Servidor MCP

ApproveKit

dev.approvekit/approvekit

Qué hace este MCP

Audits apps against Apple, Google Play, and Google OAuth review requirements and generates related compliance documents.

audit_app
Audit an app for store and Google OAuth review
Use before submitting a mobile or web app to the Apple App Store, Google Play or Google OAuth verification. Pass an inventory of what the app collects, which SDKs it uses and which Google scopes it requests (build it by reading the repo). Returns the problems reviewers are likely to reject, how to fix each one, and which paid package generates the missing documents. Free. The first call returns an app_token: save it in .approvekit.json at the project root and pass it on later calls so the app is updated instead of duplicated.
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['inventory'], 'properties': {'app_token': {'type': 'string', 'description': 'The app_token returned by audit_app. It is stored in .approvekit.json at the project root. Omit on the first audit of an app.'}, 'inventory': {'type': 'object', 'required': ['app_name', 'developer_name', 'support_email', 'platforms', 'has_user_accounts'], 'properties': {'stack': {'anyOf': [{'enum': ['expo', 'react-native', 'flutter', 'ios', 'android', 'web'], 'type': 'string'}, {'type': 'null'}], 'description': 'How the app is built. Expo config plugins add permission strings automatically, so some checks differ.'}, 'app_name': {'type': 'string', 'maxLength': 100, 'minLength': 1}, 'platforms': {'type': 'array', 'items': {'enum': ['ios', 'android', 'web'], 'type': 'string'}, 'minItems': 1}, 'bundle_ids': {'anyOf': [{'type': 'object', 'properties': {'ios': {'type': ['string', 'null']}, 'android': {'type': ['string', 'null']}}}, {'type': 'null'}], 'description': 'iOS bundle identifier and Android application id.'}, 'permissions': {'type': 'array', 'items': {'type': 'string'}, 'default': [], 'description': 'iOS usage-description keys and Android permissions the app declares, e.g. NSCameraUsageDescription, android.permission.READ_CONTACTS.'}, 'support_email': {'type': 'string', 'format': 'email', 'pattern': "^(?:[A-Za-z0-9_'+\\-]+\\.)*[A-Za-z0-9_'+\\-]*[A-Za-z0-9_+-]@(?:[A-Za-z0-9][A-Za-z0-9\\-]*\\.)+[A-Za-z]{2,}$", 'description': 'Public contact address for privacy and deletion requests.'}, 'auth_providers': {'type': 'array', 'items': {'type': 'string'}, 'default': [], 'description': 'How users sign in, e.g. "Sign in with Apple", "Google", "email and password", "Supabase Auth".'}, 'data_collected': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'purpose'], 'properties': {'type': {'type': 'string', 'description': 'Kind of data, e.g. "email", "precise location", "photos", "purchase history".'}, 'purpose': {'type': 'string', 'description': 'Why it is collected, e.g. "account login", "analytics".'}, 'shared_with': {'anyOf': [{'type': 'array', 'items': {'type': 'string'}}, {'type': 'null'}], 'description': 'Third parties that receive this data.'}}}, 'default': []}, 'developer_name': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Legal name that appears in the policies, usually the company or the individual developer.'}, 'takes_payments': {'type': ['boolean', 'null']}, 'third_party_sdks': {'type': 'array', 'items': {'type': 'string'}, 'default': [], 'description': 'SDKs found in the dependencies, e.g. "Firebase Analytics", "RevenueCat", "Sentry".'}, 'has_user_accounts': {'type': 'boolean', 'description': 'True if users can sign up or log in.'}, 'android_target_sdk': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'targetSdkVersion from build.gradle, if known.'}, 'privacy_policy_url': {'anyOf': [{'type': 'string', 'format': 'uri'}, {'type': 'null'}], 'description': 'Existing privacy policy URL, if any.'}, 'google_oauth_scopes': {'type': 'array', 'items': {'type': 'string'}, 'default': [], 'description': 'Full Google OAuth scope URLs the app requests, if it uses Sign in with Google or Google APIs.'}, 'account_deletion_url': {'anyOf': [{'type': 'string', 'format': 'uri'}, {'type': 'null'}], 'description': 'Existing public page where users can request account deletion, if any.'}, 'play_developer_account': {'anyOf': [{'enum': ['personal-new', 'personal-old', 'organization'], 'type': 'string'}, {'type': 'null'}], 'description': 'Google Play account type: personal created after 2023-11-13 (closed-testing requirement applies), personal created before, or organization. Ask the user.'}, 'account_deletion_in_app': {'type': ['boolean', 'null'], 'description': 'True if the app already lets users delete their account from inside the app.'}}}}}
create_checkout
Create a payment link for a ApproveKit package
Creates a Stripe Checkout link for one app. Only call this after the user agreed to the purchase. Show the link to the user so they can pay; then call get_order with the returned order_id to receive the documents.
Acceso externo
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app_token', 'product'], 'properties': {'product': {'enum': ['launch_pass', 'oauth_pack'], 'type': 'string', 'description': 'launch_pass (US$49) or oauth_pack (US$249).'}, 'app_token': {'type': 'string', 'description': 'The app_token returned by audit_app. It is stored in .approvekit.json at the project root.'}}}
get_order
Get an order's status and its documents
Returns the payment status of an order. Once paid, returns every generated document as Markdown plus the public URLs of the hosted privacy policy and account deletion pages, ready to paste into App Store Connect, Play Console or the Google OAuth consent screen.
Solo lectura Acceso externo Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app_token', 'order_id'], 'properties': {'order_id': {'type': 'string', 'description': 'The order_id returned by create_checkout.'}, 'app_token': {'type': 'string', 'description': 'The app_token returned by audit_app. It is stored in .approvekit.json at the project root.'}}}
publish_document
Publish the final text of a generated document
Saves the final version of a document after every [CONFIRM: ...] placeholder has been resolved with the user. For privacy-policy and account-deletion this makes the hosted page live at its public URL; for the other kinds it just stores the final text. Call it again whenever the text needs an update (for example after the app adds a new data type).
Idempotente
Esquema de entrada
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app_token', 'kind', 'markdown'], 'properties': {'kind': {'enum': ['privacy-policy', 'account-deletion', 'reviewer-notes', 'oauth-scope-justifications', 'oauth-demo-script'], 'type': 'string'}, 'markdown': {'type': 'string', 'minLength': 50, 'description': 'The complete final document in Markdown (headings, lists, bold and links only).'}, 'app_token': {'type': 'string', 'description': 'The app_token returned by audit_app. It is stored in .approvekit.json at the project root.'}}}
Añadido
publish_document
1 de October de 2026 a las 02:40
Añadido
get_order
1 de October de 2026 a las 02:40
Añadido
create_checkout
1 de October de 2026 a las 02:40
Añadido
audit_app
1 de October de 2026 a las 02:40