Skip to main content
The dashboard and the two programmatic surfaces work on the same resources. Everything listed under What the surface covers below is reachable from both — with a few exceptions under Where the two surfaces differ below, which is where most of the surprises live. The MCP server mirrors the v4 resource surface, and most of its tools wrap a single v4 operation. An AI client never handles the Secret Key.

What the surface covers

Customers and users · identities · purchases · user properties · entitlements · products · remote configurations · experiments and groups · segments · analytics, cohorts and LTV · Apple Ads reports and connection status · exports · events · scheduled reports · integrations · project settings.

Where the two surfaces differ

  • Apple Ads is read-only on both. The report, the daily series and the connection status are available through REST API v4 — see Apple Ads — and as MCP tools, where Apple Ads is a closed beta — see Apple Ads via MCP. Both answer for accounts with Apple Ads enabled; other accounts receive 404. You create and change campaigns in Apple Ads.
  • Some v4 resources are legacy. Screens and automations remain callable for existing integrations, but the products behind them are no longer maintained. They are not a place to build something new.

Which one to use

  • Your own server code, cron jobs, a warehouse sync — the REST API v4. Start at API reference and Authentication.
  • An agent acting on your behalf — the MCP server, so that access is scoped to your account role and revocable. Start at For agents and MCP Server.
  • Being told when something changes, instead of polling — webhooks.

Guardrails worth knowing before you wire anything up

  • Destructive tools do not fire on the first call. Over MCP, delete_*, revoke_*, detach_* and the deprecated regenerate_project_secret return a short-lived token addressed to the human operator. Completing the action requires echoing the resource id verbatim and giving a reason, which is recorded in the audit log.
  • Secret Keys belong on a server. Never ship one in an iOS, Android or web bundle. Rotate them in the dashboard — see Project keys.
  • Rate limits are not one number. SDK requests are throttled on the client — see Rate limits. The Apple Ads report and series are rate limited on both surfaces, and a 429 carries Retry-After — see Apple Ads and Apple Ads via MCP.
  • v3 is legacy. It still answers for existing integrations and gets no new functionality. Build on v4 — start from API reference; API v3 (legacy) maps each v3 resource to its v4 counterpart.

Next steps

For agents

Connect an agent in a few minutes, and read these docs as markdown.

MCP Server

Tool list, client-by-client setup, scopes and the confirmation flow.

API reference

Base URL, authentication, pagination, errors, resource guides.

Webhooks

Get subscription events pushed to your endpoint.