# App-Store-Connect-CLI: a JSON-first asc command line for App Store Connect

> The rorkai/App-Store-Connect-CLI project wraps the App Store Connect API in a Go binary called asc, aimed at CI pipelines and scripts rather than interactive use. Its strengths are output defaults and auth handling; its limits are Apple's API surface, macOS-only signing work, and telemetry that is on by default.

**rorkai/App-Store-Connect-CLI** — Project brief: Fast, scriptable CLI for the App Store Connect API. Automate TestFlight, builds, submissions, signing, analytics, screenshots, subscriptions, and more. JSON-first, no interactive prompts.

- Repository: https://github.com/rorkai/App-Store-Connect-CLI
- Website: https://asccli.sh
- Stars: 7,550 · Forks: 637
- Language: Go
- License: MIT
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/rorkai-app-store-connect-cli

## What asc replaces, and who ends up using it

App Store Connect is a web console. Anything repetitive in it, uploading a build, moving a build to a TestFlight group, editing metadata, submitting for review, is a sequence of clicks that does not survive contact with a release train. The App Store Connect API exists for that reason, but consuming it directly means JWT signing with an ES256 key, token refresh, pagination, and a different JSON shape per resource.

asc is a Go binary that wraps that API and exposes it as subcommands. The README describes it as "a fast, lightweight, and scriptable CLI for the App Store Connect API" and lists iOS, macOS, tvOS, and visionOS workflows. The intended user is whoever owns the release job: a mobile release engineer, a platform team maintaining a shared CI image, or a solo developer who wants the upload step out of a browser tab.

The design signal is in the output defaults. When stdout is a TTY, asc prints a table. When stdout is a pipe, a file, or CI, it prints JSON. That single rule tells you which audience the project optimises for. A tool built for humans would print tables everywhere and add a --json flag. asc does the opposite, and the README states explicit flags always win over the default.

## How asc talks to Apple: auth profiles, keychain, and JSON output

Authentication is stored as named profiles. asc auth login takes a key ID, an issuer ID, and a path to an AuthKey.p8 private key, and by default keeps the credential in the system keychain. The --bypass-keychain flag writes it as config instead, which is what you use on a headless runner where no keychain is available. There is also a --local variant that keeps credentials in ./.asc/config.json inside the repository, useful when you want the profile scoped to a checkout rather than the machine.

On top of the profile sits the request layer. Every command resolves the active profile, signs a JWT, calls the API, and renders the response through the output layer. The rendering layer is where the TTY detection lives, and ASC_DEFAULT_OUTPUT lets you set a global preference such as markdown without touching individual invocations.

The README also documents lifecycle labels. A command with no label is described as a stable public CLI contract. A command marked [experimental] is described as useful but still evolving, with sharper edges and faster iteration. Deprecated commands carry a DEPRECATED: marker or a warning. That labelling is more honest than most CLIs manage, and it is the thing to check before wiring a command into a release job that must not change behaviour under you.

## Installing asc and running a first authenticated command

The README recommends Homebrew. On macOS or Linux, the install script at asccli.sh is the alternative. Windows users are pointed at WinGet, with the caveat that the package may not be accepted yet, in which case the signed release binaries are the fallback.

Start by confirming the binary resolves and reading the top-level help.

```bash
asc version
asc --help
```

Next, register a profile. You generate the API key in the App Store Connect integrations page, and the private key file is the .p8 you download once. The --network flag is part of the documented login form.

```bash
asc auth login \
  --name "MyApp" \
  --key-id "ABC123" \
  --issuer-id "DEF456" \
  --private-key /path/to/AuthKey.p8 \
  --network
```

For CI or any machine without keychain access, the README gives this form instead. Note that the keychain flag is dropped and --bypass-keychain is added.

```bash
asc auth login \
  --bypass-keychain \
  --name "MyCIKey" \
  --key-id "ABC123" \
  --issuer-id "DEF456" \
  --private-key /path/to/AuthKey.p8
```

Validate before you build anything on top of it. asc auth status --validate checks the active profile, and asc auth doctor runs a health check. If keychain access is blocked at runtime, the README says to retry with ASC_BYPASS_KEYCHAIN=1.

```bash
asc auth status --validate
asc auth doctor
```

The first real command is a list of apps. Piped or redirected, it returns JSON; run in a terminal, it returns a table. Adding --pretty makes the JSON readable, which the README recommends for bug reports.

```bash
asc apps list --output table
asc apps list --output json --pretty
```

If uploads or API calls fail for no obvious reason, asc system-status checks Apple's developer services without credentials. The README marks it [experimental] and shows a --service filter and a --watch mode with --poll-interval 30s.

## Telemetry is on by default, and that is a decision you have to make

asc sends pseudonymous command-level telemetry by default. The README is unusually specific about what that includes: CLI version, operating system and architecture, the registered command path, duration, runtime context, invocation source, a bounded outcome class, and the HTTP status when a request fails. It may include a sanitized public flag name. The README states it does not include raw arguments, stderr, error messages, flag values, response bodies, credentials, private keys, Apple account, team or issuer IDs, app or bundle IDs, usernames, hostnames, repository names, or file paths.

A random installation ID groups events from one installation over time. The README says it is not derived from an Apple account or a machine identifier.

Three commands control it: asc telemetry status, asc telemetry disable, and asc telemetry reset-id. The environment variables ASC_TELEMETRY_DISABLED=1 and DO_NOT_TRACK=1 also switch it off. If your organisation has a policy against outbound telemetry from build machines, you need one of those set before the first CI run, not after. This is a real adoption cost and the README does not hide it, but it also does not make it opt-in.

## Where asc stops: signing, Apple's API surface, and non-Apple platforms

asc is a client of Apple's API, so it inherits every gap in it. If App Store Connect does not expose an operation, asc cannot invent it. The README's feature list covers TestFlight, builds, submissions, signing, analytics, screenshots, and subscriptions, but the depth of each is not something the README quantifies, and the repository marks some commands [experimental]. Treat the command reference as the source of truth for what is actually supported rather than the feature list.

Signing is the area where expectations most often go wrong. The go.mod file pulls in bitrise-io/go-xcode, bitrise-io/go-pkcs12, and sslmate/go-pkcs12, which indicates certificate and provisioning profile handling implemented in Go. That is a substantial dependency surface, and it is the part of the toolchain most sensitive to Xcode version drift. Even where asc manages certificates, producing a signed archive still requires Xcode and a macOS host. asc does not remove the Mac from an iOS release pipeline.

The other boundary is the platform itself. App Store Connect is Apple's service. The related searches include questions about an Android version, and nothing in the project's documentation indicates that one exists. If you ship on Google Play, this tool has nothing to say to you.

Finally, the WinGet package may not be accepted yet. The README points Windows users at the signed release binaries until winget search asc returns a result. That is a documented rough edge, not a permanent one, but it means Windows setup is not a one-liner today.

## How asc differs from Fastlane and from calling the API directly

Fastlane is the obvious comparison, and the difference is architectural rather than cosmetic. Fastlane is a Ruby toolchain built around a Fastfile, lanes, and a large plugin ecosystem. Its value is the orchestration layer: you describe a release as a sequence of lanes and let the tool sequence the steps. asc has no equivalent of a lane file. It is a set of independent subcommands that each do one API operation and return structured output. Orchestration is your problem, expressed in whatever the CI system already uses.

That trade cuts both ways. With asc you get a single self-contained binary, JSON on stdout, and no Ruby runtime to install on the runner. You give up the batteries-included workflows, and you write more shell.

Calling the App Store Connect API directly is the other alternative, and it is a genuine one if you need only one or two endpoints. The cost is JWT signing, token lifetime handling, pagination, and per-resource JSON schemas. asc exists to absorb exactly that, which is why the profile and output layers are the parts of it worth evaluating. If you already have a working API client in your codebase, asc adds a binary rather than replacing a dependency.

The project also ships Agent Skills through asc install-skills, which checks out a pinned commit and copies 23 skills into the global agent-skills directory. The README states it requires only git and does not execute Node.js, npx, or repository scripts, and that it verifies the pack and rolls back on failure. That is a separate concern from the CLI itself, but it is part of the install surface you should be aware of.

## Maintenance, licensing, and what an upgrade actually costs

The repository is not archived, and the last push was on 2026-08-27, with 4.10.0 released the same day. That is recent enough that the project is not dormant.

The upgrade cost is visible in the repository layout: migrate-to-4-0.mdx and migrate-to-5-0.mdx sit at the top level alongside quickstart.mdx and installation.mdx. Two major migrations with dedicated guides means the CLI contract has changed in ways that required users to edit scripts. The stability labels described earlier exist precisely because of that history. Before you pin asc into a release job, read both migration files and decide whether you are pinning a version or tracking latest.

asc is MIT licensed. That permits commercial and internal use, modification, and redistribution, subject to the usual condition that the copyright notice and licence text travel with copies. The dependencies are separate works under their own licences, and the go.mod file lists a long set of them, including AWS SDK modules and several Bitrise packages. If your organisation runs licence scanning, that dependency list is what the scanner will read; the README does not state that the project audits those licences for you.

Builds from source use the Go toolchain version declared in go.mod, and the Makefile defines both a development build and a release build with stripped symbols and trimmed paths. Released binaries are self-contained and do not require a Go installation.

## Conclusion

Adopt asc if your release process already runs in a shell or CI job and you want Apple's API behind one binary with predictable JSON output. Skip it if you need a GUI, if you are not on macOS for signing work, or if your team will not accept telemetry enabled by default. Before depending on it, run asc auth doctor against a real key, check which commands carry the [experimental] label, and read the migration notes for 4.0 and 5.0 in the docs directory, since the CLI has already broken its own contract once.

## FAQ

### What is App Store Connect used for?

App Store Connect is Apple's web console for managing apps, builds, TestFlight, metadata, and submissions. asc is a command line client for the App Store Connect API, so it automates those same operations from a terminal or CI job rather than a browser.

### Is App Store Connect free?

The README does not discuss App Store Connect pricing or Apple Developer Program membership costs. It only covers the asc CLI, which is MIT licensed and free to use.

### What is a CLI-based app?

A CLI-based app is operated through typed commands in a shell instead of a graphical interface. asc fits that description: the README describes it as scriptable and JSON-first, with no interactive prompts, and its output defaults to JSON whenever stdout is not a terminal.

### What is the difference between the App Store and App Store Connect?

The App Store is the consumer storefront where users download apps. App Store Connect is the developer-facing console where apps, builds, TestFlight groups, and submissions are managed, and it is the service asc targets through its API.

## Sources

- [Official documentation](https://asccli.sh)
- [Official README](https://github.com/rorkai/App-Store-Connect-CLI#readme)
- [Project repository](https://github.com/rorkai/App-Store-Connect-CLI)
- [Release notes](https://github.com/rorkai/App-Store-Connect-CLI/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/rorkai-app-store-connect-cli
