Skip to main content
Glama
ForgeHQ-Agents

mcp-appstore-reviews

README.md
# mcp-appstore-reviews

A small, **reviews-only** MCP server for the Apple App Store, backed by the
[App Store Connect API](https://developer.apple.com/documentation/appstoreconnectapi).
It lets an agent read customer reviews and publish or delete developer responses —
and deliberately nothing else.

## Why so narrow?

The capability boundary *is* the trust guarantee. This server exposes only the
three review tools below. There is intentionally **no** build, release,
submission, pricing, in-app-purchase, certificate, profile, or beta-tester tool,
so the App Store Connect key you give it can't be used to do any of those things.
Scope the key itself narrowly too (the **Customer Support** role is enough).

It is also **dependency-free** — pure Node 18+ (`fetch` + built-in `crypto`),
no third-party packages — so there is no supply chain to audit beyond this one
file (`index.mjs`).

## Tools

| Tool | Description |
| --- | --- |
| `list_reviews` | List reviews for an app (newest first by default), including any existing developer response and its id. Filters: `territory`, `rating`, `sort` (`recent`/`favorable`/`critical`), `limit`. |
| `respond_to_review` | Publish a developer response to a review (`reviewId`, `responseBody`). |
| `delete_review_response` | Delete a developer response by its `responseId` (from `list_reviews`). |

## Authentication

Create an App Store Connect API key (Users and Access → Integrations → App Store
Connect API). Two kinds of key work:

- **Team key** — needs the **Customer Support** role (enough to manage reviews
  without Admin's broader powers), but only an Admin can generate it. Supply the
  Issuer ID along with the Key ID and `.p8`.
- **Individual key** — any user can generate their own (no Admin needed) and it
  inherits that user's permissions. It has **no Issuer ID**: leave
  `APP_STORE_CONNECT_ISSUER_ID` unset and supply just the Key ID and `.p8`.

Then provide:

| Env var | What |
| --- | --- |
| `APP_STORE_CONNECT_ISSUER_ID` | Issuer ID shown at the top of the Integrations page — **team keys only**; omit for individual keys |
| `APP_STORE_CONNECT_KEY_ID` | Key ID of the API key |
| `APP_STORE_CONNECT_PRIVATE_KEY_PATH` | Path to the downloaded `.p8` private key file |

The private key is read only to sign a short-lived ES256 JWT for Apple; it is
never logged, copied, or sent anywhere but Apple's API.

## Run

```bash
# stdio MCP server
APP_STORE_CONNECT_ISSUER_ID=... \
APP_STORE_CONNECT_KEY_ID=... \
APP_STORE_CONNECT_PRIVATE_KEY_PATH=/path/to/AuthKey_XXXX.p8 \
npx -y github:ForgeHQ-Agents/mcp-appstore-reviews
```

The agent passes the app's numeric App Store ID as `appId` (find it in App Store
Connect → your app → App Information, or in the app's App Store URL).

## Test

```bash
npm test   # node --test, zero dependencies
```

## License

MIT

TDQS

A4.6/5.0

Scored across 3 tools

Disambiguation5/5

Each tool has a clear, distinct purpose: listing reviews, responding to a review, and deleting a response. No overlap or ambiguity.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern in snake_case (list_reviews, respond_to_review, delete_review_response).

Tool Count5/5

Three tools cover the essential operations for app store review responses: list, respond, and delete. The count is well-scoped for this domain.

Completeness4/5

Covers the full lifecycle of review responses (read, create, delete). Minor gap: no direct update for a response (requires delete+create), but the documentation clarifies the intended workflow.

Maintenance

ActivityInactive
ResponsivenessNo issues