ApproveKit
What this MCP does
Audits apps against Apple, Google Play, and Google OAuth review requirements and generates related compliance documents.
Tools
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['inventory'], 'properties': {'app_token': {'type': 'string', 'description': 'The app_token returned by audit_app. It is stored in .approvekit.json at the project root. Omit on the first audit of an app.'}, 'inventory': {'type': 'object', 'required': ['app_name', 'developer_name', 'support_email', 'platforms', 'has_user_accounts'], 'properties': {'stack': {'anyOf': [{'enum': ['expo', 'react-native', 'flutter', 'ios', 'android', 'web'], 'type': 'string'}, {'type': 'null'}], 'description': 'How the app is built. Expo config plugins add permission strings automatically, so some checks differ.'}, 'app_name': {'type': 'string', 'maxLength': 100, 'minLength': 1}, 'platforms': {'type': 'array', 'items': {'enum': ['ios', 'android', 'web'], 'type': 'string'}, 'minItems': 1}, 'bundle_ids': {'anyOf': [{'type': 'object', 'properties': {'ios': {'type': ['string', 'null']}, 'android': {'type': ['string', 'null']}}}, {'type': 'null'}], 'description': 'iOS bundle identifier and Android application id.'}, 'permissions': {'type': 'array', 'items': {'type': 'string'}, 'default': [], 'description': 'iOS usage-description keys and Android permissions the app declares, e.g. NSCameraUsageDescription, android.permission.READ_CONTACTS.'}, 'support_email': {'type': 'string', 'format': 'email', 'pattern': "^(?:[A-Za-z0-9_'+\\-]+\\.)*[A-Za-z0-9_'+\\-]*[A-Za-z0-9_+-]@(?:[A-Za-z0-9][A-Za-z0-9\\-]*\\.)+[A-Za-z]{2,}$", 'description': 'Public contact address for privacy and deletion requests.'}, 'auth_providers': {'type': 'array', 'items': {'type': 'string'}, 'default': [], 'description': 'How users sign in, e.g. "Sign in with Apple", "Google", "email and password", "Supabase Auth".'}, 'data_collected': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'purpose'], 'properties': {'type': {'type': 'string', 'description': 'Kind of data, e.g. "email", "precise location", "photos", "purchase history".'}, 'purpose': {'type': 'string', 'description': 'Why it is collected, e.g. "account login", "analytics".'}, 'shared_with': {'anyOf': [{'type': 'array', 'items': {'type': 'string'}}, {'type': 'null'}], 'description': 'Third parties that receive this data.'}}}, 'default': []}, 'developer_name': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': 'Legal name that appears in the policies, usually the company or the individual developer.'}, 'takes_payments': {'type': ['boolean', 'null']}, 'third_party_sdks': {'type': 'array', 'items': {'type': 'string'}, 'default': [], 'description': 'SDKs found in the dependencies, e.g. "Firebase Analytics", "RevenueCat", "Sentry".'}, 'has_user_accounts': {'type': 'boolean', 'description': 'True if users can sign up or log in.'}, 'android_target_sdk': {'anyOf': [{'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991}, {'type': 'null'}], 'description': 'targetSdkVersion from build.gradle, if known.'}, 'privacy_policy_url': {'anyOf': [{'type': 'string', 'format': 'uri'}, {'type': 'null'}], 'description': 'Existing privacy policy URL, if any.'}, 'google_oauth_scopes': {'type': 'array', 'items': {'type': 'string'}, 'default': [], 'description': 'Full Google OAuth scope URLs the app requests, if it uses Sign in with Google or Google APIs.'}, 'account_deletion_url': {'anyOf': [{'type': 'string', 'format': 'uri'}, {'type': 'null'}], 'description': 'Existing public page where users can request account deletion, if any.'}, 'play_developer_account': {'anyOf': [{'enum': ['personal-new', 'personal-old', 'organization'], 'type': 'string'}, {'type': 'null'}], 'description': 'Google Play account type: personal created after 2023-11-13 (closed-testing requirement applies), personal created before, or organization. Ask the user.'}, 'account_deletion_in_app': {'type': ['boolean', 'null'], 'description': 'True if the app already lets users delete their account from inside the app.'}}}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app_token', 'product'], 'properties': {'product': {'enum': ['launch_pass', 'oauth_pack'], 'type': 'string', 'description': 'launch_pass (US$49) or oauth_pack (US$249).'}, 'app_token': {'type': 'string', 'description': 'The app_token returned by audit_app. It is stored in .approvekit.json at the project root.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app_token', 'order_id'], 'properties': {'order_id': {'type': 'string', 'description': 'The order_id returned by create_checkout.'}, 'app_token': {'type': 'string', 'description': 'The app_token returned by audit_app. It is stored in .approvekit.json at the project root.'}}}
Input schema
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['app_token', 'kind', 'markdown'], 'properties': {'kind': {'enum': ['privacy-policy', 'account-deletion', 'reviewer-notes', 'oauth-scope-justifications', 'oauth-demo-script'], 'type': 'string'}, 'markdown': {'type': 'string', 'minLength': 50, 'description': 'The complete final document in Markdown (headings, lists, bold and links only).'}, 'app_token': {'type': 'string', 'description': 'The app_token returned by audit_app. It is stored in .approvekit.json at the project root.'}}}
Recent tool changes
Similar MCP servers
Kamy
Renders, converts, edits and extracts PDFs, manages document templates and schedules, supports e-signature workflows and provides…
Spdx License
Browses SPDX open-source license metadata, approved-license lists, and complete license texts.
Licenses
Looks up SPDX open-source license metadata and retrieves complete license texts.
Clearlydefined
Finds software package coordinates and provides license, attribution, provenance, harvesting, and completeness information for ex…
SPDX license expression tokens, value discarded
Tokenizes and checks SPDX license expressions.
SPDX license id shape
Checks the shape of SPDX license identifiers.
AgentAegis
Performs cybersecurity assessments including vulnerability scans, code and dependency audits, secret detection, threat intelligen…
aribot-mcp
Performs threat modeling, code security, API and cloud security scans, compliance analysis, and governed remediation.