Skip to main content
Glama
erayendes

Heimdall App Store Connect MCP

apps__app_encryption_declarations__list

Read-onlyIdempotent

List app encryption declarations for an app by ID or bundle ID, with optional filters for platform and builds to pinpoint compliance data.

Instructions

List the app encryption declarations belonging to an app. [GET /v1/apps/{id}/appEncryptionDeclarations]

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
idYesApp name, bundle ID (com.example.app) or numeric Apple ID.
limitNomaximum resources per page
includeNocomma-separated list of relationships to include Pull related records in the same call. Without it, checking a relationship costs one extra call per row returned.
next_urlNoAbsolute links.next URL from a previous response.
filter_buildsNofilter by id(s) of related 'builds' Takes a 'builds' resource id, read from the call that lists them — not a name. A value that matches nothing returns 200 with an empty list rather than an error.
filter_platformNofilter by attribute 'platform'
fields_appEncryptionDeclarationsNothe fields to include for returned resources of type appEncryptionDeclarations Return only these attributes. A full row set can exceed 200 KB.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changedv2.3.0
    • changedInput schema / properties / id / description
      Previous value: -"ID from the matching list call."New value: +"App name, bundle ID (com.example.app) or numeric Apple ID."
  2. Changed1 schema field changedv2.2.0
    • changedInput schema / properties / filter_builds / description
      Previous value: -"filter by id(s) of related 'builds'"New value: +"filter by id(s) of related 'builds' Takes a 'builds' resource id, read from the call that lists them — not a name. A value that matches nothing returns 200 with an empty list rather than an error."
  3. Changed1 schema field changedv2.0.1
    • addedInput schema / properties / id / description
      Added value: +"ID from the matching list call."
  4. Changed4 schema fields changedv2.0.0
    • addedInput schema / properties / fields_appEncryptionDeclarations
      Added value: +{
      +  "description": "the fields to include for returned resources of type appEncryptionDeclarations Return only these attributes. A full row set can exceed 200 KB.",
      +  "items": {
      +    "enum": [
      +      "appDescription",
      +      "createdDate",
      +      "usesEncryption",
      +      "exempt",
      +      "containsProprietaryCryptography",
      +      "containsThirdPartyCryptography",
      +      "availableOnFrenchStore",
      +      "platform",
      +      "uploadedDate",
      +      "documentUrl",
      +      "documentName",
      +      "documentType",
      +      "appEncryptionDeclarationState",
      +      "codeValue",
      +      "app",
      +      "builds",
      +      "appEncryptionDeclarationDocument"
      +    ],
      +    "type": "string"
      +  },
      +  "type": "array"
      +}
    • removedInput schema / properties / id / description
      Removed value: -"Resource identifier."
    • changedInput schema / properties / include / description
      Previous value: -"comma-separated list of relationships to include"New value: +"comma-separated list of relationships to include Pull related records in the same call. Without it, checking a relationship costs one extra call per row returned."
    • changedInput schema / properties / next_url / description
      Previous value: -"Absolute `links.next` URL from a previous response, to fetch the next page. When set, all other parameters are ignored."New value: +"Absolute links.next URL from a previous response."
  5. First observedv1.3.0

TDQS

A3.8/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, and the 'List' wording is consistent with that. The description adds the endpoint but does not disclose additional behavioral details such as pagination behavior or response shape. No contradiction exists.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single focused sentence followed by the endpoint reference. It is front-loaded with the action and scope, and every part is useful with no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only list operation, the description plus complete schema and safety annotations is nearly sufficient. It does not describe the returned list structure or explicitly differentiate from the unapp-scoped sibling, but the endpoint and required app id give enough information to invoke the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all 7 parameters thoroughly. The endpoint line does clarify that id is a path parameter, but the description otherwise adds no meaningful parameter semantics beyond what the schema provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb ('List'), the resource ('app encryption declarations'), and the scope ('belonging to an app'), plus the exact endpoint. This distinguishes it from the sibling app_encryption_declarations__list, which appears to be the non-app-scoped equivalent.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description makes the core use case clear: call when you need encryption declarations for a specific app, identified by the app id in the path. However, it does not explicitly name any alternative tool or describe when not to use it, so selection among sibling list tools is left mostly to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools