Submit your app for App Review from Cursor
Your build finished processing. Ask Cursor to ship it: MetaRun attaches the build to the version, checks every field App Review will look at, and shows the submission before anything is sent. Resubmitting after a rejection goes through the same submission, the way App Store Connect does it.
Setup checked October 2026 against Cursor MCP docs, Cursor CLI
Connect Cursor once
01 · Add to ~/.cursor/mcp.json (or .cursor/mcp.json for one project)
{
"mcpServers": {
"metarun": {
"url": "https://metarun.dev/api/mcp"
}
}
}02 · Or use the install link
Opens Cursor with the server filled in.
https://cursor.com/link/mcp/install?name=metarun&config=eyJ1cmwiOiJodHRwczovL21ldGFydW4uZGV2L2FwaS9tY3AifQ%3D%3D03 · Sign in
When Cursor connects, MetaRun opens in your browser. Pick read-only or read and change, and you're back in the editor with the tools listed under MCP.
Prefer a personal access token (scripts, CI)?
Use a token instead
Mint a personal access token in MetaRun under Settings, MCP. It's shown once and can be revoked any time. Cursor reads ${env:METARUN_TOKEN} from your environment. Some Cursor versions start the browser sign-in even when a header is set; if that happens, signing in works the same.
{
"mcpServers": {
"metarun": {
"url": "https://metarun.dev/api/mcp",
"headers": { "Authorization": "Bearer ${env:METARUN_TOKEN}" }
}
}
}What Cursor handles here
Submitting by hand is six screens in App Store Connect: pick the build, answer the encryption question, fill in review contact and demo account details, check that every language has its screenshots and description, press Add for Review, then Submit. Miss one field and the button stays grey with no reason given.
Through MetaRun the agent does the same steps as tool calls. The readiness sweep reads the version, the build, the listing in every language and the review details, and returns one list of blockers before any write. Fix those, preview the submission, approve it, and it is in Apple's queue.
Before you start
- A version in Prepare for Submission. If there isn't one, apple_preview_create_version makes it.
- A processed build for that version, uploaded from Xcode, Xcode Cloud, fastlane or your CI.
- An App Store Connect API key in MetaRun with the Admin or App Manager role.
How it runs
- 01
Find the version and the build
Cursor lists the app's versions and builds, picks the processed build that matches the version you named, and previews attaching it. A build still processing is reported as such, not attached.
- 02
Clear what App Review will ask
If the build has no export compliance answer, the agent previews one. If review contact details or the demo account are missing, it previews those too. Each is its own change with its own before and after.
- 03
Run the readiness sweep
The submit preview reads the version, every language's description and screenshots, What's New on an update, the review details and any submission already in flight. Blockers come back as a list with the tool that fixes each one.
- 04
Submit with an explicit acknowledge
The apply takes the preview's confirm token plus acknowledge set to true. If anything changed on Apple's side since the preview, the token no longer matches and nothing is sent.
An example session in Cursor
Attach the newest processed build to 2.4 and run the readiness check. Don't submit yet.
- apple_list_versionsVersion 2.4 is in Prepare for Submission.
- apple_list_buildsBuild 312 finished processing a few minutes ago.
- apple_preview_set_version_buildPreview: attach build 312 to version 2.4.
- Cursor asks before running apple_apply_set_version_build. You read the preview above and approve.
- apple_apply_set_version_buildAttached. Recorded in change history.
- apple_preview_submit_for_reviewSweep: no blockers. One note: App Privacy answers are entered in App Store Connect.
- Cursor asks before running apple_apply_submit_for_review. You read the preview above and approve.
- apple_apply_submit_for_reviewSubmitted with acknowledge set to true. Version 2.4 is Waiting for Review.
Illustrative: your apps, versions and numbers will differ. The tool names and their order are real.
The MetaRun tools Cursor calls
| Tool | What it does |
|---|---|
| apple_get_listing_editabilityread | Which parts of the listing are locked right now, and why. |
| apple_list_buildsread | Processed builds for the app, newest first, with their processing state. |
| apple_preview_set_version_buildpreview + apply | Attach a processed build to the version. Required before submitting. |
| apple_preview_declare_build_encryptionpreview + apply | Answer export compliance for the build, or reuse an existing declaration. |
| apple_preview_set_review_detailpreview + apply | Contact details, demo account and notes for the App Review team. |
| apple_preview_submit_for_reviewpreview + apply | Runs the readiness sweep and previews the submission. Needs an explicit acknowledge to apply. |
| apple_list_review_submissionsread | Every submission with its state, each item's verdict and who submitted it. |
| apple_preview_cancel_review_submissionpreview + apply | Withdraw a submission from Apple's queue, naming exactly which one. |
Each preview has an apply twin (the same name with apply instead of preview) that only runs with the confirm token from a fresh preview, and refuses if App Store Connect changed in between. MetaRun tools save to your MetaRun workspace only (studio projects, tracked keywords), never to Apple.
What Apple enforces, and how MetaRun handles it
One submission at a time per platform
Apple lets one app-version submission wait for or sit in review per platform. The sweep blocks a second instead of letting Apple refuse it halfway through.
A rejection resubmits through its own submission
After a rejection Apple keeps the version inside the rejected submission and refuses to add it to a new one. MetaRun marks the item resolved and resubmits that same submission, which is what the Resubmit button in App Store Connect does. Verified against a live app on 11 September 2026: same submission id, item moved from Rejected to Ready for Review.
App Privacy has no API
Apple's App Store Connect API cannot read or write App Privacy answers. On a first submission the sweep warns about it rather than blocking, and apple_build_privacy_answers turns your PrivacyInfo.xcprivacy files into the exact answers to enter by hand.
App Review's message is not in the API either
The rejection reason, the guideline cited and any attachments only exist in App Store Connect. MetaRun returns a direct link to that page and the agent is told not to guess the reason.
What's New only exists after the first release
A first version has no What's New field and the API rejects one. The sweep only requires it on an update.
What to ask Cursor
- Ask Cursor: Attach the newest processed build to 2.4 and run the readiness check. Don't submit yet.
- Ask Cursor: Take the demo account from @.env.review and set it as the App Review sign-in for 2.4.
- Ask Cursor: Preview the submission for 2.4 and list anything that would block it.
Run it from a script with Cursor
The Cursor CLI runs one request without the editor with agent -p. Allow only the read tools the request needs in ~/.cursor/cli-config.json (Mcp(metarun:tool_name) rules), and keep MetaRun's apply tools out of that list.
Read-only check, safe to schedule
agent -p "Check whether version 2.4 of com.example.app is ready to submit for review and list every blocker. Read and preview only; do not apply anything." --output-format jsonDon't run it with --force for MetaRun: that approves every tool, applies included.
How Cursor asks before a change
Cursor asks before each MCP tool call by default, following your Run Mode settings. Keep MetaRun's apply tools on ask: that prompt is the confirm step for every App Store change. In the Cursor CLI, allow rules live in ~/.cursor/cli-config.json in the form Mcp(server:tool), so you can allow MetaRun's read tools and leave the applies out.
Frequently asked questions
Can Cursor submit my app for review without asking me?
Not through MetaRun's contract. The submit apply needs a confirm token from a fresh preview plus an explicit acknowledge, and Cursor asks you before it runs the tool unless you have pre-approved that exact tool. Pre-approve reads and previews if you like; keep applies on ask.
What does the readiness sweep check?
The attached build and its processing state, export compliance, review contact and demo account, every language's description, keywords and screenshots, What's New on an update, and whether another submission is already waiting or in review on the same platform.
Does MetaRun upload the build?
No. Xcode, Xcode Cloud, fastlane or any CI uploads the build to App Store Connect as usual. MetaRun picks up from there: attach, answer compliance, submit.
What happens after a rejection?
Ask Cursor for the submission state. You get each item's verdict and a link to App Review's message in App Store Connect, since that message has no API. Once you've fixed and replied, the agent resubmits the same submission.
How do I connect Cursor to App Store Connect?
Add https://metarun.dev/api/mcp to ~/.cursor/mcp.json (or use the install link) and sign in to MetaRun when Cursor opens your browser. After that, ask for "submit for review" in plain words and Cursor picks the MetaRun tools.
Does Cursor see my App Store Connect key?
No. Your App Store Connect API key stays envelope-encrypted on MetaRun's servers and is decrypted per request. Cursor holds a MetaRun token that you can revoke in Settings at any time.
More with Cursor
Cursor
Phased release
Choose how an approved version goes out, then pause, resume or finish a phased rollout.
OpenCursor
Release notes
Write What's New from your changelog and stage it in every language.
OpenCursor
TestFlight
Hand builds to tester groups, write What to Test, and read crash feedback.
OpenCursor
App Privacy and compliance
Turn your privacy manifests into App Privacy answers; set age rating and export compliance.
OpenSubmit for review with another agent
In depth: App Store Connect MCP server
Agent access
14-day free trial with agent access. No credit card. Your Apple key stays encrypted on MetaRun.