Codex · App Store Connect

Submit your app for App Review from Codex

Your build finished processing. Ask Codex to ship it: MetaRun attaches the build to the version, checks every field App Review will look at, and shows the submission before anything is sent. Resubmitting after a rejection goes through the same submission, the way App Store Connect does it.

Setup checked October 2026 against Codex MCP docs, non-interactive mode

01 · Uplink

Connect Codex once

01 · Add the server

Codex sees that MetaRun offers sign-in and starts it straight away, in your browser. Pick read-only or read and change.

codex mcp add metarun --url https://metarun.dev/api/mcp

02 · Sign in again later

If the sign-in expires or you disconnected it in MetaRun's settings. --no-browser prints the link instead, for SSH sessions.

codex mcp login metarun

03 · Or edit ~/.codex/config.toml

The Codex CLI, the IDE extension and Codex in the ChatGPT desktop app read the same file, so one entry covers all three.

[mcp_servers.metarun]
url = "https://metarun.dev/api/mcp"
Prefer a personal access token (scripts, CI)?

Add the server with a token

Mint a personal access token in MetaRun under Settings, MCP. It's shown once and can be revoked any time. Codex reads it from the environment variable you name.

export METARUN_TOKEN="mr_pat_..."
codex mcp add metarun --url https://metarun.dev/api/mcp --bearer-token-env-var METARUN_TOKEN

Or in config.toml

[mcp_servers.metarun]
url = "https://metarun.dev/api/mcp"
bearer_token_env_var = "METARUN_TOKEN"
02 · Briefing

What Codex handles here

Submitting by hand is six screens in App Store Connect: pick the build, answer the encryption question, fill in review contact and demo account details, check that every language has its screenshots and description, press Add for Review, then Submit. Miss one field and the button stays grey with no reason given.

Through MetaRun the agent does the same steps as tool calls. The readiness sweep reads the version, the build, the listing in every language and the review details, and returns one list of blockers before any write. Fix those, preview the submission, approve it, and it is in Apple's queue.

03 · Preflight

Before you start

  • A version in Prepare for Submission. If there isn't one, apple_preview_create_version makes it.
  • A processed build for that version, uploaded from Xcode, Xcode Cloud, fastlane or your CI.
  • An App Store Connect API key in MetaRun with the Admin or App Manager role.
04 · Execution

How it runs

  1. 01

    Find the version and the build

    Codex lists the app's versions and builds, picks the processed build that matches the version you named, and previews attaching it. A build still processing is reported as such, not attached.

  2. 02

    Clear what App Review will ask

    If the build has no export compliance answer, the agent previews one. If review contact details or the demo account are missing, it previews those too. Each is its own change with its own before and after.

  3. 03

    Run the readiness sweep

    The submit preview reads the version, every language's description and screenshots, What's New on an update, the review details and any submission already in flight. Blockers come back as a list with the tool that fixes each one.

  4. 04

    Submit with an explicit acknowledge

    The apply takes the preview's confirm token plus acknowledge set to true. If anything changed on Apple's side since the preview, the token no longer matches and nothing is sent.

05 · Session

An example session in Codex

The 2.4 build just finished uploading. Attach it to version 2.4 of com.example.app, sort out export compliance, and tell me what still blocks submission.

  1. apple_list_versionsVersion 2.4 is in Prepare for Submission.
  2. apple_list_buildsBuild 312 finished processing a few minutes ago.
  3. apple_preview_set_version_buildPreview: attach build 312 to version 2.4.
  4. Codex asks before running apple_apply_set_version_build. You read the preview above and approve.
  5. apple_apply_set_version_buildAttached. Recorded in change history.
  6. apple_preview_submit_for_reviewSweep: no blockers. One note: App Privacy answers are entered in App Store Connect.
  7. Codex asks before running apple_apply_submit_for_review. You read the preview above and approve.
  8. apple_apply_submit_for_reviewSubmitted with acknowledge set to true. Version 2.4 is Waiting for Review.

Illustrative: your apps, versions and numbers will differ. The tool names and their order are real.

06 · Tools

The MetaRun tools Codex calls

ToolWhat it does
apple_get_listing_editabilityreadWhich parts of the listing are locked right now, and why.
apple_list_buildsreadProcessed builds for the app, newest first, with their processing state.
apple_preview_set_version_buildpreview + applyAttach a processed build to the version. Required before submitting.
apple_preview_declare_build_encryptionpreview + applyAnswer export compliance for the build, or reuse an existing declaration.
apple_preview_set_review_detailpreview + applyContact details, demo account and notes for the App Review team.
apple_preview_submit_for_reviewpreview + applyRuns the readiness sweep and previews the submission. Needs an explicit acknowledge to apply.
apple_list_review_submissionsreadEvery submission with its state, each item's verdict and who submitted it.
apple_preview_cancel_review_submissionpreview + applyWithdraw a submission from Apple's queue, naming exactly which one.

Each preview has an apply twin (the same name with apply instead of preview) that only runs with the confirm token from a fresh preview, and refuses if App Store Connect changed in between. MetaRun tools save to your MetaRun workspace only (studio projects, tracked keywords), never to Apple.

07 · Apple rules

What Apple enforces, and how MetaRun handles it

One submission at a time per platform

Apple lets one app-version submission wait for or sit in review per platform. The sweep blocks a second instead of letting Apple refuse it halfway through.

A rejection resubmits through its own submission

After a rejection Apple keeps the version inside the rejected submission and refuses to add it to a new one. MetaRun marks the item resolved and resubmits that same submission, which is what the Resubmit button in App Store Connect does. Verified against a live app on 11 September 2026: same submission id, item moved from Rejected to Ready for Review.

App Privacy has no API

Apple's App Store Connect API cannot read or write App Privacy answers. On a first submission the sweep warns about it rather than blocking, and apple_build_privacy_answers turns your PrivacyInfo.xcprivacy files into the exact answers to enter by hand.

App Review's message is not in the API either

The rejection reason, the guideline cited and any attachments only exist in App Store Connect. MetaRun returns a direct link to that page and the agent is told not to guess the reason.

What's New only exists after the first release

A first version has no What's New field and the API rejects one. The sweep only requires it on an update.

08 · Comms

What to ask Codex

  • Ask Codex: The 2.4 build just finished uploading. Attach it to version 2.4 of com.example.app, sort out export compliance, and tell me what still blocks submission.
  • Ask Codex: Use the review notes in docs/review-notes.md for the App Review details, then preview submitting 2.4.
  • Ask Codex: We got rejected. Show me the submission state and the link to Apple's message, then resubmit once I've replied.
09 · Unattended

Run it from a script with Codex

codex exec runs one request without an interactive session and with its approval policy set to never. MetaRun's reads and previews still run, because they're marked read-only; anything that would ask is refused.

Read-only check, safe to schedule

codex exec "Check whether version 2.4 of com.example.app is ready to submit for review and list every blocker. Read and preview only; do not apply anything."

Applies are refused in codex exec by design. Don't set MetaRun's approval mode to approve just to make them pass; keep App Store changes in an interactive session.

10 · Safety

How Codex asks before a change

Codex decides per tool from the hints MetaRun sends with each one. In its default mode it runs tools marked read-only, which covers MetaRun's reads and previews, and asks before the rest, which covers every apply. You can change that per server with default_tools_approval_mode, or per tool with tools.<name>.approval_mode in config.toml; keep the apply tools on prompt.

Apple key stays on MetaRun, encryptedPreview before every writeRecorded, revertible from history
11 · FAQ

Frequently asked questions

Can Codex submit my app for review without asking me?

Not through MetaRun's contract. The submit apply needs a confirm token from a fresh preview plus an explicit acknowledge, and Codex asks you before it runs the tool unless you have pre-approved that exact tool. Pre-approve reads and previews if you like; keep applies on ask.

What does the readiness sweep check?

The attached build and its processing state, export compliance, review contact and demo account, every language's description, keywords and screenshots, What's New on an update, and whether another submission is already waiting or in review on the same platform.

Does MetaRun upload the build?

No. Xcode, Xcode Cloud, fastlane or any CI uploads the build to App Store Connect as usual. MetaRun picks up from there: attach, answer compliance, submit.

What happens after a rejection?

Ask Codex for the submission state. You get each item's verdict and a link to App Review's message in App Store Connect, since that message has no API. Once you've fixed and replied, the agent resubmits the same submission.

How do I connect Codex to App Store Connect?

Run codex mcp add metarun --url https://metarun.dev/api/mcp; Codex detects MetaRun's sign-in and opens it in your browser. After that, ask for "submit for review" in plain words and Codex picks the MetaRun tools.

Does Codex see my App Store Connect key?

No. Your App Store Connect API key stays envelope-encrypted on MetaRun's servers and is decrypted per request. Codex holds a MetaRun token that you can revoke in Settings at any time.

More with Codex

In depth: App Store Connect MCP server

Agent access

14-day free trial with agent access. No credit card. Your Apple key stays encrypted on MetaRun.