Connect App Store Connect to ASO Signals
Choose suitable Apple permissions, verify your API key, and understand connection limits.
Written By Enrique Bonansea
Last updated About 2 hours ago
ASO Signals needs an App Store Connect API connection to load your apps. Use a dedicated key and follow the setup guidance for the capabilities you need.
Prepare a dedicated key
Open App Store Connect and select the team that owns your apps.
Go to Users and Access → Integrations → App Store Connect API → Team Keys.
An Account Holder or Admin can create a team key. The suggested name is ASOSignals.
Select the appropriate access level, then download the .p8 file and copy the matching Issuer ID and Key ID.
If Apple shows Request Access, the Account Holder must request API access first. Team keys apply across their Apple team’s apps. See Apple’s key setup guide.
Understand the permissions
Creating a team key and choosing that key’s permissions are separate decisions. Apple requires Admin for creating or recovering analytics report requests. Existing generated reports can be listed and downloaded using Admin, Sales and Reports, or Finance access. Apple recommends Sales and Reports for sharing a report-processing key; that role does not establish access to every metadata resource. See Apple’s analytics permission guide.
Admin is broad access. Use the permissions needed for your intended work and review missing capabilities individually. The current preview’s performance reports remain unavailable even if your key has analytics permissions.
Verify the connection
Open Settings in ASO Signals.
Enter the Issuer ID and Key ID, and choose the matching .p8 file.
Select Verify key and connect and wait for the result.
After success, select your apps under Choose your apps.
For an existing individual key, choose Use an individual API key instead. Enter its Key ID and .p8 file; no Issuer ID is used. Access follows its owner’s permissions and may not cover all apps or analytics setup.
Keep credentials private
Upload your .p8 file only through the secure connection form. Never paste private-key contents, passwords, or sign-in codes into email or chat. A connected key confirms app access; it does not mean all reports, metadata families, or analyses are ready.