Security
Last updated: September 28, 2026
What happens to the credentials you give AppStorePack, what they can do, and how to take access back.
Your App Store Connect API key
To fill your App Store listing for you, AppStorePack uses an App Store Connect API key you create and add on your Account page.
- Checked, then encrypted. When you add a key we first make a read-only call to Apple to confirm it works, then encrypt the private key with AES-256-GCM before it is stored. The encryption key is kept in our server environment, separate from the database, so the stored value is unreadable on its own.
- Never shown again. The private key is never sent back to your browser or included in any API or MCP response — you’ll only ever see its Key ID.
- Used only when you ask. Our server decrypts it only to make the App Store Connect calls you (or an app you connected, like Claude) request: listing your apps, planning a push, or pushing.
- Limited to your listing. A push updates the name, subtitle, keywords, promotional text and description for your project’s language, and replaces the iPhone 6.9″ and iPad 13″ screenshots. Fields you leave empty in AppStorePack are skipped, not blanked. It never submits your app for review — you do that in App Store Connect.
- Removable anytime. “Remove” on your Account page deletes the stored key. You can also revoke the key in App Store Connect, which stops it working everywhere immediately.
Our recommendation
- Create a dedicated key just for AppStorePack (for example named “AppStorePack”), so you can revoke it without affecting anything else.
- Give it the App Manager role, which can edit app metadata and screenshots.
- Apple describes the App Store Connect API as a tool for your team’s own workflow. Decide whether connecting a third-party tool fits how you manage your developer account — and if you’d rather not, you can always export your bundle and upload it yourself.
API tokens and connected apps (Claude)
- Personal access tokens (for Claude Code and other tools) are shown once when you create them. We store only a SHA-256 hash, so we can’t show them again — revoke and create a new one if you lose it.
- Connected apps such as Claude Desktop sign in through OAuth with your approval on a consent screen. Their access tokens expire after one hour and only work with the AppStorePack MCP server; refresh tokens rotate on every use.
- You can revoke tokens and disconnect apps anytime on your Account page; it takes effect immediately.
- Upload links that Claude or the in-chat upload panel use to send your screenshots and logo are single-purpose: each works for one project and one slot, and expires after 15 minutes.
- Downloadable export bundles are built on our servers only for accounts with an active subscription.
Infrastructure
- Everything is served over HTTPS.
- Data is stored with Supabase (database and file storage) and the app runs on Railway. Your projects and files are only accessible to your account.
Reporting a problem
If you think you’ve found a security issue, email support@appstorepack.com.