Reported issues for Heimdall by erayendes
Pod holds 7 of 7 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to Heimdall by erayendes.
Most discussed
Xcode 27 MCP integration
What are you trying to do
Hi! Thanks for building and maintaining app-store-connect-mcp.
With Xcode 27, Apple has introduced MCP support and the ability to extend Xcode Agents with external MCP servers.
I’m wondering if you have any plans to support Xcode 27’s MCP/Agent ecosystem directly, or if app-store-connect-mcp can already be used with Xcode 27 as an external MCP server.
<img width="822" height="764" alt="Image"…
Read the thread · 2026-09-17 · closed · external user · 2 comments
Multiple App Store Connect accounts in one installation
Problem
One installation talks to one App Store Connect account. People who manage apps for several companies or teams have to re-run setup or keep separate configs to switch.
Proposal
setupcan store several API keys in the Keychain, each under a name.- A profile can be registered for a named account, e.g.
register analytics@acme, producing a server such asasc-analytics-acme. asc__statusreports which account a server is using.- The rule in
src/core/config.tsthat a…
Read the thread · 2026-09-29 · open · 0 comments
TestFlight: feedback screenshots as images, and a "why can't testers see this build" check
Problem
The testflight profile can already list crash and screenshot feedback and read a crash log. Two gaps remain:
- Screenshot feedback comes back as a URL, so the model cannot see what the tester saw.
- "Why can't my testers see this build?" takes several calls (processing state, expiry, export compliance, beta review, group assignment), and the model often misses one.
Proposal
- Return screenshot feedback as MCP image content (downloaded server-side, size-capped) alongside…
Read the thread · 2026-09-29 · open · 0 comments
StoreKit: generate promotional and introductory offer signatures
Problem
To present a promotional offer (and some introductory-offer flows) in the app, the developer's server must produce a signature Apple verifies. Heimdall can read transactions and subscription statuses but cannot produce these signatures, so the agent cannot help set up or test offers end to end.
Proposal
StoreKit tools that generate:
- promotional offer signatures (the v2 JWS format, and the legacy format for older clients);
- introductory offer eligibility signatures.…
Read the thread · 2026-09-29 · open · 0 comments
Turn Apple's bare 409 conflicts into a remedy
Problem
Apple answers several mistakes with a bare 409 Conflict and a message that does not say what to do. Common cases:
- setting a price before the territory availability exists;
- deleting a resource that other resources still reference;
- editing a version or product in a state that does not allow the change.
The model then retries blindly or gives up.
Proposal
A small table of known Apple error signatures (status, error code, and where needed the operation) mapped to a…
Read the thread · 2026-09-29 · open · 0 comments
Purchasing-power mode for pricing__equalize_price
Problem
pricing__equalize_price derives every territory's price from one anchor using Apple's own equalization, which is an exchange-rate conversion. A price that is reasonable in the US is often far too high in lower-income storefronts.
Proposal
An opt-in purchasing-power mode for pricing__equalize_price:
- Scale the anchor price per territory by a purchasing-power index, then snap to the nearest valid Apple price point.
- Guards, all required: a floor (never below X of the…
Read the thread · 2026-09-29 · open · 0 comments
Keep the write guard on clients without elicitation: preview + request-bound confirmation token
Problem
High-stakes writes (revenue, destructive, infrastructure, access) ask the user through MCP elicitation. A client that never declared elicitation cannot be asked, so the guard fails closed (src/core/confirm.ts, confirmWrite): the write is blocked, and the only way forward is ASC_CONFIRM_WRITES=0 / --no-confirm, which removes the guard entirely.
So on those clients the choice is "no high-stakes writes" or "no guard".
Proposal
A two-step fallback for clients without…
Read the thread · 2026-09-29 · open · 0 comments
Most recent
The remaining reports are on the project's issue tracker.