ApproveKit
Audits app repositories against Apple's App Review Guidelines and generates reviewer notes for App Store Connect, helping apps get through App Store review.
Supports Google OAuth verification by deriving OAuth scopes from the repo, auditing against Google's verification rules, and generating per-scope justifications and a demo video shot list.
Audits app repositories against Google Play policy and generates reviewer notes for Play Console, helping apps get through Google Play review.
Creates Stripe checkout links for paid document packages after the user agrees, and checks payment status via order lookup.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ApproveKitaudit my repo for App Store review issues and tell me what to fix"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ApproveKit
Get AI-built apps through App Store review, Google Play review and Google OAuth verification.
ApproveKit is a Claude Code plugin plus a remote MCP server. Your coding agent reads the repo, builds an inventory of what the app collects, and runs a free audit against the rules reviewers actually apply. If you want the documents those reviews require, the agent gets them generated and hosted for a one-time fee per app.
Install
claude plugin marketplace add yateshaw/approvekit
claude plugin install approvekit@approvekitThen, inside any app repo, tell Claude:
get my app ready for the App Store
or "prepare the Google OAuth verification", "why would Google Play reject this app", "I need a privacy policy and an account deletion page".
Any MCP-capable agent can use the server without the plugin:
claude mcp add --transport http approvekit https://approvekit.dev/mcpRelated MCP server: opzyai
What it does
Inventory. The skill tells the agent how to derive platforms, sign-in methods, permissions, data collected, third-party SDKs, Google OAuth scopes and payments from the repo (Expo, React Native, Flutter, native iOS and Android, web). Your source code never leaves your machine; only the inventory is sent.
Free audit. 23 rules across Apple's App Review Guidelines, Google Play policy and Google's OAuth verification. Every finding comes with its severity, the fix, and a link to the official source.
Documents (paid, optional). A privacy policy and an account deletion page hosted at
yourapp.approvekit.dev, reviewer notes for App Store Connect and Play Console, and for Google OAuth the per-scope justifications and the demo video shot list. Anything the repo cannot answer is marked[CONFIRM: ...]for you to fill in; pages go live only when the text is final.
The agent never buys on its own: it reports the findings and the price, and creates a checkout link only after you say yes.
Pricing
Audit | Free |
Launch Pass (privacy policy, account deletion page, reviewer notes) | US$49 per app |
Google OAuth Verification Pack (Launch Pass + scope justifications + demo video script) | US$249 per app |
MCP tools
Tool | Purpose |
| Send the inventory, get findings and offers. Returns an |
| Stripe link for a package, after the user agrees. |
| Payment status and, once paid, the documents as Markdown. |
| Save the final text and put the hosted pages live. |
Endpoint: https://approvekit.dev/mcp (Streamable HTTP, no authentication; the app token identifies the app).
Links
Site: https://approvekit.dev
Terms: https://approvekit.dev/terms
Privacy: https://approvekit.dev/privacy
Support: support@approvekit.dev
ApproveKit is a product of WyeTech LLC. It is a software tool, not legal advice, and it does not guarantee approval by any platform.
This server cannot be deployed
Maintenance
Related MCP Connectors
Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.
Security reviews for coding agents: diffs checked against your org policy and live infrastructure.
Free enterprise-grade due diligence for your app, run by your coding agent. Then the full SDLC.
1HIPAA compliance AI agent — scan, grade, SRA, and generate compliance docs.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceThe only Multi-LLM Compliance Engine (GPT-4o + Claude + DeepSeek). Auto-fix GDPR/LGPD risks and more 15 frameworks. code.guard.eu6 npm1MIT
- AlicenseNot gradedqualityDmaintenanceLocal-first security check for AI coding agents — finds hardcoded secrets, exposed .env files, git-history leaks and vulnerable dependencies (OSV), entirely on your machine. Ask your agent "is this safe to ship?" and get a Launch Readiness score with a fix for every finding.MIT
- AlicenseAqualityBmaintenanceScans codebases for AI frameworks, checks EU AI Act compliance, and generates compliance reports, roadmaps, and audit-ready packages.1611MIT
- AlicenseNot gradedqualityBmaintenanceEnables MCP-compatible AI agents to scan code for leaked secrets, copyleft licenses, unprotected routes, missing privacy policies, and risky card handling before committing or shipping.61 npmMIT