Critical-risk tools in Appstoreconnect Mcp
43 of the 278 tools in Appstoreconnect Mcp are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
asc_delete_accessibility_declarationDestructiveDELETE /v1/accessibilityDeclarations/{id} — remove a DRAFT declaration. Published declarations are superseded by publishing a new draft (REPLACED), not deleted.
-
asc_delete_alternative_distribution_domainDestructive⚠️ DELETE /v1/alternativeDistributionDomains/{id} — apps distributed from this domain stop being installable from it. Confirm intent first.
-
asc_delete_alternative_distribution_keyDestructive⚠️ DELETE /v1/alternativeDistributionKeys/{id} — artifacts signed against this key stop validating. Confirm intent first.
-
asc_delete_analytics_report_requestDestructiveDELETE /v1/analyticsReportRequests/{id} — stop report generation for this request and drop access to its report chain. Recreating later starts fresh (ONGOING resumes from creati...
-
asc_delete_app_custom_product_pageDestructiveDELETE an AppCustomProductPage. Removes the page + every version + every localization + every asset set under it. The public CPP URL stops resolving immediately. Apple may refus...
-
asc_delete_app_custom_product_page_localizationDestructiveDELETE an AppCustomProductPageLocalization. Customers in this locale fall back to the parent AppStoreVersionLocalization. Apple may refuse if the parent version is in a frozen s...
-
asc_delete_app_custom_product_page_versionDestructiveDELETE an AppCustomProductPageVersion. Removes every localization + asset set under it. Apple gates this — versions in WAITING_FOR_REVIEW / IN_REVIEW typically cannot be deleted...
-
asc_delete_app_eventDestructiveDELETE an AppEvent. Removes the event + every localization + every asset. Apple may refuse if the event is PUBLISHED or IN_REVIEW.
-
asc_delete_app_event_localizationDestructiveDELETE an AppEventLocalization. Removes the per-locale copy + every event screenshot + video clip under it. Customers in this locale fall back to the event
-
asc_delete_app_event_screenshotDestructiveDELETE an AppEventScreenshot. Removes the asset under its slot; if the slot goes empty Apple may reject the event for review with an asset-missing error.
-
asc_delete_app_event_video_clipDestructiveDELETE an AppEventVideoClip. Removes the video asset; if both screenshot + video slot are emptied, Apple may reject the event for review with an asset-missing error.
-
asc_delete_app_info_localizationDestructiveDELETE an AppInfoLocalization. The locale-specific app-level copy is removed (subtitle, privacy URLs, etc.). Customers in that locale fall back to the default locale
-
asc_delete_app_previewDestructiveDELETE an AppPreview. Removes the video asset + its slot in the set; if all previews are removed the parent localization may need a new upload before submission.
-
asc_delete_app_preview_setDestructiveDELETE an AppPreviewSet. All AppPreview resources under the set are removed as well.
-
asc_delete_app_screenshotDestructiveDELETE an AppScreenshot. Removes the asset + its slot in the set; if the set goes empty the parent localization will need a new upload before the App Store version can be submit...
-
asc_delete_app_screenshot_setDestructiveDELETE an AppScreenshotSet. All AppScreenshot resources under the set are removed as well. Use when retiring a device class for a locale or rebuilding a set from scratch.
-
asc_delete_app_store_versionDestructiveDELETE an App Store version. Allowed only when the version is in an editable state (PREPARE_FOR_SUBMISSION, *_REJECTED, INVALID_BINARY, DEVELOPER_REMOVED_FROM_SALE). The tool pr...
-
asc_delete_app_store_version_localizationDestructiveDELETE an AppStoreVersionLocalization. The locale is removed for this version; users in that locale fall back to the default locale
-
asc_delete_app_store_version_phased_releaseDestructiveDELETE an AppStoreVersionPhasedRelease — cancels the staged rollout and reverts the version to standard immediate release (all users on the next App Store refresh). Apple may re...
-
asc_delete_beta_app_localizationDestructiveDELETE a BetaAppLocalization. The locale-specific copy is removed; testers in that locale fall back to whatever default TestFlight uses. Per-build
-
asc_delete_beta_build_localizationDestructiveDELETE a BetaBuildLocalization. The locale is removed for this build; testers in that locale fall back to whatever default locale TestFlight chooses. Doesn
-
asc_delete_beta_feedback_crash_submissionDestructiveDELETE /v1/betaFeedbackCrashSubmissions/{id}. Permanently removes the crash feedback record (including its crash log) from App Store Connect. Irreversible; the tester is not not...
-
asc_delete_beta_feedback_screenshot_submissionDestructiveDELETE /v1/betaFeedbackScreenshotSubmissions/{id}. Permanently removes the feedback record and its screenshot images from App Store Connect — same as dismissing it in the TestFl...
-
asc_delete_beta_groupDestructiveDELETE a beta group. Apple supports DELETE on this resource (unlike offer codes). All tester + build linkages are removed atomically. Testers themselves are NOT deleted — they r...
-
asc_delete_beta_recruitment_criterionDestructiveDELETE /v1/betaRecruitmentCriteria/{id} — remove the criterion entirely; the public link goes back to accepting ANY device. The beta group and its public link are untouched.
-
asc_delete_beta_testerDestructiveDELETE a beta tester record from the team. All group memberships and build accesses for this tester are removed atomically. The tester loses access to every app + build they had...
-
asc_delete_customer_review_responseDestructiveDELETE /v1/customerReviewResponses/{id} — remove your public reply from the App Store. The review itself is untouched (customer reviews cannot be deleted by developers). Get the...
-
asc_delete_experiment_treatmentDestructiveDELETE /v1/appStoreVersionExperimentTreatments/{id} — remove a variant (and its localizations/assets) from a pre-submission experiment.
-
asc_delete_iap_localizationDestructiveDELETE an InAppPurchaseLocalization. The locale-specific copy is removed; customers in that locale fall back to the default. Apple may reject if the IAP is in a state that locks...
-
asc_delete_marketplace_search_detailDestructiveDELETE /v1/marketplaceSearchDetails/{id}.
-
asc_delete_marketplace_webhookDestructiveDELETE /v1/marketplaceWebhooks/{id} — stop marketplace update notifications.
-
asc_delete_promoted_purchaseDestructiveDELETE a PromotedPurchase. Removes the IAP / subscription from the promoted slots on the storefront. The underlying IAP / subscription is NOT deleted — only the promotion linkage.
-
asc_delete_review_submission_itemDestructiveDELETE a ReviewSubmissionItem from a draft submission. Only valid while the parent submission is READY_FOR_REVIEW — after submission, items cannot be removed (use asc_patch_revi...
-
asc_delete_subscription_introductory_offerDestructiveDelete a pending or active introductory offer by ID. Apple refuses to delete an offer that is currently redeemable by users — to stop an active offer, PATCH endDate to today ins...
-
asc_delete_subscription_localizationDestructiveDELETE a SubscriptionLocalization. The locale-specific copy is removed; subscribers in that locale fall back to the default locale. Apple may reject if the subscription is in a ...
-
asc_delete_subscription_priceDestructiveDelete a pending scheduled subscription price by ID. Use this to roll back a change that has not yet activated.
-
asc_delete_subscription_promotional_offerDestructiveDelete a promotional offer by ID. Returns 204 on success. Apple does not document whether the offerCode is immediately reusable after delete — recommend appending a suffix when ...
-
asc_delete_treatment_localizationDestructiveDELETE /v1/appStoreVersionExperimentTreatmentLocalizations/{id} — remove a locale (and its variant assets) from a treatment.
-
asc_delete_version_experimentDestructiveDELETE /v2/appStoreVersionExperiments/{id} — removes the experiment and its treatments/localizations. Works on un-started experiments; running experiments should be stopped thro...
-
asc_delete_webhookDestructiveDELETE /v1/webhooks/{id} — permanently remove the webhook and stop all deliveries. Delivery history is gone with it. To pause instead of delete, PATCH enabled=false.
-
asc_remove_beta_group_buildsDestructiveUnassign builds from a beta group via DELETE /v1/betaGroups/{id}/relationships/builds. The build itself is not deleted; only the group→build linkage is removed. Testers in the g...
-
asc_remove_beta_group_testersDestructiveRemove testers from a beta group via DELETE /v1/betaGroups/{id}/relationships/betaTesters. Pass only the IDs you want removed — Apple uses the body, not a
-
asc_post_subscription_priceFinancialSchedule a price change for a single (subscription, territory) on a future date.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.