Skip to main content

App Store Connect roles

RolePermissions it grantsRisk if the agent goes wrong
AdminFull control over everything, including user management (users), code-signing (provisioning) and webhooks (webhooks).Highest. Can revoke other users' access and delete certificates/profiles — which breaks signing for the whole team. Blast radius extends beyond your own app.
App ManagerManage apps end to end: metadata (apps), versions (versions), builds (builds), TestFlight (testflight), subscriptions and IAP (subscriptions, iap), pricing (pricing).High. Can submit or withdraw a live version and delete an in-app purchase or subscription group. Directly affects your live listing and revenue.
DeveloperBuild and test only: builds (builds), TestFlight (testflight), Xcode Cloud (xcode_cloud) — upload, not submission.Medium. Can remove testers, builds and beta groups, but can't touch pricing, live metadata, or submit for review.
MarketingManage store presence: screenshots, custom pages, in-app events and reviews (marketing).Medium. Can remove custom product pages, previews and in-app events that are already customer-facing.
SalesRead sales and trends reports (analytics).Low. Almost entirely read-only — report requests, nothing that changes your listing.
FinanceRead financial and payment reports (analytics; also needs ASC_VENDOR_NUMBER).Low. Same read-heavy analytics domain as Sales.
Customer SupportRead and reply to customer reviews (reviews, including reviews_ai__*).Low–medium. One operation posts a public reply — reversible, but visible to customers before you catch a mistake.
note

Most day-to-day release work needs only App Manager. Developer is enough for CI build uploads. Add Finance/Sales only if you actually run analytics tools.

Least privilege in practice​

The table above is what you choose when creating the key in App Store Connect. A few limits remain regardless.

  • First requesting an analytics report type on an account needs Admin. There is no path to it in the App Store Connect web UI at all; it has to come from the API, with an Admin key.

  • Nothing reaches the Account Holder's area, at any role. Contracts, tax forms and banking are managed only on their own web page. Until an unsigned or expired agreement is accepted, the account is blocked.

  • Reading what a key actually has: call asc__status with check_capabilities: true.

StateMeaning
okThe probe succeeded. This family is open.
forbiddenApple refused this specific request. The key authenticates; this family is not in its role.
unauthorizedThe key itself is not authenticating — every family will read this way, and the fix is the key, not a role.
agreementThe account has an unsigned or expired agreement — the same 403 a narrow role would give, for an unrelated reason. Only the Account Holder can clear it, at developer.apple.com/account; no key, however wide, fixes this.
unknownInconclusive: a network failure, a 5xx, or (for reports/metadata/reviews) no app on the account to probe against. Never treat this as a denial — it is not one.