Claude Code · App Store Connect

Get App Privacy, age rating and compliance right with Claude Code

Your privacy manifests already say what the app and its SDKs collect. Claude Code reads them, MetaRun turns them into the exact App Privacy answers App Store Connect asks for, and the age rating questionnaire and export compliance go through previews.

Setup checked October 2026 against Claude Code MCP docs, permissions

01 · Uplink

Connect Claude Code once

01 · Add the server

Run it in any terminal. --scope user makes MetaRun available in every project; leave it out to limit it to the current one.

claude mcp add --transport http --scope user metarun https://metarun.dev/api/mcp

02 · Sign in

In a Claude Code session, run /mcp, choose metarun and authenticate. MetaRun opens in your browser, where you pick read-only or read and change. From a plain shell, claude mcp login metarun does the same.

/mcp

03 · Optional: add the skills too

The MetaRun plug-in bundles the same server with six mission skills (release handoff, worldwide pricing, localization, review inbox, ASO audit, store media).

claude plugin marketplace add metarun/metarun-skills
claude plugin install metarun-skills@metarun
Prefer a personal access token (scripts, CI)?

Add the server with a token

Mint a personal access token in MetaRun under Settings, MCP. It's shown once and can be revoked any time.

claude mcp add --transport http --scope user metarun https://metarun.dev/api/mcp \
  --header "Authorization: Bearer $METARUN_TOKEN"

Or share it with your team in .mcp.json

Project scope writes .mcp.json at the repo root. Claude Code expands ${METARUN_TOKEN} from each person's environment, so the token itself is never committed.

{
  "mcpServers": {
    "metarun": {
      "type": "http",
      "url": "https://metarun.dev/api/mcp",
      "headers": { "Authorization": "Bearer ${METARUN_TOKEN}" }
    }
  }
}
02 · Briefing

What Claude Code handles here

App Privacy is the questionnaire behind your App Store privacy label: 35 data types, six purposes, linked or not, tracking or not, for your code and every SDK you ship. Getting it wrong is a common rejection, and Apple's API can't read or write it.

A coding agent has the input App Privacy needs: your PrivacyInfo.xcprivacy and the ones inside each Swift package or pod. MetaRun maps them one to one onto App Store Connect's answers and flags what App Review rejects. The age rating and export compliance do have an API, and go through previews.

03 · Preflight

Before you start

  • Your app's PrivacyInfo.xcprivacy and each SDK's.
  • Access to App Store Connect in a browser, to enter the App Privacy answers.
  • The age rating questionnaire's facts: user content, web access, purchases.
04 · Execution

How it runs

  1. 01

    Collect the manifests

    Claude Code finds your app's PrivacyInfo.xcprivacy and each SDK's: Swift packages under DerivedData's SourcePackages checkouts, CocoaPods under Pods.

  2. 02

    Build the answers

    MetaRun merges them strictest-wins and returns every data type to tick, whether it's linked to the user or used for tracking, its purposes, and how the label will read.

  3. 03

    Fix what review would reject

    Findings name the problems App Review flags: unknown keys, a data type with no purpose, tracking declared with nothing marked for tracking, missing tracking domains.

  4. 04

    Enter and publish

    Because App Privacy has no API, you enter the answers in App Store Connect; MetaRun returns the steps and a link to the right page. Age rating and compliance apply through previews.

05 · Session

An example session in Claude Code

Find every PrivacyInfo.xcprivacy in this repo and in DerivedData's SourcePackages, build our App Privacy answers, and list anything App Review would reject.

  1. apple_build_privacy_answersAnswers built from four manifests, with one finding: an SDK declares tracking without a tracking domain.
  2. apple_get_age_rating_declarationThree age rating questions were never answered.
  3. apple_preview_set_age_ratingPreview: your answers plus the three unanswered questions, listed so you can see them.
  4. Claude Code asks before running apple_apply_set_age_rating. You read the preview above and approve.
  5. apple_apply_set_age_ratingApplied. Apple derives the rating from the answers.

Illustrative: your apps, versions and numbers will differ. The tool names and their order are real.

06 · Tools

The MetaRun tools Claude Code calls

ToolWhat it does
apple_build_privacy_answersreadTurns PrivacyInfo.xcprivacy files into App Privacy answers, with findings App Review rejects.
apple_get_age_rating_declarationreadThe age rating questionnaire as answered now.
apple_preview_set_age_ratingpreview + applyAnswer or change the questionnaire, and overrides.
apple_list_encryption_declarationsreadExisting export compliance declarations.
apple_preview_declare_build_encryptionpreview + applyAnswer export compliance for a build.
apple_preview_set_content_rightspreview + applyDeclare whether the app uses third-party content.
apple_list_accessibility_declarationsreadAccessibility Nutrition Labels per device family.
apple_preview_set_accessibility_declarationpreview + applyDeclare which accessibility features the app supports.

Each preview has an apply twin (the same name with apply instead of preview) that only runs with the confirm token from a fresh preview, and refuses if App Store Connect changed in between. MetaRun tools save to your MetaRun workspace only (studio projects, tracked keywords), never to Apple.

07 · Apple rules

What Apple enforces, and how MetaRun handles it

App Privacy has no API

There's no App Store Connect API endpoint for App Privacy at all. MetaRun builds the answers and the label; publishing them is done in App Store Connect.

Unanswered isn't the same as No

Apple stores an unanswered age rating question as empty, not No. An override sent on an empty questionnaire comes back as a server error, so MetaRun stages every unanswered question alongside your edits and lists them for you to see.

Korea's override needs the right category

Apple only accepts a Korea age rating override for apps in the Games or Entertainment category. The preview warns before the attempt instead of letting Apple refuse it.

Compliance declarations are permanent

An export compliance declaration can't be withdrawn once assigned to a build. Setting ITSAppUsesNonExemptEncryption in Info.plist avoids the question for future builds.

08 · Comms

What to ask Claude Code

  • Ask Claude Code: Find every PrivacyInfo.xcprivacy in this repo and in DerivedData's SourcePackages, build our App Privacy answers, and list anything App Review would reject.
  • Ask Claude Code: Our analytics SDK isn't declaring a tracking domain. Check its manifest and tell me what the label will say.
  • Ask Claude Code: Walk me through the age rating questionnaire for com.example.app and stage the answers.
09 · Unattended

Run it from a script with Claude Code

claude -p runs one request with no interactive session. The browser sign-in can't complete inside -p, so sign in once interactively first, or configure the server with a personal access token in CI. Tools missing from --allowedTools are refused in -p mode.

Read-only check, safe to schedule

claude -p "Build the App Privacy answers from the PrivacyInfo.xcprivacy files in this repository and list every finding App Review would reject. Read only." \
  --allowedTools "mcp__metarun__apple_build_privacy_answers,mcp__metarun__apple_get_age_rating_declaration,mcp__metarun__apple_preview_set_age_rating,mcp__metarun__apple_list_encryption_declarations,mcp__metarun__apple_preview_declare_build_encryption,mcp__metarun__apple_preview_set_content_rights,mcp__metarun__apple_list_accessibility_declarations,mcp__metarun__apple_preview_set_accessibility_declaration"

Only reads and previews are on that list, so nothing can reach App Store Connect unattended. Run applies in an interactive session where Claude Code can ask you.

10 · Safety

How Claude Code asks before a change

Claude Code asks before every MCP tool call by default. You can allow a tool for the session or permanently; allow rules look like mcp__metarun__apple_list_versions for one tool, and mcp__metarun__* allows the whole server, applies included. Allowing reads and previews is reasonable. Leave the apply tools on ask: that prompt is the confirm step for every App Store change.

Apple key stays on MetaRun, encryptedPreview before every writeRecorded, revertible from history
11 · FAQ

Frequently asked questions

Can Claude Code fill in App Privacy for me?

It can do all the thinking: Claude Code reads the manifests and MetaRun produces the exact answers and the label. The last step, entering them in App Store Connect, is manual because Apple offers no API for App Privacy.

Which manifests should it read?

Your app's own PrivacyInfo.xcprivacy and every SDK's: Swift packages under DerivedData/<project>/SourcePackages/checkouts, CocoaPods under Pods. App Privacy covers everything the app links.

Can it set the age rating?

Yes. The questionnaire has an API, so Claude Code reads it, stages your answers through a preview, and applies on your approval.

What about export compliance?

Per build, via apple_preview_declare_build_encryption. It's permanent for that build, so the preview says so before you approve.

How do I connect Claude Code to App Store Connect?

Run claude mcp add --transport http --scope user metarun https://metarun.dev/api/mcp, then run /mcp in Claude Code and sign in to MetaRun in your browser. After that, ask for "app privacy and compliance" in plain words and Claude Code picks the MetaRun tools.

Does Claude Code see my App Store Connect key?

No. Your App Store Connect API key stays envelope-encrypted on MetaRun's servers and is decrypted per request. Claude Code holds a MetaRun token that you can revoke in Settings at any time.

More with Claude Code

In depth: App Store Connect MCP server

Agent access

14-day free trial with agent access. No credit card. Your Apple key stays encrypted on MetaRun.