For developers · Checked 30 September 2026

App Store Connect API key: create it, store it, use it

Short answer: in App Store Connect, go to Users and Access > Integrations > App Store Connect API, pick Team Keys and click Generate API Key; you need the Admin role. Give it a name and a role, then download the private key right away: Apple lets you download it only once and keeps no copy. The same page shows the key ID and the issuer ID, the other two values tools such as CI and upload scripts ask for.

Team key or individual key

From Apple «Creating API Keys for App Store Connect API», read 30 September 2026.

Team keyIndividual key
AccessAll apps, limited by the role you assignThe apps and permissions of the user who owns it
Who can create itAn AdminA user with the Generate Individual API Keys permission
WhereUsers and Access > Integrations > App Store Connect API > Team KeysYour user profile > Individual API Key
JWT identity fieldiss: your issuer IDsub: user
LimitsRole-basedNo Provisioning endpoints, no Sales and Finance, no notarytool

Choose the role carefully

A team key gets one role, and the roles are the same as for people on your team. An Admin key can create and delete users, so give CI or an upload script the narrowest role that does the job. Team keys see all apps whatever their role, so if a tool should only touch what one person can see, an individual key tied to that user is the tighter option, with the limits in the table above.

Store the private key like a password

The private key downloads once; if you lose it, you generate a new key. Apple asks you not to share keys, not to commit them to a code repository and not to put them in client-side code. Keep it in your CI’s secret store, and give each tool its own key so you can revoke one without breaking the rest. App Store Connect API keys work only with the App Store Connect API, not with other Apple services.

How requests are signed

Every API request carries a JSON Web Token you sign with the private key. The header uses alg ES256, kid set to your key ID and typ JWT. For a team key the payload holds iss (issuer ID), iat (issued at), exp (expiry) and aud set to appstoreconnect-v1; an individual key uses sub set to user instead of iss. An optional scope array limits the token to specific GET requests. For most requests App Store Connect rejects a token whose lifetime, exp minus iat, is longer than 20 minutes, so tools generate a fresh token as they go.

Revoke a key the moment it leaks

If a key is lost, unused or might be exposed, revoke it: an Admin does it in Users and Access, on the keys list, with Edit, then Revoke Key; you can revoke your own individual key from your profile. Revoking cannot be undone, and revoked keys stay visible for 30 days under the Revoked heading. Generate a replacement, update the secret in your tools, and check that builds and uploads still run.

Where Censuus fits

Automating releases keeps updates flowing; being found is the rest. Censuus ranks apps by the visits they draw, and adding your app is free on the List my app form. Placement comes from traffic and sponsorship: apps climb on the visits they draw, and a sponsor can pay to rise higher.

Frequently asked questions

Where do I find my App Store Connect API issuer ID?

In App Store Connect, under Users and Access, on the Integrations tab. The issuer ID is near the top of the page with a Copy button.

Where is the key ID?

On the same Integrations page, in the column under Active keys; hover next to a key ID to copy it. For an individual key, it is on your user profile under Individual API Key.

Can I download the private key again?

No. Apple offers the download once and keeps no copy. If you lose it, revoke the key and generate a new one.

How long can an App Store Connect API token be valid?

For most requests, no more than 20 minutes between the issued-at and expiration times. Apple suggests about two minutes for a one-off request.

Who can create a team API key?

Only a user with an Admin account in App Store Connect.

Guides for app developers

Put your app in the ranking

Censuus ranks apps by the visits they draw and by sponsorship, no bots. Listing is free; sponsorship raises placement.