App Store Connect API key: create it, store it, use it
Short answer: in App Store Connect, go to Users and Access > Integrations > App Store Connect API, pick Team Keys and click Generate API Key; you need the Admin role. Give it a name and a role, then download the private key right away: Apple lets you download it only once and keeps no copy. The same page shows the key ID and the issuer ID, the other two values tools such as CI and upload scripts ask for.
Team key or individual key
From Apple «Creating API Keys for App Store Connect API», read 30 September 2026.
| Team key | Individual key | |
|---|---|---|
| Access | All apps, limited by the role you assign | The apps and permissions of the user who owns it |
| Who can create it | An Admin | A user with the Generate Individual API Keys permission |
| Where | Users and Access > Integrations > App Store Connect API > Team Keys | Your user profile > Individual API Key |
| JWT identity field | iss: your issuer ID | sub: user |
| Limits | Role-based | No Provisioning endpoints, no Sales and Finance, no notarytool |
Choose the role carefully
Store the private key like a password
How requests are signed
alg ES256, kid set to your key ID and typ JWT. For a team key the payload holds iss (issuer ID), iat (issued at), exp (expiry) and aud set to appstoreconnect-v1; an individual key uses sub set to user instead of iss. An optional scope array limits the token to specific GET requests. For most requests App Store Connect rejects a token whose lifetime, exp minus iat, is longer than 20 minutes, so tools generate a fresh token as they go.Revoke a key the moment it leaks
Where Censuus fits
Frequently asked questions
Where do I find my App Store Connect API issuer ID?
In App Store Connect, under Users and Access, on the Integrations tab. The issuer ID is near the top of the page with a Copy button.
Where is the key ID?
On the same Integrations page, in the column under Active keys; hover next to a key ID to copy it. For an individual key, it is on your user profile under Individual API Key.
Can I download the private key again?
No. Apple offers the download once and keeps no copy. If you lose it, revoke the key and generate a new one.
How long can an App Store Connect API token be valid?
For most requests, no more than 20 minutes between the issued-at and expiration times. Apple suggests about two minutes for a one-off request.
Who can create a team API key?
Only a user with an Admin account in App Store Connect.
Guides for app developers
- How to market an app: a stage-by-stage plan
- Submit your app for free
- How to get your app to show up in Google search
- How to get your app recommended by AI assistants
- Free app promotion sites, checked for dofollow
- App store optimization checklist: what Apple and Google actually say
- App launch checklist: iOS and Android, step by step
- How to find beta testers for your app
- How to get more app reviews without breaking the store rules
- How to get your app featured on the App Store and Google Play
- App Store and Google Play screenshot sizes: what you must upload
- How to promote an app on Google Play with Play Console’s own tools
- How to promote an iOS app with App Store Connect’s own tools
- App Store keywords: how to fill the 100-character field
- How to market a fitness app: what Apple and Google let you claim
- How to market a kids app: the store rules that shape it
- How to market a finance app: the store rules to know first
- How to market a dating app: the store rules that shape it
- How to market a subscription app: what the stores require of your offer
- How to market a mobile game: the store rules that shape it
- Apple Ads MCP: connect an AI assistant to your campaigns
- How to promote an app on TikTok with creators
- How to promote an app on YouTube with creators
- How to market a VPN app: the store rules to know first
- How to market an AI app: the store rules that shape it
- How to market an education app: schools, parents and learners
- How to localize your App Store and Google Play listing
- Android vitals and Google Play visibility: the thresholds that hide apps
- App Store and Google Play age ratings: what drives them
- App Store privacy labels and Google Play Data safety: what to declare
- Common App Store rejection reasons and how to avoid them
- How to get the first users for your app
- App preview video specs: App Store sizes, length and rules, and the Google Play video
- App Store custom product pages, and the Google Play version
- App icon size for the App Store and Google Play
- App Store phased release and Google Play staged rollouts
- App Store subtitle and promotional text: limits and how to use them
- Google Play feature graphic: size, placement and rules
- TestFlight public link: set it up, limit it, and fix it when it does not work
- App Store promo codes and offer codes: how they work and their limits
- App Store A/B testing: product page optimization and Google Play experiments
- App Store in-app events: limits, badges and media sizes
- App Store Connect analytics: what each metric means
- Google Play store listing reports: clicks, CTR and the 2026 changes
- Google Play target API level requirements for 2026
- Android developer verification: what changed on September 30, 2026
- App Store and Google Play fees in 2026
- Google Play’s 12 testers for 14 days rule, explained
- How to transfer an app to another developer account
- How to remove an app from the App Store and Google Play
- The app account deletion requirement on the App Store and Google Play
- Google Play 16 KB page size requirement: dates, checks and fixes
- Declared Age Range and Play Age Signals: age assurance APIs for app developers
- Xcode 26 and the iOS 26 SDK requirement for App Store Connect
- The iOS privacy manifest: what to declare and how
- Accessibility Nutrition Labels: what to declare on your App Store page
- Google Play’s photo and video permissions policy, explained
- Google Play Billing Library version requirement: what you need to ship now
- App Tracking Transparency: when to ask and how
- How to submit an In-App Purchase for review
- The Play Integrity API: what it checks and how to use it
- How long app review takes on the App Store and Google Play
- Google Play policy updates in 2026, with the deadlines
- Rosetta 2 end of support: what Mac developers need to do
- Monthly subscriptions with a 12-month commitment on the App Store
- Subscription Bundles, Suites and multiseat purchases on the App Store
- Sign in with Apple private relay email and the new private.icloud.com domain
- App Store Server Notifications V2: switching from V1 and handling every event
- Migrating to StoreKit 2: what is deprecated and what replaces it
- App Store creative assets: headers and search result visuals in iOS 27
- On-Demand Resources is deprecated: moving to Background Assets
- Time Allowances in iOS 27: how your app gets its category
- Android Contact Picker and the new READ_CONTACTS rules
- The Android 17 location button and Google Play’s precise location rules
- Phone verification without READ_CALL_LOG: what replaces call-based checks
- Apple’s EU business terms from October 1, 2026
- Android 17 app memory limits: detect, test and stay under them
- The Android 17 local network permission
- Android 17 background audio hardening
- Cleartext HTTP and certificate transparency on Android 17
- Android 17: lock-free MessageQueue and static final fields
- Android 17 ignores orientation lock and resizability on large screens
- Android 17 behavior changes: a checklist for target SDK 37
- Preparing your app for iPhone Duo
- Google Play subscription grace period and account hold
- Getting your Android app ready for Googlebook
- The Android 17 Handoff API
- ADB Wi-Fi 2.0 wireless debugging
- Android AppFunctions: your app as on-device tools for AI agents
- Android Live Updates: how to qualify for a promoted notification
- App Store Connect webhooks
- Apple Foundation Models: on-device vs Private Cloud Compute
- Using Claude, Codex and other agents in Android Studio
- Gemini Nano for Android developers
- Firebase AI Logic: the App Check deadline and Gemini 2.5 shutdowns
- Swift 6.4: what’s new for app developers
- The Swift SDK for Android
- Publishing your game on Android Auto and Android Automotive OS
- Liquid Glass in a Compose Multiplatform app
- Expo SDK 58: when it ships and what changes
- Device Hub in Xcode 27
- Using the Xcode MCP server with Claude Code, Codex and other agents
- Xcode 27: release, requirements and point releases
- Gemma 4 and Android skills in Android Studio
- The UIScene life cycle is required in iOS 27
- Migrating to Android Gradle plugin 9
- Navigation 3 for Jetpack Compose
- Kotlin 2.4, 2.4.20 and the road to 2.5
- Upgrading your app build to Gradle 9
- The latest Compose BOM and Compose 1.12
- Compose Multiplatform 1.12 and the Hot Reload MCP server
- Opting out of Liquid Glass with UIDesignRequiresCompatibility
- Flutter 3.47 and the latest stable version
- React Native 0.87 and the latest version
- Android Studio Quail 4 and what comes next
- CocoaPods goes read-only: what changes and when
- Fixing YouTube Error 153 in embedded players
- Fixing “APNS token has not been set yet” in Firebase Messaging
- Older iOS Simulator runtimes and Rosetta destinations in Xcode
- Fixing the fmt consteval error in React Native on Xcode 26.4
Put your app in the ranking
Censuus ranks apps by the visits they draw and by sponsorship, no bots. Listing is free; sponsorship raises placement.