v3.1.0
Summary
v3.1.0 aligns the existing 389-tool surface with Apple App Store Connect API 4.4.1 and adds an operation-level contract gate to detect future API drift before release.
- Corrected request fields, enums, relationships, response projections, nullable updates, report versions, and workflow behavior across app versions, TestFlight, reviews, pricing, Product Page Optimization, users, subscriptions, analytics, and asset uploads.
- Added credential-free
openapi-contract-check,--version, and--helpcommands. - Bundled a semantic manifest that accounts for all 1,263 Apple operations: 363 mapped, 537 explicitly deferred, and 363 scoped out.
Reliability
- Made company switching atomic across concurrent MCP calls and rejected empty or ambiguous company matches.
- Reworked screenshot, preview, IAP, subscription, and review-attachment uploads with immutable file snapshots, bounded-memory transfer, rollback before commit, reconciliation after ambiguous commits, and explicit pending or failed delivery states.
- Bound pagination URLs to the original App Store Connect origin, route, and required query parameters.
- Added strict sales and financial report validation, exact decimal aggregation, bounded gzip decoding, and bounded TSV processing.
- Fully validate cached JWT identity, signature, claims, lifetime, and expiry before reuse.
Security and privacy
- Webhook callbacks must use HTTPS and cannot contain credentials, fragments, invalid hosts, or malformed ports.
- Webhook secrets must be at least 32 characters, sufficiently diverse, non-repeating, and are never returned by the MCP.
- Resource IDs are encoded exactly once as URL path segments; unsafe, traversing, pre-encoded, query-bearing, and fragment-bearing endpoints are rejected before network access.
- Signed Apple upload URLs and headers are no longer exposed in results or transport-error diagnostics.
- Gzip reports validate headers, trailers, CRC32, trailing or concatenated data, decompressed size, and processing limits before returning data.
Compatibility and migration
All 389 public tool names remain registered, but several contract and security fixes intentionally reject inputs that were previously accepted:
- Pass raw App Store Connect resource IDs. Do not percent-encode IDs before calling a tool.
- Use strong webhook secrets and HTTPS callback URLs.
builds_update_beta_detailno longer accepts Apple's read-onlyinternal_build_stateorexternal_build_state.- Move app-level TestFlight contact and policy metadata from
builds_set_beta_localizationto the correspondingbeta_app_*_localizationtools. - Replace
app_versions_set_review_details.attachment_file_idwith a separatereview_attachments_uploadcall. - Subscription offer creators now require the Apple 4.4.1 inputs documented by their schemas, including
territory_ids,customer_eligibilities, orprice_point_idswhere applicable. - Signed upload URLs and headers are intentionally omitted. An upload still processing at Apple returns a non-error pending state instead of encouraging a duplicate upload.
Eight legacy tools remain registered with explicit deprecation guidance:
- Four promoted-purchase image tools whose Apple endpoints were removed.
subscriptions_get_availability,subscriptions_set_availability,subscriptions_list_available_territories, andsubscriptions_inventory, whose legacy availability resource was superseded by plan-type-aware availability APIs.
The contract gate proves operation identity, top-level input ownership, required Apple inputs, internal value bindings, and response lineage. Full optional enum, range, and response-schema parity remains future work; the current public tool mapping is 381 partial and 8 deprecated.
Verification
GitHub Actions on macOS 15 with Xcode 26.2 verifies:
- Debug and warning-free release builds.
- 792 Swift tests across 72 suites.
- Strict comparison with Apple's live App Store Connect 4.4.1 OpenAPI specification.
- Generated coverage parity and relocated release-binary resource loading.
- Annotated-tag provenance, main-branch ancestry, version, README install pin, and changelog consistency.
Upgrade
mint install zelentsov-dev/asc-mcp@v3.1.0 --force