Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
APP_STORE_KEY_IDNoCompatibility alias for APPSTORE_CONNECT_API_KEY_ID. The primary variable wins if both are set.
APP_STORE_ISSUER_IDNoCompatibility alias for APPSTORE_CONNECT_API_ISSUER_ID.
APP_STORE_PRIVATE_KEYNoCompatibility alias for APPSTORE_CONNECT_API_KEY_CONTENT.
APPSTORE_CONNECT_API_KEY_IDNoYour App Store Connect API key ID. Alias: APP_STORE_KEY_ID.
APPSTORE_CONNECT_API_ISSUER_IDNoYour App Store Connect API issuer ID. Alias: APP_STORE_ISSUER_ID.
APPSTORE_CONNECT_API_KEY_CONTENTNoYour App Store Connect API key content. Accepts literal multiline PEM or escaped \n. Alias: APP_STORE_PRIVATE_KEY.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
resources
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
get_capabilitiesA

Report implemented features and configured safety gates without credentials or network access.

validate_repositoryA

Validate selected AppStore domains/locales offline. Does not mutate files, execute project tools, or require Apple credentials. Omitted fields remain unmanaged.

list_appsA

Discover apps through public Apple API reads. Bundle ID is an exact filter; names are not identity.

get_app_store_stateA

Read a verified app/bundle identity. Omit version to inspect candidates; specify an exact platform/version to read metadata and redacted screenshot/review inventory.

export_app_store_stateA

Read Apple state and export into a fresh approved local directory. Refuses overwrite; review secrets and notes are not exported. Screenshot inventory is not original image bytes.

prepare_app_recordA

Confirm an existing app by ID/bundle or report owner-supplied manual bootstrap fields when absent. Never creates an Apple app record.

apply_planA

Apply the exact host-authorized subset of an immutable, current-process domain plan. Requires write mode; rejects submission. Never accepts endpoints or plan-file paths. Unknown outcomes are read back, never replayed.

get_operation_statusA

Inspect a current-process plan journal. Optional polling only reads back previously approved uncertain operations; it never executes remaining writes. Journal files remain available after process exit, but execution requires a fresh plan.

get_bundle_id_stateA

Read one exact bundle identifier and its portal platform/capabilities before authoring provisioning.json. Returns absent explicitly; never registers anything.

inspect_xcode_projectA

Statically inspect one explicit app/extension target, configuration and platform using Apple plutil. No xcodebuild, scripts, dependency resolution or project edits. Unresolved settings remain provisional; proposals never register identifiers.

plan_provisioning_changesA

Read exact identifiers explicitly selected from AppStore provisioning.json and produce an immutable approval plan. Preserves omitted capabilities, never deletes signing resources or rewrites projects. Capability changes can invalidate profiles; regeneration and APNs credentials are separate owner tasks.

plan_metadata_changesA

Plan exact selected AppStore locales/domains against an editable app/platform/version. Locale-only appInfo/versionMetadata does not select categories, copyright, release behavior or review. New versions require the explicit version domain and releaseType. Secrets stay redacted; actual writes require approved apply_plan.

plan_screenshot_changesB

Plan exact macOS locale screenshot sets from decoded original bytes. Merge preserves verified unowned images; replace explicitly shows every removal, capacity gap and final order. Pending/unknown bytes require recovery before merge. Writes require approved apply_plan.

plan_commerce_changesA

Plan explicitly managed app-wide base pricing and compare territory availability. Exact catalog points use decimal strings. Generic territory mutations are unavailable, so availability differences are returned as manualActionRequired with blocker statuses and no write operations.

get_provisioning_resourcesA

Read bounded certificate, device and profile inventory without artifact contents. Exact IDs remain available for typed planning; serial numbers, UDIDs and profile UUIDs are fingerprinted in the response.

plan_signing_changesA

Plan one explicit sensitive certificate, device or profile lifecycle action. CSR files stay under an approved root; private keys are rejected. Destructive revocation/deletion is separate and shows affected profile counts. Apply requires the exact approved operation.

download_signing_artifactA

Download one exact certificate or provisioning profile to a new approved local file with mode 0600. Raw contents never appear in the MCP response and existing paths are never overwritten.

check_release_readinessA

Check one exact existing build and release using local manifests plus bounded App Store Connect evidence. Manual privacy, age-rating, legal and regional obligations remain explicit; passing checks cannot guarantee Apple review acceptance.

plan_submissionA

Create a fresh immutable submission-only plan for one exact processed build. Requires explicit manual confirmations and reports automatic-release behavior. Compatible drafts are reused; unrelated items or active conflicting submissions block planning.

submit_for_reviewA

Execute every operation in an exact fresh submission-only plan. Requires --allow-writes, the independent --allow-submission flag, the exact digest and explicit host confirmation. Uncertain outcomes are read back and never replayed.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription
schema-app
schema-info
schema-version
schema-metadata
schema-review
schema-screenshots
schema-commerce
schema-provisioning
capabilitiesPackaged implementation and safety contract.
operationsPackaged implementation and safety contract.

TDQS

A3.9/5.0

Scored across 20 tools

Disambiguation5/5

Each tool has a clearly distinct purpose, ranging from read-only discovery (e.g., list_apps, get_bundle_id_state) to planning and applying changes. Even similar planning tools (e.g., plan_metadata_changes, plan_screenshot_changes) specify different domains. No two tools appear to overlap in a way that would cause misselection.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern, with verbs like get, list, plan, apply, submit, and check. Read-only tools use get/list/check/inspect/export/validate, while mutation intent is clear with plan/apply/submit. The naming is uniform and predictable.

Tool Count4/5

20 tools is at the upper end of the ideal range but still justified given the breadth of App Store Connect domains (apps, provisioning, metadata, screenshots, commerce, signing, submission). Slightly heavy but each tool serves a distinct purpose in the workflow.

Completeness4/5

The tool surface covers read, plan, and apply steps for common App Store workflows, including provisioning, metadata, screenshots, signing, and submission. Minor gaps exist (e.g., no tool for managing users or analytics), and some destructive actions are intentionally separate or require manual steps, but the core lifecycle is well covered.

Maintenance

ActivityMaintained
ResponsivenessNo issues