Apple Developer · 28.08.2026 · 4 мин

Apple Developer API & App Store Connect API: Getting Started

How to access the App Store Connect API: creating a key, JWT authorization, roles, and fixing common 401/403 errors on your first requests.


Apple Developer API & App Store Connect API: Getting Started

The App Store Connect API lets you manage apps, metadata, TestFlight testers, and financial reports programmatically — without touching the web UI. Here’s the basic access setup and JWT authorization.

How authorization works

Unlike a simple single-string API key, App Store Connect API uses a more layered scheme:

  1. API key — a pair consisting of a public part (kept by Apple) and a private key (a .p8 file you download once).
  2. JSON Web Token (JWT) — a token you generate and sign with your private key before each request, valid for a limited window (max 20 minutes).

Every API request needs a fresh JWT in the Authorization: Bearer header.

Step 1: Create an API key

  1. Sign in to App Store Connect → Users and Access → Integrations (or Keys, depending on the interface version).
  2. Click “Generate API Key” (or “+”).
  3. Name the key and choose an access role — this determines what the key can do, similar to regular user roles.
  4. Download the .p8 file — this is your only chance to download the private key; it can’t be reissued.
  5. Note the Key ID and Issuer ID, shown on the key’s page — you’ll need both to build your JWT.

Step 2: Build the JWT

Building the token requires three values:

The token is signed with ES256 and must include:

header: { "alg": "ES256", "kid": "<Key ID>", "typ": "JWT" }
payload: {
  "iss": "<Issuer ID>",
  "iat": <current time as a Unix timestamp>,
  "exp": <expiration, max +20 minutes from iat>,
  "aud": "appstoreconnect-v1"
}

Building a JWT by hand is impractical — in practice, developers use existing libraries (jsonwebtoken for Node.js, PyJWT for Python, equivalents for Java/Ruby) or tools like fastlane, which handle token generation from the three values above.

Step 3: Make your first request

With a valid JWT, a request is a standard REST call:

GET https://api.appstoreconnect.apple.com/v1/apps
Authorization: Bearer <your JWT>

A successful response returns the list of apps available to the role assigned to your API key.

How App Store Connect API authorization works

Common errors

401 Unauthorized

403 Forbidden

Usually means a role problem — the requested action is outside the permissions assigned when the API key was created. Fix it by creating a new key with a broader role, or adjusting your app’s logic to fit the current permissions.

The key works but can’t see provisioning-related data

For certificate and profile operations, it’s recommended to use a Team Key (a key with team-level, not individual-user, role) — some provisioning endpoints specifically require that access level.

401 vs 403: the difference

Security practices

FAQ

Do I pay separately to use the App Store Connect API?
No — API access is included with standard Apple Developer Program membership at $99/year.

Can I use one API key for multiple apps?
Yes, if the key’s role grants team-level access rather than being scoped to a specific app.

What if the .p8 private key gets lost after downloading?
You can’t re-download the same key — revoke it in App Store Connect and create a new one.


This article is independent and not affiliated with Apple Inc. For official documentation, see developer.apple.com/documentation/appstoreconnectapi.

Related: Certificates, Identifiers & Profiles: A Beginner’s Guide · How to Publish an App on the App Store: Step-by-Step · Developer Account Roles and Permissions Explained


Читайте дальше

Нужен аккаунт разработчика?Выдаём за сутки.