Back to Browse

Appdrift MCP Server

Developer ToolsModerate7.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Read app-store keyword observations and prepare reviewable listing drafts. AI actions use tokens.

About

Read app-store keyword observations and prepare reviewable listing drafts. AI actions use tokens.

Security Report

7.2
Moderate7.2Low Risk

AppDrift MCP server is a well-engineered, security-conscious implementation for App Store Optimization tasks. Strong authentication enforcement via API keys, comprehensive input validation using JSON Schema, and careful credential handling prevent sensitive data leakage. Permissions align appropriately with the server's purpose (network API calls, environment variable access). Minor code quality observations around error handling breadth do not materially impact security. Supply chain analysis found 1 known vulnerability in dependencies. Package verification found 1 issue.

7 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

API key from the AppDrift Developers dashboard. API access requires a paid plan.Required

Environment variable: APPDRIFT_API_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-blaze-apps-appdrift": {
      "env": {
        "APPDRIFT_API_KEY": "your-appdrift-api-key-here"
      },
      "args": [
        "-y",
        "appdrift-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

AppDrift MCP Server

Read your AppDrift keyword observations, account apps and action plan from Claude Desktop, Cursor or another MCP client. Generate or translate listing copy, review the result, and apply accepted fields to an editable AppDrift draft. These tools do not publish to Apple or Google.

This package is a small local stdio client for the AppDrift REST API. It requires Node.js 22 or later and an AppDrift API key. API access is available on eligible paid plans. Eligible first subscriptions have a seven-day trial with a card; the trial adds no tokens. Current plans and token allowances.

Install

Add AppDrift to your MCP client's configuration (Claude Desktop, Cursor or another MCP client):

{
  "mcpServers": {
    "appdrift": {
      "command": "npx",
      "args": ["-y", "appdrift-mcp"],
      "env": { "APPDRIFT_API_KEY": "ad_live_your_key_here" }
    }
  }
}
  1. Create a key in the Developers dashboard.
  2. Replace the placeholder in your client's local MCP configuration. Keep the key out of shared configuration and source control.
  3. Restart the client. Ask it to call account_status, then list_apps. These calls consume no AI tokens.
  4. Choose the returned app ID before asking for its tracked keywords. Review proposed text before allowing a paid action or a saved-draft change.

On the first run, npx downloads the package and its dependencies. If the client cannot find npx, use its absolute local executable path.

Without the npm registry: AppDrift also hosts the same wrapper as a versioned archive. Use https://appdrift.co/downloads/appdrift-mcp-0.2.0.tgz in args in place of appdrift-mcp, and check it against its SHA-256 checksum. The archive includes the complete wrapper source and MIT license. server.json prepares the official MCP registry entry, which is not published yet.

Tools and costs

No additional AI tokens: API access still requires an eligible account plan.

ToolResult
keyword_difficultyLegacy competitor-based difficulty/popularity heuristics. These are not measured keyword demand or ranking probability. Store collection can fail or be incomplete.
list_appsApps connected to the account, including the ID used by app-scoped tools.
app_keywordsTracked keywords and latest observed ranks for the selected app.
app_opportunitiesTracked keywords ranked 11–30, ordered by the legacy difficulty heuristic; candidates to review, not predicted gains.
action_planThe account's prioritized ASO actions.
account_statusPlan and remaining AI-token balance.
apply_optimizationChanges saved content: applies accepted title, subtitle, keywords or short_description fields to the app's editable draft. Review and store publishing remain separate.

AI tools: AppDrift charges for successful processing. Check the returned token charge and account balance. The client never retries these actions automatically.

ToolCostResult
optimize_for_keyword3 tokensProposed title/subtitle/keyword changes and rationale.
generate_metadata1 per short field; 2 per long fieldListing fields generated from the app brief.
translate_metadataPer language: 1 normally; 3 for description; 5 for full_descriptionOne field translated into 1–15 distinct locales.

Paid operations and apply_optimization are advertised as writes to MCP clients. A timeout or lost response does not prove that the server stopped processing or charged nothing. Check the account and draft before retrying. The client sends your API key and supplied listing text to the configured AppDrift API; AI requests may use the account's configured AI provider.

The legacy keyword_difficulty tool is separate from the experimental Keyword analyzer. Its scores do not predict rank, traffic or download gains.

Configuration

Environment variableRequiredDefault
APPDRIFT_API_KEYYesCreate it in the Developers dashboard.
APPDRIFT_API_BASENoAppDrift production API. Change only to an endpoint you trust with the key and listing text. HTTPS required; HTTP permitted only for loopback development.
APPDRIFT_REQUEST_TIMEOUT_MSNo90000; permitted range 1000–120000.

The client rejects redirects, bounds response size, validates tool inputs before requests and returns authored error messages instead of provider errors or stack traces. These safeguards do not replace backend authorization or review of an agent's proposed actions.

Troubleshooting

  • No tools: confirm Node 22+, npx availability and a nonempty APPDRIFT_API_KEY. MCP protocol messages use stdout; startup errors use stderr.
  • Invalid or revoked key: create or select an active key in Developers and update the local config.
  • Insufficient tokens: inspect account_status and current token options. A trial itself adds no tokens.
  • No editable draft: create the app's draft in AppDrift, then apply only the fields you reviewed.
  • No store results: try again later. A missing score is not zero competition.
  • Timeout after a paid action: inspect balance and saved state before requesting the action again.

Development

Within a source checkout, run npm ci, npm test and npm run verify:package. Integration checks launch the actual stdio process against local fixture APIs; they do not use production credentials or spend tokens. Package verification packs only the declared runtime files, installs the archive through a local HTTP URL into a clean directory and runs the integration suite against the installed executable.

License

MIT. See LICENSE.

Reviews

No reviews yet

Be the first to review this server!