Skip to content

Authentication

Both stores work without any authentication. The default providers use public endpoints and require no setup.

If you need account-scoped official access, you can configure the store APIs. Their fields, ordering, and history differ from the public sources; they are not strict supersets. This page walks through setup for each store.


Apple App Store Connect API

The official API gives credentials access to reviews for apps in the associated App Store Connect account.

What You Need

  • An Apple Developer Program membership ($99/year)
  • An API key from App Store Connect
  • Three pieces of information: Key ID, Issuer ID, and a .p8 private key file

Step-by-Step Setup

Step 1: Open App Store Connect

Go to App Store Connect and sign in with your Apple Developer account.

Step 2: Navigate to API Keys

Go to Users and Access, select the Integrations tab, then App Store Connect API in the left column, and make sure the Team Keys tab is selected. Generating team keys requires the Admin role (see Apple's Creating API Keys for App Store Connect API).

Step 3: Generate a New Key

Click Generate API Key or the + button to create a new API key. Give it a name (like "App Reviews") and, under Access, select the role for the key.

After creating the key, you will see two values on the page:

  • Key ID, a short alphanumeric string (like ABC123DEF4)
  • Issuer ID, a UUID (like 12345678-1234-1234-1234-123456789012)

Copy both.

Step 4: Download the Private Key

Click Download API Key to get the .p8 file. This file contains your private key.

Download it now

You can only download the .p8 file once. If you lose it, you will need to create a new key.

Save it somewhere safe, like ~/.appstore-keys/AuthKey_ABC123DEF4.p8.

Step 5: Use the Credentials

Pass the credentials to AppStoreReviews via AppStoreAuth:

from app_reviews import AppStoreAuth, AppStoreReviews

with AppStoreReviews(
    auth=AppStoreAuth(
        key_id="ABC123DEF4",
        issuer_id="12345678-1234-1234-1234-123456789012",
        key_path="/path/to/AuthKey_ABC123DEF4.p8",
    )
) as client:
    # Connect is global; each review may report its own territory.
    result = client.fetch("324684580", limit=100, max_pages=3)

Keys held in memory

To load the key from a secret manager or an environment variable instead of a file, pass its PEM text as private_key. Pass exactly one of key_path and private_key; the PEM is left out of repr and out of validation errors.

import os

from app_reviews import AppStoreAuth

auth = AppStoreAuth(
    key_id="ABC123DEF4",
    issuer_id="12345678-1234-1234-1234-123456789012",
    private_key=os.environ["ASC_PRIVATE_KEY"],
)

Replying to reviews

AppStoreReplies needs a key whose role may answer reviews: Customer Support or Admin (see Apple's Respond to reviews). AppStoreVersions needs a key that can read the app's App Store versions.

No Auth (Public RSS Feed)

If you do not provide auth, the client automatically uses the public RSS feed:

from app_reviews import AppStoreReviews

# No auth: uses the public RSS feed
with AppStoreReviews() as client:
    result = client.fetch("324684580", limit=100, max_pages=3)

How It Works

The package uses your .p8 private key to sign a JWT (JSON Web Token) using the ES256 algorithm. This token is sent as a Bearer token in the Authorization header of each request to the App Store Connect API.

Tokens are short-lived. One client caches its signed token and reuses it until it nears expiry, then signs a fresh one; it does not sign once per fetch or per request. Your private key never leaves your machine.


Google Play Developer API

The official API gives you access to reviews through Google's authenticated endpoint, with pagination support and structured data.

What You Need

  • A Google Cloud account
  • A Google Play Developer account linked to your Google Cloud project
  • A service account JSON key file

Step-by-Step Setup

Step 1: Open Google Cloud Console

Go to Google Cloud Console and select your project (or create a new one).

Step 2: Enable the Google Play Developer API

Open the Google Play Developer API page in Google Cloud Console and click Enable.

Step 3: Create a Service Account

Go to Service Accounts and click Create service account.

Give it a name (like "app-reviews") and click through the wizard. You do not need to grant it any Google Cloud roles; the permissions come from the Google Play Console side.

Step 4: Download the Key File

After creating the service account, click on it, go to the Keys tab, and click Add Key > Create New Key > JSON.

This downloads a JSON file. Save it somewhere safe, like ~/.google-keys/service-account.json.

Step 5: Invite the Service Account in Google Play Console

Go to the Users and permissions page in the Google Play Console and click Invite new users. Enter the service account's email address, grant it the Reply to reviews permission for the app, and click Invite user. Google's Reply to Reviews API requires that permission for reading reviews as well as replying (see also Google's Getting Started).

Propagation delay

After granting access, it can take up to 24 hours for the permissions to take effect.

Step 6: Use the Credentials

Pass the credentials to GooglePlayReviews via GooglePlayAuth:

from app_reviews import GooglePlayAuth, GooglePlayReviews

with GooglePlayReviews(
    auth=GooglePlayAuth(
        service_account_path="/path/to/service-account.json",
    )
) as client:
    # Play reviews are global; reviewer country is not reported.
    result = client.fetch("com.spotify.music", limit=100, max_pages=3)

Keys held in memory

To load the key from a secret manager instead of a file, pass the parsed JSON as service_account_info. Pass exactly one of service_account_path and service_account_info; the info mapping is left out of repr.

import json
import os

from app_reviews import GooglePlayAuth

auth = GooglePlayAuth(
    service_account_info=json.loads(os.environ["PLAY_SERVICE_ACCOUNT_JSON"])
)

Replying to reviews

GooglePlayReplies uses the same Reply to reviews permission granted in Step 5.

No Auth (Public Web Endpoint)

If you do not provide auth, the client automatically uses the public web endpoint:

from app_reviews import GooglePlayReviews

# No auth: uses the public web endpoint
with GooglePlayReviews() as client:
    result = client.fetch("com.spotify.music", limit=100, max_pages=3)

How It Works

The package reads your service account JSON file or uses the mapping supplied as service_account_info, extracts the RSA private key, and signs a JWT using the RS256 algorithm. This JWT is exchanged for an OAuth2 access token via Google's token endpoint.

The access token is then used as a Bearer token in requests to the Google Play Developer API. One client caches the token and reuses it until it nears expiry, then exchanges for a fresh one; it does not exchange once per fetch or per request. Your private key never leaves your machine.