Codex · App Store Connect

Read and reply to App Store reviews from Codex

Ask Codex what users are complaining about this week. MetaRun pulls the reviews, finds the recurring themes, and every reply Codex drafts is shown to you before it's posted under your app.

Setup checked October 2026 against Codex MCP docs, non-interactive mode

01 · Uplink

Connect Codex once

01 · Add the server

Codex sees that MetaRun offers sign-in and starts it straight away, in your browser. Pick read-only or read and change.

codex mcp add metarun --url https://metarun.dev/api/mcp

02 · Sign in again later

If the sign-in expires or you disconnected it in MetaRun's settings. --no-browser prints the link instead, for SSH sessions.

codex mcp login metarun

03 · Or edit ~/.codex/config.toml

The Codex CLI, the IDE extension and Codex in the ChatGPT desktop app read the same file, so one entry covers all three.

[mcp_servers.metarun]
url = "https://metarun.dev/api/mcp"
Prefer a personal access token (scripts, CI)?

Add the server with a token

Mint a personal access token in MetaRun under Settings, MCP. It's shown once and can be revoked any time. Codex reads it from the environment variable you name.

export METARUN_TOKEN="mr_pat_..."
codex mcp add metarun --url https://metarun.dev/api/mcp --bearer-token-env-var METARUN_TOKEN

Or in config.toml

[mcp_servers.metarun]
url = "https://metarun.dev/api/mcp"
bearer_token_env_var = "METARUN_TOKEN"
02 · Briefing

What Codex handles here

Reviews arrive per storefront, in every language, and App Store Connect shows them one at a time. Answering the ones that matter (the bug report with one star, the feature request that keeps coming back) gets pushed to someday.

For a coding agent this is useful in a second way: the complaint and the code are in the same session. Codex can read a review about a crash, look at the code path, and draft a reply that says the fix is in 2.4.1.

03 · Preflight

Before you start

  • An API key with the Admin or Customer Support role, to reply.
  • A decision on tone, and on what you're willing to promise in public.
  • For crash complaints: the code or crash logs to check against.
04 · Execution

How it runs

  1. 01

    Pull and sort

    Codex reads recent reviews and sorts them by what needs an answer: low ratings with specific complaints first.

  2. 02

    Find the themes

    aso_mine_reviews groups complaints and praise without an extra model call, and lists words users use that your listing doesn't.

  3. 03

    Draft replies

    The agent drafts. Each reply is a preview showing the review and the exact text that will appear under it.

  4. 04

    Post on approval

    The apply posts the reply. It's public as soon as Apple processes it, so this is the step to read carefully.

05 · Session

An example session in Codex

Pull this week's 1- and 2-star reviews for com.example.app and group them by complaint.

  1. apple_list_reviewsThis week's reviews, lowest rating first.
  2. aso_mine_reviewsTop complaint theme: sync on iPad. Top praise: the widget.
  3. apple_preview_respond_to_reviewPreview: the reply, exactly as it will appear under the review.
  4. Codex asks before running apple_apply_respond_to_review. You read the preview above and approve.
  5. apple_apply_respond_to_reviewPosted. Public once Apple processes it.

Illustrative: your apps, versions and numbers will differ. The tool names and their order are real.

06 · Tools

The MetaRun tools Codex calls

ToolWhat it does
apple_list_reviewsreadCustomer reviews with rating, territory, text and any existing reply.
apple_get_review_summaryreadApple's AI summary of your reviews, the one shown on the product page.
aso_mine_reviewsreadPraise and complaint themes, plus keywords users use that your listing doesn't.
aso_get_territory_ratingsreadStar ratings per storefront and the worldwide average.
apple_preview_respond_to_reviewpreview + applyPreview a public reply, or an edit to an existing one.
apple_preview_delete_review_responsepreview + applyRemove a reply.

Each preview has an apply twin (the same name with apply instead of preview) that only runs with the confirm token from a fresh preview, and refuses if App Store Connect changed in between. MetaRun tools save to your MetaRun workspace only (studio projects, tracked keywords), never to Apple.

07 · Apple rules

What Apple enforces, and how MetaRun handles it

Replies are public

A developer response appears under the review on the App Store. Each review has one response; replying again replaces it.

The key needs the right role

Responding needs an App Store Connect API key with the Admin or Customer Support role. A key with a narrower role reads reviews but can't reply.

Ratings without text can't be answered

Only written reviews take a response. Star-only ratings show up in averages, not in the review list.

No ratings endpoint in the API

Apple's API has no per-storefront ratings call. MetaRun reads ratings from the public store lookup instead, so the numbers match what shoppers see.

08 · Comms

What to ask Codex

  • Ask Codex: Pull this week's 1- and 2-star reviews for com.example.app and group them by complaint.
  • Ask Codex: Three people say sync loses data on iPad. Find where that could happen in Sources/Sync, then draft replies saying the fix ships in 2.4.1.
  • Ask Codex: Reply to the five most helpful reviews this month. Show me every reply before posting.
09 · Unattended

Run it from a script with Codex

codex exec runs one request without an interactive session and with its approval policy set to never. MetaRun's reads and previews still run, because they're marked read-only; anything that would ask is refused.

Read-only check, safe to schedule

codex exec "Summarize the last 7 days of reviews for com.example.app: count by rating, the top three complaint themes, and reviews with no reply. Read only."

Applies are refused in codex exec by design. Don't set MetaRun's approval mode to approve just to make them pass; keep App Store changes in an interactive session.

10 · Safety

How Codex asks before a change

Codex decides per tool from the hints MetaRun sends with each one. In its default mode it runs tools marked read-only, which covers MetaRun's reads and previews, and asks before the rest, which covers every apply. You can change that per server with default_tools_approval_mode, or per tool with tools.<name>.approval_mode in config.toml; keep the apply tools on prompt.

Apple key stays on MetaRun, encryptedPreview before every writeRecorded, revertible from history
11 · FAQ

Frequently asked questions

Will Codex post replies on its own?

No. Each reply is a preview first and the apply needs your approval in Codex. Replies are public, so this is one to keep on ask.

Can it reply in the reviewer's language?

Yes. Codex writes the reply; MetaRun posts it under the review in whatever language you approved.

Can I edit or delete a reply later?

Yes. Replying again replaces the existing response, and apple_preview_delete_review_response removes it.

Why can't it see some ratings?

Star-only ratings have no text and no reply option. They count in your averages, which aso_get_territory_ratings reports per storefront.

How do I connect Codex to App Store Connect?

Run codex mcp add metarun --url https://metarun.dev/api/mcp; Codex detects MetaRun's sign-in and opens it in your browser. After that, ask for "reply to reviews" in plain words and Codex picks the MetaRun tools.

Does Codex see my App Store Connect key?

No. Your App Store Connect API key stays envelope-encrypted on MetaRun's servers and is decrypted per request. Codex holds a MetaRun token that you can revoke in Settings at any time.

More with Codex

In depth: ASO rank tracking

Agent access

14-day free trial with agent access. No credit card. Your Apple key stays encrypted on MetaRun.