Native macOS App • App Store Connect • Local MCP Server

Ship to the App Store.
Without leaving your IDE.

FlightDeck connects your AI coding agent to App Store Connect through a local MCP server. Let your agent manage releases, metadata, screenshots, localization, ASO, and more—while you stay in control.

Coming Soon to the Mac App Store macOS Native
Explore AI Workflows
FlightDeck Approval Center displaying an AI change request across 7 localizations with exact operations, localization diffs, and approval status
Your AI Agent. Your App Store Workflow.

Spend more time building. Let your AI agent handle the App Store.

FlightDeck gives your AI agent access to App Store workflows directly from your development process—while you decide what it can do and what requires your approval.

Releases & App Review

Prepare new versions, attach builds, update release information, and manage App Store review submissions through supported agent workflows.

Version Creation Build Attachment Review Submissions

Metadata & ASO

Update app titles, subtitles, descriptions, promotional text, keywords, URLs, and What’s New release notes across multiple localizations.

Store Metadata Keywords & ASO Release Notes

Screenshots & Localization

Upload and organize screenshot sets across required device display sizes and manage localized store presence for global App Store regions.

Screenshot Sets Localizations Multi-Locale

TestFlight & Builds

Query uploaded builds, inspect processing status, manage internal and external beta groups, and coordinate TestFlight distribution workflows.

Beta Groups Build Status TestFlight Notes

Pre-Flight Diagnostics

Evaluate release readiness before submission and surface missing or incomplete App Store requirements before they become submission blockers.

Readiness Audit Prerequisites Submission Previews

Local, Auditable Operations

Keep operations local with sanitized logging, macOS Keychain credential storage, and configurable human approval before mutations contact Apple.

Local FIFO Audit macOS Keychain Configurable Approval
The FlightDeck App

See your apps before you ship.

FlightDeck also gives you a visual view of your App Store presence. Browse your apps, inspect metadata and localizations, preview screenshots and storefront content, and review upcoming releases before they go live.

FlightDeck Storefront Preview displaying Block 1000 with iPhone and iPad Pro device tabs, localized release notes, and version readiness status
Zero-Cloud Architecture

Your Mac talks directly to Apple. No middleman.

Most SaaS tools require you to paste your private App Store Connect API keys into their cloud databases. FlightDeck rejects that risk entirely.

Your Mac (FlightDeck)
Private .p8 Key in macOS Keychain

Local JWT Signing (ES256)
15-minute token lifetime

Encrypted HTTPS
Direct TLS 1.3
Apple Servers
api.appstoreconnect.apple.com

Apple Official REST Endpoints
Presigned Asset Upload Storage

✓ Zero Cloud Proxies

We do not operate any backend server, proxy, or relay between FlightDeck and Apple. Your requests never touch our servers.

✓ Zero Private Key Transmission

Your .p8 private key is never sent over the network to anyone—not even Apple. Only short-lived locally signed tokens are transmitted.

✓ Strict Host Locking

The networking transport enforces HTTPS and restricts requests to Apple’s verified domains and RevenueCat for subscription validation.

AI Automation Without Giving Up Control

Decide what your AI agent can do—and what requires your approval.

FlightDeck embeds a local Model Context Protocol (MCP) server that connects compatible AI coding agents to App Store Connect. You set fine-grained permissions to determine which operations can execute and which must be staged for review.

Strict Loopback Isolation

The embedded MCP server binds strictly to the local IPv4 loopback interface (127.0.0.1). It does not listen on local network adapters or public interfaces. Other devices on your Wi-Fi or LAN cannot connect.

127.0.0.1 Only No LAN Exposure

Configurable Authentication

By default, connections are locked to this Mac without extra setup. When desired, enable password protection to require an authentication Bearer token stored securely in your macOS Keychain.

Local by Default Optional Password Keychain Backed

Granular Permissions & Approvals

Configure access modes (Read, Read + Write, Off) and toggle AI Approval per capability. Reviewed mutations can execute directly, or remain staged in the Approval Center for your inspection.

Per-Domain Scopes Approval Center Configurable Approval

Important Fact: FlightDeck contains zero direct integrations with AI companies (such as OpenAI, Anthropic, or Google). FlightDeck operates strictly as an MCP server. You choose which local AI client to connect, and your credentials are never revealed to the client.

FlightDeck MCP Server settings showing Capability Permissions and AI Approval Controls across functional domains
Evidence-Based Privacy

Verified by source code. Grounded in facts.

We audited every line of FlightDeck’s implementation before publishing this documentation. Here are the verifiable facts about your data:

🔒 macOS Keychain Storage

Private .p8 API keys are stored in the macOS Keychain (kSecClassGenericPassword) using Apple’s Security framework. Keys are streamed via stdin to avoid command-line argument inspection.

🛡 Zero Analytics & Telemetry

FlightDeck contains no third-party tracking frameworks, analytics trackers, or user behavioral SDKs (no Google Analytics, Firebase, Sentry, Mixpanel, Amplitude, or PostHog). We do not record or transmit your activity.

💳 StoreKit 2 & RevenueCat

Pro subscriptions are processed via Apple StoreKit 2 and validated by RevenueCat. RevenueCat receives anonymous StoreKit receipts; it never receives App Store Connect API keys, Issuer IDs, or private keys.

📄 No Plaintext Key Persistence

Non-sensitive profile identifiers (Key ID, Issuer ID) are saved in sandboxed preferences. The private key itself is never written to disk, preferences files, or temporary directories.

⏱ 15-Minute Ephemeral Tokens

JSON Web Tokens (JWTs) are signed locally with ECDSA P-256 (ES256) and expire within 15 minutes. They are kept in volatile memory and never persisted to disk.

ℹ︎ Standard macOS Diagnostics

FlightDeck does not run custom crash uploaders. If an unexpected crash occurs, crash logs are processed solely through Apple’s native macOS system diagnostic mechanisms if opted in by the user.

Read Full FlightDeck Privacy Policy →
Developer Hub

Expanding the FlightDeck ecosystem.

Following the initial Mac App Store release, this portal will expand into a comprehensive resource center for macOS and iOS developers.

Phase 4 • Coming Soon

Developer Documentation

Comprehensive step-by-step guides for API key setup, Claude & Cursor MCP configuration, and release automation.

Phase 5 • Coming Soon

AI Prompt Library

Curated prompt templates for drafting release notes, reviewing localized store copy, and generating changelogs via MCP.

Phase 6 • Coming Soon

Community & Feedback

Direct feature requests, bug submission triage, and public upvoting for upcoming FlightDeck enhancements.

Phase 7 • Coming Soon

Engineering Changelog

Detailed release notes, API compatibility updates, and architecture write-ups for every FlightDeck version.