Connect ASOgenic and run an ASO pass

ASOgenic is a Model Context Protocol server. Point an MCP client at it with a per-user key, give it your App Store Connect credentials, and your agent can research keywords, write and validate metadata, manage screenshots, and submit to Apple review.

In a hurry? Paste https://asogenic.com/setup to your agent. It's a plain-text runbook the agent can follow to wire everything up itself.

How it works

Three services, kept deliberately separate:

  • Your MCP client (any MCP-compatible AI agent) holds your App Store Connect .p8 key in its own environment and talks to the ASOgenic MCP endpoint.
  • The ASOgenic MCP server exposes the tools. It mints short-lived JWTs from your ASC key per request and never stores the key (unless you explicitly opt into server-side storage on a hosted deployment).
  • This dashboard only issues and manages your platform key. It never sees your Apple credentials.

Authentication

The hosted endpoint currently supports a per-account bearer API key. This is the most portable option for unattended agents, CI, and local MCP clients. Store it in the client secret store and send it only as Authorization: Bearer <key>. MCP OAuth discovery is not enabled yet, so a client asking for OAuth should use the API-key path until that compatibility layer is released.

Setup

  1. Create a platform key.

    Sign in, create a key, and copy it. It is shown once.

  2. Add the MCP server to your client config.

    Add this to your MCP client config (commonly .mcp.json), pointing it at https://mcp.asogenic.com/mcp with your key in the Authorization header:

    { "mcpServers": { "asogenic": { "url": "https://mcp.asogenic.com/mcp", "headers": { "Authorization": "Bearer <your key>" } } } }
  3. Provide App Store Connect credentials.

    Set ASC_KEY_ID, ASC_ISSUER_ID and ASC_P8_PATH (or ASC_P8_PEM) in that MCP server's env block. The key stays on your machine. Don't paste the .p8 into a tool call unless you're on a hosted deployment and want server-side storage.

  4. Verify.

    Call asogenic_auth_status. You want asc_configured: true and asc_valid: true.

The release workflow

The order that actually gets a never-launched app through Apple review:

  1. asogenic_auth_status: credentials work.
  2. asogenic_list_apps / asogenic_resolve_app: find the app; keep the session_key.
  3. asogenic_intake_product_context: record what the app is. Everything downstream depends on this.
  4. Per locale: asogenic_fetch_source → generate the fields yourself (asogenic_research_keywords, asogenic_assemble_locale, asogenic_get_field_spec are aids) → asogenic_validate_record → asogenic_approve_locale → asogenic_publish.
  5. Store setup, each required before submission: category, age rating, version copyright, content-rights declaration, review info (+ demo account if the app needs login), base price, screenshots for every device family the app supports.
  6. asogenic_get_release_readiness: blockers must be empty; read the warnings too (some name gaps the server can't verify).
  7. asogenic_submit_for_review.

App Privacy is not in this list on purpose. Apple has never exposed the App Privacy "nutrition label" to API-key auth. Set it once in the App Store Connect web UI; it carries forward to every later version, and leaving it unset is Apple review's number-one rejection reason.

Quotas & rate limits

Each account gets 500 tool calls per month, shared across every key you create. The window rolls continuously: old calls age out, they don't reset on a fixed date. On top of that there are short-window burst caps, about 120 calls per minute.

  • RATE_LIMITED: a burst cap. Wait the retry_after_s seconds and continue.
  • QUOTA_EXCEEDED: the monthly allowance is spent. It recovers as the oldest calls age out.

A full optimization pass (keyword research, metadata, and publishing across a few locales) is roughly 50 to 100 calls, so a free key covers real, repeated use.

Troubleshooting

asc_configured: false from asogenic_auth_status
The ASC_* variables aren't reaching the MCP server process. Check they're in the server's env block (not your shell), and restart the MCP client.
asc_valid: false
The credentials are present but Apple rejected them: wrong key ID/issuer ID pairing, a revoked key, or a malformed .p8.
Tools return 401 / "invalid token"
The platform key in your Authorization header is wrong or was rotated/revoked. Create or rotate a key on the dashboard.
APP_PRIVACY_NO_API
Expected; see the App Privacy note above. Set it in the web UI.

Still stuck? See the FAQ or contact us.