Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.gbatistuta0/appfactory

PYPI · APPFACTORY · SCANNED OCT 4

Lets your coding agent ship a SwiftUI iOS subscription app from idea to TestFlight.

Available components

75 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security100
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
  • 1 of 22 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to gbatistuta0/appfactory). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 4 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability48
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • Instruction-quality not yet verified: the AI judgement didn't run.Unverified
  • Context-footprint check failed: tool/resource definitions use about 19176 tokens (~152/item across 126 items; 125 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • Manipulation not yet verified: only 2 of 127 captured unit(s) of tool text has been judged so far, so we will not certify text no model has read as clean.Unverified
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

How do I install the io.github.gbatistuta0/appfactory MCP server?

io.github.gbatistuta0/appfactory runs locally as a PyPI package, launched with uvx appfactory. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

pypi · appfactory

# add to Claude Code
claude mcp add gbatistuta0-appfactory -- uvx appfactory
// .cursor/mcp.json
{
  "mcpServers": {
    "gbatistuta0-appfactory": {
      "command": "uvx",
      "args": [
        "appfactory"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "gbatistuta0-appfactory": {
      "command": "uvx",
      "args": [
        "appfactory"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add gbatistuta0-appfactory -- uvx appfactory
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "gbatistuta0-appfactory": {
      "type": "local",
      "command": [
        "uvx",
        "appfactory"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add gbatistuta0-appfactory --command uvx --arg appfactory
# ~/.hermes/config.yaml
mcp_servers:
  gbatistuta0-appfactory:
    command: "uvx"
    args: ["appfactory"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "gbatistuta0-appfactory": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "appfactory"
      ]
    }
  }
}
# add to Vellum
assistant mcp add gbatistuta0-appfactory -t stdio -c uvx -a appfactory
// mcp.json
{
  "mcpServers": {
    "gbatistuta0-appfactory": {
      "command": "uvx",
      "args": [
        "appfactory"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 30 Sept 26 +15
    • Malware scan: unverified → pass ▲ security
  • 29 Sept 26 60

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 6 Oct 2026 · Analysed pypi/appfactory@0.1.5

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem pypi
Reason Verified
Discovered via Registry attestation endpoint
Source repo gbatistuta0/appfactory
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/gbatistuta0/appfactory/.github/workflows/release.yml@refs/tags/v0.1.5
Rekor log index 3004333188
Predicate type PyPI publish attestation https://docs.pypi.org/attestations/publish/v1
Subject digest sha256:19e11c989976e965a51efa3cbc68c13783dfdc12d467cef474242976ecf7de2f

Background: How many MCP packages publish verified provenance →

Install scripts 1 script
Hook Tier Command
build_backend allowlisted hatchling.build

Background: Why install scripts are a supply-chain risk →

Dependencies 22 packages
Packages resolved 22
Stale 1
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 125 exposed · ~18,907 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
ai_configure ~78

Report the AI provider/model selection (currently fal.ai Flux schnell); does not change anything. Use when: checking which image model the backend will use. Keys are set with ai_deploy_proxy or backend_deploy. Returns: {ok, providers, models, note}.

NameTypeReqDescription
providers––AI provider ids; default ['fal.ai'].

Structured output declared, but exposes no named fields.

No examples provided.

ai_deploy_proxy ~201

Deploy the AI backend: the full spec-driven backend in subscription mode, or the legacy ai-proxy in credits mode (live, needs human approval). Use when: the app has an AI feature. AI keys go only to server-side secrets. For explicit dry-run planning use backend_deploy. Returns: {ok, deployed: [...]} or an approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
daily_limitinteger–Per-user daily request cap for the legacy ai-proxy (default 20).
project_refstringyesSupabase project ref to deploy to.

Structured output declared, but exposes no named fields.

No examples provided.

animation_fetch_recolor ~223

Fetch a cute Lottie animation from the free LottieFiles library and recolor it to the app palette into Resources/Animations/<slot>.json. Use when: once per slot (loading, success, empty, onboarding_hero) for every app; rendered by lottie-spm with .named(slot). Colors are mapped at build time (dominant to primary, others to accent). Returns: {ok, path, source, colors}.

NameTypeReqDescription
accent_hexstringyesAccent palette color as hex, '#' optional, e.g. 'FFB300'.
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
keyword––App-themed search keyword override, e.g. 'happy dog celebration'.
primary_hexstringyesPrimary palette color as hex, '#' optional, e.g. '006A63'.
slotstringyesAnimation slot: 'loading', 'success', 'empty' or 'onboarding_hero'.

Structured output declared, but exposes no named fields.

No examples provided.

app_inject_config ~377

Fill in the scaffolded app's AppConfig and StoreKit tokens (Supabase, proxy, PostHog, product ids, credits, paywall strategy). Use when: after backend and RevenueCat values exist. Credit fields default to 15/10/10/30/60 and pack amounts must match the server-side PACK_MAP. Not for: spec-driven changes (edit app.spec.json, then app_sync_spec). Returns: {ok, changed: [files]}.

NameTypeReqDescription
ai_proxy_url––URL of the deployed AI proxy/edge function.
credit_pack_large––Credits in the large top-up pack (default 60).
credit_pack_medium––Credits in the medium top-up pack (default 30).
credit_pack_small––Credits in the small top-up pack (default 10).
paywall_strategy––'hard_only' (hard paywall only) or 'hard_and_offer' (default: plus a discounted offer paywall on dismiss).
posthog_key––PostHog project API key.
privacy_url––Public privacy policy URL.
product_weekly––Weekly subscription product id.
product_yearly––Yearly subscription product id.
project_dirstringyesPath to the scaffolded app project directory.
revenuecat_key––RevenueCat public SDK key (appl_...).
supabase_anon_key––Supabase anon (public) key.
supabase_url––Supabase project URL, e.g. https://abcd.supabase.co.
support_email––Public support email address.
weekly_credits––Credits granted per week on the weekly plan (default 10).
yearly_credits––Credits granted per month on the yearly plan (default 15).

Structured output declared, but exposes no named fields.

No examples provided.

app_scaffold ~207

Scaffold a new SwiftUI app from app.spec.json (xcodegen), init the pipeline manifest and a local git repo. Use when: starting a new app after idea validation. The spec drives products, StoreKit file, locales, onboarding length, monetization mode and backend mode. Not for: editing an existing app (use app_sync_spec after changing the spec). Returns: {ok, dir, name, bundle_id, manifest}.

NameTypeReqDescription
bundle_id––App bundle identifier in reverse-DNS form, e.g. com.example.app.
dest_dir––Directory to create the app folder in; omit for the default apps directory.
display_name––Name shown under the app icon; defaults to name.
name––App name, e.g. 'PetPortrait'; used for the folder and target.
spec––Full app.spec.json as a dict, a dict of overrides on the defaults, or a path to an app.spec.json file.

Structured output declared, but exposes no named fields.

No examples provided.

app_sync_spec ~85

Regenerate AppSpec.swift, PaywallSource.swift and Configuration.storekit and prune String Catalogs to locales.app. Use when: after editing app.spec.json. Local writes only. Returns: {ok, files}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

asc_add_subscription_group_localization ~161

Add one display-name localization to a subscription group (required to clear MISSING_METADATA; live write, needs human approval). Use when: a single locale is needed. For many languages use asc_localize_group. Returns: {ok, data} or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
group_idstringyesApp Store Connect subscription group id.
localestring–Locale code, e.g. 'en-US', 'de-DE'.
namestringyesSubscription group display name shown to users.

Structured output declared, but exposes no named fields.

No examples provided.

asc_append_subscription_disclosure ~236

Append the subscription disclosure, Terms/EULA and Privacy links to the app description in every language (Apple 3.1.2; live write, needs human approval). Use when: preparing a subscription app for review. Idempotent (skips when the marker is present) and truncated to 4000 characters. Not for: uploading other metadata (use deliver_metadata). Returns: {ok, per-locale results} or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.
disclosure_by_locale––Optional {locale: disclosure text} overriding the default subscription disclosure per language.
privacy_urlstringyesPublic privacy policy URL, e.g. https://example.com/privacy.
terms_url––Terms of Use/EULA URL; omit to use Apple's standard EULA.

Structured output declared, but exposes no named fields.

No examples provided.

asc_create_app ~235

Create an app shell in App Store Connect via fastlane produce (live write, needs human approval). Use when: after aso_check_name confirms a free name; pass candidate_names and the first available is used. Not for: bundle ids (asc_create_bundle_id) or metadata (deliver_metadata). Returns: {ok, app_id, name, ...} or an approval_required refusal.

NameTypeReqDescription
app_name––Single app name; prefer candidate_names. Converted to a one-element candidate list.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.
candidate_names––Ordered candidate App Store names; the first one not already taken is used.
primary_languagestring–Primary App Store language, e.g. 'en-US'.
sku––Unique SKU string for the app record; omit to derive from the bundle id.

Structured output declared, but exposes no named fields.

No examples provided.

asc_create_bundle_id ~252

Register a bundle id in App Store Connect and check or apply its App ID capabilities (live write, needs human approval). Use when: first ASC step for a new app; capabilities (IN_APP_PURCHASE, Sign in with Apple, HEALTHKIT if enabled) must exist before signing. Not for: creating the app record (use asc_create_app). Returns: {bundle_id: <ASC result>, capabilities: <store_setup report>} or an approval_required refusal.

NameTypeReqDescription
app_dir––Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
apply_capabilitiesboolean–If true, also enable the spec's App ID capabilities (needs app_dir); false only checks them.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
identifierstringyesBundle identifier to register, e.g. com.example.app.
namestringyesHuman-readable name of the bundle id in the developer portal, e.g. 'My App'.

Structured output declared, but exposes no named fields.

No examples provided.

asc_create_subscription ~212

Create a subscription product inside a subscription group (live write, needs human approval). Use when: hand-building a single product. Prefer store_setup for the whole spec. Returns: {ok, data: {data: {id, ...}}} or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
family_shareableboolean–Whether the subscription can be shared with family members; default false.
group_idstringyesApp Store Connect subscription group id.
namestringyesInternal reference name of the subscription product.
periodstring–Subscription period enum: ONE_WEEK, ONE_MONTH, TWO_MONTHS, THREE_MONTHS, SIX_MONTHS or ONE_YEAR.
product_idstringyesProduct identifier of the subscription, e.g. com.example.app.yearly.

Structured output declared, but exposes no named fields.

No examples provided.

asc_create_subscription_group ~183

Create a subscription group for an app (live write, needs human approval). Use when: hand-building the subscription tree. Prefer store_setup, which does groups, products, prices and offers idempotently from app.spec.json. Returns: {ok, data: {data: {id, ...}}} or an approval_required refusal.

NameTypeReqDescription
app_idstringyesApp Store Connect app id (numeric Apple id, e.g. '1234567890'); for aso_competitor_iap the iTunes trackId.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
reference_namestringyesInternal reference name of the subscription group (not shown to users).

Structured output declared, but exposes no named fields.

No examples provided.

asc_ensure_subscription_prices ~202

Set a price on every subscription of the app that has none, clearing MISSING_METADATA (live write, needs human approval). Use when: subscriptions are stuck in MISSING_METADATA for price. Idempotent: priced subscriptions are skipped. Returns: {ok, priced: [...], skipped: [...]} or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.
default_usd––USD price string applied to subscriptions not listed in usd_price_by_product.
usd_price_by_product––Map of subscription productId to USD price string, e.g. {'com.example.app.yearly': '49.99'}.

Structured output declared, but exposes no named fields.

No examples provided.

asc_finalize_submission_requirements ~354

Fill the submit-blocking app-level fields in one call: content rights, copyright, age rating (4+), free price, App Review contact and notes (live write, needs human approval). Use when: once per app before asc_submit_for_review. App Privacy is not in Apple's API and must be set in the ASC web UI. Missing copyright falls back to config; missing contact_email to support_email. Returns: {ok, steps...} or an approval_required refusal.

NameTypeReqDescription
ai_services––Short description of the AI services the app uses, inserted into the review notes.
app_name––App name used to fill the generic App Review notes template.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.
contact_email––App Review contact email; defaults to the config support_email.
contact_firststring–App Review contact first name.
contact_laststring–App Review contact last name.
contact_phonestring–App Review contact phone in international format, e.g. '+14155550100'.
copyright––Copyright line for the store listing, e.g. '2026 Example Ltd'; falls back to the config 'copyright' key.
freeboolean–If true (default) the app price is set to Free.
review_notes––Custom App Review notes; omit to fill the generic 7-item test-flow template.

Structured output declared, but exposes no named fields.

No examples provided.

asc_finalize_subscription ~271

Finalize one subscription in order: localization, availability (all but CHN), price, intro offer (live write, needs human approval). Use when: fixing a single product by hand. Prefer store_setup, which does every product idempotently. Pass the spec product's intro (e.g. {"type": "free", "duration": "P3D"}); offer products get no intro. Returns: {ok, steps...} per step, or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
descriptionstringyesSubscription description shown to users (en-US).
intro––Intro offer from the spec product, e.g. {"type": "free", "duration": "P3D"}; omit for offer products (no intro).
namestringyesSubscription display name shown to users (en-US).
period––Ignored; kept for backward compatibility.
sub_idstringyesApp Store Connect subscription id.
usd_pricestringyesUSD base price as a decimal string, e.g. '49.99'.

Structured output declared, but exposes no named fields.

No examples provided.

asc_get_app ~94

Find one App Store Connect app by bundle id (live, read-only). Use when: you need the numeric app id for a known bundle id. Not for: listing all apps (use asc_list_apps). Returns: {ok, data: {data: [app resources]}} from the ASC API.

NameTypeReqDescription
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.

Structured output declared, but exposes no named fields.

No examples provided.

asc_list_apps ~69

List the apps in App Store Connect (live, read-only). Use when: you need app ids or want to see what exists. To find one app by bundle id use asc_get_app. Returns: {ok, count, apps: [{id, bundleId, name, sku}]}.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

asc_localize_group ~148

Localize a subscription group's display name in many languages at once (live write, needs human approval). Use when: several locales are needed; for one locale use asc_add_subscription_group_localization. Returns: {ok, done: [locales], skipped: [locales]} or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
group_idstringyesApp Store Connect subscription group id.
name_by_localeobjectyesMap {locale: group display name}.

Structured output declared, but exposes no named fields.

No examples provided.

asc_localize_subscription ~156

Localize a subscription's name and description in many languages at once (live write, needs human approval). Use when: filling per-locale product copy. Languages the IAP API does not support are skipped. Returns: {ok, done: [locales], skipped: [locales]} or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
itemsobjectyesMap {locale: {name, description}} of subscription display copy per locale.
sub_idstringyesApp Store Connect subscription id.

Structured output declared, but exposes no named fields.

No examples provided.

asc_sbp_check ~141

Prove Small Business Program status from the latest subscription sales report (US proceeds/price ratio, about 0.85 SBP vs 0.70 standard; live, read-only). Use when: confirming the 15% commission. Needs a Finance-role key (asc_finance_key_id, asc_finance_key_filepath, asc_vendor_number); a 403 gives a clear error. Returns: {ok, ratio, program, report_date}.

NameTypeReqDescription
days_backinteger–How many days back to search for the latest report (default 7).
report_date––Sales report date YYYY-MM-DD; omit to use the latest available.

Structured output declared, but exposes no named fields.

No examples provided.

asc_submit_for_review ~184

Submit the app to App Store review (live write, ALWAYS needs out-of-band human approval, even with approvals off). Use when: everything else is ready and the human has approved. Without a valid approval_id nothing is submitted. Not for: uploading a TestFlight build (use testflight_ship). Returns: {ok, review_submission_id, detail} or {ok: false, blockers, next}, or an approval_required refusal.

NameTypeReqDescription
app_idstringyesApp Store Connect app id (numeric Apple id, e.g. '1234567890'); for aso_competitor_iap the iTunes trackId.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.

Structured output declared, but exposes no named fields.

No examples provided.

asc_token_check ~88

Verify App Store Connect authentication through the asc CLI with one live read-only call. Use when: before any asc_* tool, to confirm key id, issuer and .p8 work. Not for: listing apps (use asc_list_apps). Returns: {ok, asc: {path, version}, auth_source, key_id, p8, keychain_profiles, note, error?}.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

aso_check_name ~103

Check whether an App Store app name is free, by exact-name collision in iTunes Search. Use when: testing one name before asc_create_app. For several names use aso_find_available_name. Returns: {ok, name, available, conflicts: [...]}.

NameTypeReqDescription
countrystring–Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'.
namestringyesCandidate App Store app name to check.

Structured output declared, but exposes no named fields.

No examples provided.

aso_competitor_iap ~156

Fetch a competitor's subscription/IAP price ladder from its App Store product page. Use when: setting our pricing. app_id is the iTunes trackId from aso_fetch_competitors. Fragile, undocumented source: on failure ok:false and prices null mean unknown, not free. Returns: {ok, prices: [{name, price}] | null} (untrusted_content).

NameTypeReqDescription
app_idstringyesApp Store Connect app id (numeric Apple id, e.g. '1234567890'); for aso_competitor_iap the iTunes trackId.
countrystring–Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'.

Structured output declared, but exposes no named fields.

No examples provided.

aso_complete ~96

Validate the ASO output and mark the 'aso' stage done, opening the metadata/deliver gate. Use when: ASO files are written. Not for: other stages (use pipeline_mark). Returns: {ok, problems?} or a refusal listing what is missing.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

aso_fetch_competitors ~150

Fetch competitor apps for a search term through iTunes Search (live, read-only). Use when: sizing up a niche or getting trackIds for aso_competitor_iap. For a scored go/no-go use aso_niche_score. Returns: {ok, count, apps: [{trackId, name, ratings, price, ...}]} (untrusted_content).

NameTypeReqDescription
countrystring–Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'.
limitinteger–Number of competitor apps to return (default 10).
termstringyesSearch term or seed keyword, e.g. 'habit tracker'.

Structured output declared, but exposes no named fields.

No examples provided.

aso_find_available_name ~108

Pick the first available App Store name from a candidate list. Use when: you have ordered name options; a taken name gets a submission rejected. For one name use aso_check_name. Returns: {ok, name, checked: [...]} or {ok: false} if none is free.

NameTypeReqDescription
candidatesarrayyesOrdered candidate app names.
countrystring–Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'.

Structured output declared, but exposes no named fields.

No examples provided.

aso_niche_score ~183

Score an idea 0-100 from demand, competitor weakness, saturation and monetization, with a go/no-go verdict. Use when: ranking one idea quickly. For the full evidence bundle use idea_evaluate. verdict: GO (>=60), MAYBE (>=40), WEAK, REJECT (median competitor >50k ratings or no demand). Returns: {ok, score, verdict, demand, competitors, ...} (untrusted_content).

NameTypeReqDescription
countrystring–Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'.
genre––App Store category name (e.g. 'photo_video', 'productivity', 'health') or numeric genre id; omit for all/inferred.
termstringyesSearch term or seed keyword, e.g. 'habit tracker'.

Structured output declared, but exposes no named fields.

No examples provided.

aso_run ~80

Start the mandatory ASO stage: create the outputs skeleton and return the skill instructions. Use when: the pipeline reaches ASO. Finish with aso_complete. Returns: {ok, outputs_dir, instructions}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

aso_scaffold_outputs ~118

Create the outputs/<App>/ ASO skeleton including apple-metadata.md in 32 languages. Use when: standalone ASO work. Inside the pipeline use aso_run, which also returns the skill instructions. Returns: {ok, dir, files}.

NameTypeReqDescription
app_namestringyesApp name; creates outputs/<app_name>/.
base_dirstringyesDirectory that contains (or will contain) the outputs/<App>/ folder.
locales––Locale codes for the metadata skeleton; omit for the 32 default languages.

Structured output declared, but exposes no named fields.

No examples provided.

aso_search_hints ~157

Query App Store autocomplete for real search demand; the idea-stage hard gate (0 suggestions for a real term = no demand, reject). Use when: validating an idea or expanding keywords (expand=true appends a-z). An endpoint error returns ok:false, never an empty list. Returns: {ok, term, suggestions: [...], count} (untrusted_content).

NameTypeReqDescription
countrystring–Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'.
expandboolean–If true, append a-z to the seed to collect the full keyword universe; default false.
termstringyesSearch term or seed keyword, e.g. 'habit tracker'.

Structured output declared, but exposes no named fields.

No examples provided.

aso_top_grossing ~157

List the top-grossing apps of a storefront and optional category as a revenue proxy. Use when: hunting proven ideas in one category. To sweep all categories and storefronts use idea_harvest. An unknown genre returns ok:false, never the overall chart. Returns: {ok, apps: [...]} (untrusted_content).

NameTypeReqDescription
countrystring–Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'.
genre––App Store category name (e.g. 'photo_video', 'productivity', 'health') or numeric genre id; omit for all/inferred.
limitinteger–Number of chart entries to return (default 25).

Structured output declared, but exposes no named fields.

No examples provided.

aso_unit_economics ~228

Compute margin, break-even and warnings from prices, credits and AI cost (pure calculation, no network). Use when: idea/scaffold stage pricing decisions. Not for: measured-cost economics for a built app (use pricing_unit_economics). apple_cut is 0.15 for Small Business, else 0.30. Returns: {ok, weekly, yearly, margins, break_even, warnings}.

NameTypeReqDescription
ai_cost_per_creditnumber–AI provider cost per credit in USD (default 0.003).
apple_cutnumber–Apple's commission as a fraction: 0.15 (Small Business Program, default) or 0.30.
weekly_creditsinteger–Credits per week on the weekly plan (default 10).
weekly_pricenumber–Weekly subscription price in USD (default 7.99).
yearly_monthly_creditsinteger–Credits per month on the yearly plan (default 15).
yearly_pricenumber–Yearly subscription price in USD (default 49.99).

Structured output declared, but exposes no named fields.

No examples provided.

aso_validate_metadata ~116

Validate outputs/<App>/02-metadata/apple-metadata.md (fields and character limits). Use when: checking ASO output by app name and base dir. For an arbitrary file use metadata_check; to mark the stage done use aso_complete. Returns: {ok, problems: [...]}.

NameTypeReqDescription
app_namestringyesApp name whose outputs/<app_name>/02-metadata/apple-metadata.md is validated.
base_dirstringyesDirectory that contains (or will contain) the outputs/<App>/ folder.

Structured output declared, but exposes no named fields.

No examples provided.

backend_deploy ~222

Deploy the spec's Supabase backend: migrations, secrets, auth, legal build and edge functions (live unless dry_run; needs human approval). Use when: after backend_render. dry_run=true (default) returns the plan without any call. Not for: single SQL (supabase_run_sql) or one secret (supabase_set_secret). Returns: {ok, plan/steps, dry_run} or an approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
dry_runboolean–If true (default) nothing is changed or sent and the exact plan/command is returned; false performs the live action.
project_refstringyesSupabase project ref to deploy to.

Structured output declared, but exposes no named fields.

No examples provided.

backend_render ~107

Render the scaffolded backend from app.spec.json (offline, idempotent): prune supabase/ to the monetization mode, generate shared config, legal sources and listing locales. Use when: after editing the spec, before backend_deploy. Nothing is deployed. Returns: {ok, mode, render, legal, listing?}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

build_archive ~152

Run xcodebuild archive (generic iOS device) to produce a .xcarchive. Use when: manual signing pipeline steps. For the whole signed TestFlight flow use testflight_ship. Returns: {ok, exit_code, stdout, stderr} from xcodebuild.

NameTypeReqDescription
archive_pathstringyesPath to the .xcarchive, e.g. build/App.xcarchive.
configurationstring–Xcode build configuration, default 'Release'.
projectstringyesPath to the .xcodeproj or .xcworkspace to build, e.g. /path/App/App.xcodeproj.
schemestringyesXcode scheme name to build, e.g. 'MyApp'.

Structured output declared, but exposes no named fields.

No examples provided.

build_boot_sim ~93

Boot an iOS simulator and open Simulator.app. Use when: before capturing screenshots or running maestro_test. Idempotent if already booted. Returns: {ok, exit_code, stdout, stderr}, or {ok, note: 'already booted'}.

NameTypeReqDescription
udidstringyesSimulator UDID from build_list_simulators, e.g. 'A1B2C3D4-...'.

Structured output declared, but exposes no named fields.

No examples provided.

build_export_ipa ~130

Run xcodebuild -exportArchive to turn a .xcarchive into an .ipa. Use when: after build_archive with an ExportOptions.plist. For the whole flow use testflight_ship. Returns: {ok, exit_code, stdout, stderr} from xcodebuild.

NameTypeReqDescription
archive_pathstringyesPath to the .xcarchive, e.g. build/App.xcarchive.
export_dirstringyesDirectory to write the exported .ipa into.
export_options_pliststringyesPath to the ExportOptions.plist for xcodebuild -exportArchive.

Structured output declared, but exposes no named fields.

No examples provided.

build_for_sim ~134

Build the Xcode project for the simulator to verify it compiles. Use when: verifying code changes. Not for: signed/release builds (use build_archive or testflight_ship). Returns: {ok, exit_code, stdout, stderr} from xcodebuild.

NameTypeReqDescription
device_namestring–Simulator device name, e.g. 'iPhone 16'.
projectstringyesPath to the .xcodeproj or .xcworkspace to build, e.g. /path/App/App.xcodeproj.
schemestringyesXcode scheme name to build, e.g. 'MyApp'.

Structured output declared, but exposes no named fields.

No examples provided.

build_list_simulators ~64

List the available iOS simulators, iPhones first. Use when: you need a udid for build_boot_sim, build_screenshot or screenshot_capture. Returns: {ok, count, simulators: [{name, udid, state, runtime}]}.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

build_screenshot ~101

Capture a PNG screenshot of the booted simulator to out_path. Use when: an ad-hoc check. For localized store screenshots use screenshot_capture / screenshot_build_all. Returns: {ok, exit_code, stdout, stderr, path}.

NameTypeReqDescription
out_pathstringyesOutput file path (PNG).
udidstringyesSimulator UDID from build_list_simulators, e.g. 'A1B2C3D4-...'.

Structured output declared, but exposes no named fields.

No examples provided.

build_test ~126

Run xcodebuild test for the scheme on a simulator. Use when: running unit/UI tests. For end-to-end Maestro flows use maestro_test. Returns: {ok, exit_code, stdout, stderr} from xcodebuild.

NameTypeReqDescription
device_namestring–Simulator device name, e.g. 'iPhone 16'.
projectstringyesPath to the .xcodeproj or .xcworkspace to build, e.g. /path/App/App.xcodeproj.
schemestringyesXcode scheme name to build, e.g. 'MyApp'.

Structured output declared, but exposes no named fields.

No examples provided.

build_xcode_version ~52

Return the installed Xcode version. Use when: a quick check that xcodebuild works before build_* tools. Returns: {ok, exit_code, stdout, stderr} (stdout holds the version lines).

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

config_doctor ~97

Report which config keys in ~/.appfactory/config.toml are present or missing (secrets masked). Use when: diagnosing ASC/Finance key paths, session state or CLI availability. Not for: overall setup guidance (use setup_status) or toolchain checks (use env_doctor). Returns: {ok, config_path, present, missing, locales, asc_p8_resolved, session, asc_cli, maestro, notes}.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

config_set ~299

Write several NON-secret settings (ASC key id/issuer/path, team id, copyright, support email, ...) to ~/.appfactory/config.toml. Use when: setting multiple ASC/identity fields together; fields left empty are unchanged. Not for: secrets (use setup_credentials) or one key (use setup_set). Returns: the config_doctor result after the update, or {ok: false, error} if a secret key was passed.

NameTypeReqDescription
apple_id––Apple ID email of the developer account (used by fastlane produce only).
asc_finance_key_filepath––Path to the Finance-role .p8 key file.
asc_finance_key_id––Key id of a Finance-role App Store Connect API key (for sales reports).
asc_issuer_id––App Store Connect API issuer id (UUID).
asc_key_filepath––Path to the App Store Connect .p8 private key file.
asc_key_id––App Store Connect API key id (10 characters).
asc_vendor_number––App Store Connect vendor number (sales reports).
copyright––Copyright line for the store listing, e.g. '2026 Example Ltd'; falls back to the config 'copyright' key.
legal_controller––Legal entity name shown as data controller in the privacy policy.
support_email––Public support email address.
team_id––Apple Developer Team id (10 characters).

Structured output declared, but exposes no named fields.

No examples provided.

cpp_build_all ~177

Create one Custom Product Page per Search Ads theme (page, version, localization) and return the deep-link URLs (live write, needs human approval). Use when: after ASO produced theme clusters; the URLs feed Ad Ops. Returns: {ok, pages: [{theme, ok, id, version_id, localization_id, url}]} or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.
themesarrayyesList of {name, locale} Search Ads themes, one Custom Product Page each.

Structured output declared, but exposes no named fields.

No examples provided.

deliver_metadata ~182

Upload metadata to the App Store Connect draft version through the API (live write, needs human approval, ASO-gated). Use when: metadata files are exported (metadata_export). Not for: screenshots (deliver_screenshots) or the submit step (asc_submit_for_review). Returns: {ok, uploaded: [...]} or a gate / approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.

Structured output declared, but exposes no named fields.

No examples provided.

deliver_screenshots ~180

Upload screenshots to the App Store Connect draft with checksum-based incremental sync (live write, needs human approval). Use when: screenshot_build_all is done; unchanged files (MD5 match) are skipped. To verify afterwards use deliver_screenshots_audit. Returns: {ok, uploaded, skipped} or a gate / approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.

Structured output declared, but exposes no named fields.

No examples provided.

deliver_screenshots_audit ~128

Read-only audit that App Store Connect screenshot sets exactly match the local fastlane/screenshots files (order, COMPLETE state, MD5). Use when: after deliver_screenshots and before submission. No writes. Returns: {ok, locales: {locale: {display_type: status}}, previews, problems}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.

Structured output declared, but exposes no named fields.

No examples provided.

Common questions

What is the io.github.gbatistuta0/appfactory MCP server?

io.github.gbatistuta0/appfactory is an MCP server listed in the public MCP registry as io.github.gbatistuta0/appfactory. Lets your coding agent ship a SwiftUI iOS subscription app from idea to TestFlight. This page covers its PyPI package (appfactory).

Is the io.github.gbatistuta0/appfactory MCP server safe to use?

io.github.gbatistuta0/appfactory scores 75 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.gbatistuta0/appfactory MCP server expose?

io.github.gbatistuta0/appfactory exposes 125 tools: setup_status, setup_services, setup_set, setup_approvals, setup_credentials, and 120 more. Their descriptions and schemas cost roughly 18,907 tokens of context every time the server is loaded.

Is the io.github.gbatistuta0/appfactory MCP server still maintained?

io.github.gbatistuta0/appfactory is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the io.github.gbatistuta0/appfactory MCP server under?

io.github.gbatistuta0/appfactory declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.