Skip to content

zelentsov-dev/asc-mcp

v3.15.0 Breaking

This release includes 1 breaking change for platform teams planning a safe upgrade.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai-tools app-store-connect claude in-app-purchase ios macos
+6 more
mcp model-context-protocol subscriptions swift testflight xcode-cloud

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Requires exact resource-ID confirmation for destructive version and phased‑release actions.

Full changelog

App lifecycle and deletion safety

  • Adds complete age-rating declaration reads and calculated territory age-rating tools.
  • Extends version listing with validated array filters and query-bound pagination.
  • Hardens version, App Info, review, age-rating, and phased-release identity validation before mutations.
  • Requires exact resource-ID confirmation for destructive version and phased-release actions.
  • Stops ambiguous DELETE retries after network, timeout, or server failures and returns typed recovery guidance with retrySafe=false.
  • Preserves HTTP 202 accepted outcomes for beta tester removals and verifies app removal across every pagination page.

Compatibility

  • Public MCP surface grows from 401 to 403 tools; no existing tool was removed or renamed.
  • Two destructive lifecycle tools now require exact confirmation IDs.
  • All 1,263 pinned Apple App Store Connect API 4.4.1 operations remain classified: 375 mapped, 525 deferred, and 363 scoped out.
  • All 2,265 reviewed optional inputs are classified with zero unclassified parameters.

Verification

  • Full CI passed on develop, main, and annotated tag v3.15.0.
  • Debug and release builds passed with zero release warnings.
  • Apple operation contract, generated coverage, upload contract, full Swift test suite, and release contract passed.
  • Final SHA e6cccc0cd086778317c653299eca03dd2fe343fc received independent review with no P0-P2 findings.

Breaking Changes

  • Requires exact resource-ID confirmation for destructive version and phased-release actions.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track zelentsov-dev/asc-mcp

Get notified when new releases ship.

Sign up free

About zelentsov-dev/asc-mcp

App Store Connect API server with 208 tools for managing apps, builds, TestFlight, subscriptions, reviews, and more — directly from any MCP client.

All releases →

Related context

Earlier breaking changes

  • v3.1.0 `app_versions_set_review_details.attachment_file_id` replaced by separate `review_attachments_upload` call.
  • v3.1.0 Moved app-level TestFlight contact and policy metadata from `builds_set_beta_localization` to corresponding `beta_app_*_localization` tools.
  • v3.1.0 `builds_update_beta_detail` no longer accepts read-only fields `internal_build_state` or `external_build_state`.
  • v3.0.0 Removed public prefixes `offer_codes_*`, `intro_offers_*`, `promo_offers_*`, and `winback_*` from v3 worker schema.

Beta — feedback welcome: [email protected]