Connect ASOgenic and run an ASO pass
ASOgenic is a Model Context Protocol server. Point an MCP client at it with a per-user key, give it your App Store Connect credentials, and your agent can research keywords, write and validate metadata, manage screenshots, and submit to Apple review.
In a hurry? Paste https://asogenic.com/setup to
your agent. It's a plain-text runbook the agent can follow to wire everything up itself.
How it works
Three services, kept deliberately separate:
- Your MCP client (any MCP-compatible AI agent) holds your App Store
Connect
.p8key in its own environment and talks to the ASOgenic MCP endpoint. - The ASOgenic MCP server exposes the tools. It mints short-lived JWTs from your ASC key per request and never stores the key (unless you explicitly opt into server-side storage on a hosted deployment).
- This dashboard only issues and manages your platform key. It never sees your Apple credentials.
Authentication
The hosted endpoint currently supports a per-account bearer API key. This is the most
portable option for unattended agents, CI, and local MCP clients. Store it in the client
secret store and send it only as Authorization: Bearer <key>. MCP OAuth
discovery is not enabled yet, so a client asking for OAuth should use the API-key path until
that compatibility layer is released.
Setup
- Create a platform key.
Sign in, create a key, and copy it. It is shown once.
- Add the MCP server to your client config.
Add this to your MCP client config (commonly
.mcp.json), pointing it athttps://mcp.asogenic.com/mcpwith your key in theAuthorizationheader:{ "mcpServers": { "asogenic": { "url": "https://mcp.asogenic.com/mcp", "headers": { "Authorization": "Bearer <your key>" } } } } - Provide App Store Connect credentials.
Set
ASC_KEY_ID,ASC_ISSUER_IDandASC_P8_PATH(orASC_P8_PEM) in that MCP server'senvblock. The key stays on your machine. Don't paste the.p8into a tool call unless you're on a hosted deployment and want server-side storage. - Verify.
Call
asogenic_auth_status. You wantasc_configured: trueandasc_valid: true.
The release workflow
The order that actually gets a never-launched app through Apple review:
asogenic_auth_status: credentials work.asogenic_list_apps/asogenic_resolve_app: find the app; keep thesession_key.asogenic_intake_product_context: record what the app is. Everything downstream depends on this.- Per locale:
asogenic_fetch_source→ generate the fields yourself (asogenic_research_keywords,asogenic_assemble_locale,asogenic_get_field_specare aids) →asogenic_validate_record→asogenic_approve_locale→asogenic_publish. - Store setup, each required before submission: category, age rating, version copyright, content-rights declaration, review info (+ demo account if the app needs login), base price, screenshots for every device family the app supports.
asogenic_get_release_readiness:blockersmust be empty; read thewarningstoo (some name gaps the server can't verify).asogenic_submit_for_review.
App Privacy is not in this list on purpose. Apple has never exposed the App Privacy "nutrition label" to API-key auth. Set it once in the App Store Connect web UI; it carries forward to every later version, and leaving it unset is Apple review's number-one rejection reason.
Quotas & rate limits
Each account gets 500 tool calls per month, shared across every key you create. The window rolls continuously: old calls age out, they don't reset on a fixed date. On top of that there are short-window burst caps, about 120 calls per minute.
RATE_LIMITED: a burst cap. Wait theretry_after_sseconds and continue.QUOTA_EXCEEDED: the monthly allowance is spent. It recovers as the oldest calls age out.
A full optimization pass (keyword research, metadata, and publishing across a few locales) is roughly 50 to 100 calls, so a free key covers real, repeated use.
Troubleshooting
asc_configured: falsefromasogenic_auth_status- The
ASC_*variables aren't reaching the MCP server process. Check they're in the server'senvblock (not your shell), and restart the MCP client. asc_valid: false- The credentials are present but Apple rejected them: wrong key ID/issuer ID pairing, a
revoked key, or a malformed
.p8. - Tools return 401 / "invalid token"
- The platform key in your
Authorizationheader is wrong or was rotated/revoked. Create or rotate a key on the dashboard. APP_PRIVACY_NO_API- Expected; see the App Privacy note above. Set it in the web UI.
Still stuck? See the FAQ or contact us.