disambiguation5/5
Each tool has a clear, distinct purpose: listing reviews, responding to a review, and deleting a response. No overlap or ambiguity.
Naming Consistency5/5
All tool names follow a consistent verb_noun pattern in snake_case (list_reviews, respond_to_review, delete_review_response).
Tool Count5/5
Three tools cover the essential operations for app store review responses: list, respond, and delete. The count is well-scoped for this domain.
Completeness4/5
Covers the full lifecycle of review responses (read, create, delete). Minor gap: no direct update for a response (requires delete+create), but the documentation clarifies the intended workflow.
Maintenance
ActivityInactive
ResponsivenessNo issues