ApproveKit

Audit apps against App Store, Google Play and Google OAuth review rules; get the required docs.

使うべきか

品質と安全性

A
説明の品質
95%
スキーマの完全性
96%
命名の品質
100%
ポイズニングのリスク
80%
権限の一致
100%
プロトコルへの準拠
100%

検出事項(3)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool 'publish_document' description contains placeholder textpublish_document 内
  • INFOTool description contains placeholder or incomplete textpublish_document 内

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~1,636トークン数(ツール定義)
~3.7 KB一般的なレスポンスサイズ
注意への影響は中程度(128k コンテキストの 1.28%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "approvekit": {
      "url": "https://approvekit.dev/mcp"
    }
  }
}

リモートエンドポイント

https://approvekit.dev/mcpstreamable-http

できること

ツール一覧

ツール(4)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟡audit_app(inventory, app_token)

Use before submitting a mobile or web app to the Apple App Store, Google Play or Google OAuth verification. Pass an inventory of what the app collects, which SDKs it uses and which Google scopes it requests (build it by reading the repo). Returns the problems reviewers are likely to reject, how to fix each one, and which paid package generates the missing documents. Free. The first call returns an app_token: save it in .approvekit.json at the project root and pass it on later calls so the app is updated instead of duplicated.

入力スキーマ

{
  "type": "object",
  "properties": {
    "inventory": {
      "type": "object",
      "properties": {
        "app_name": {
          "type": "string",
          "minLength": 1,
          "maxLength": 100
        },
        "developer_name": {
          "type": "string",
          "minLength": 1,
          "maxLength": 200,
          "description": "Legal name that appears in the policies, usually the company or the individual developer."
        },
        "support_email": {
          "type": "string",
          "format": "email",
          "pattern": "^(?:[A-Za-z0-9_'+\\-]+\\.)*[A-Za-z0-9_'+\\-]*[A-Za-z0-9_+-]@(?:[A-Za-z0-9][A-Za-z0-9\\-]*\\.)+[A-Za-z]{2,}$",
          "description": "Public contact address for privacy and deletion requests."
        },
        "platforms": {
          "minItems": 1,
          "type": "array",
          "items": {
            "type": "string",
            "enum": [
              "ios",
              "android",
              "web"
            ]
          }
        },
        "has_user_accounts": {
          "type": "boolean",
          "description": "True if users can sign up or log in."
        },
        "account_deletion_in_app": {
          "description": "True if the app already lets users delete their account from inside the app.",
          "type": [
            "boolean",
            "null"
          ]
        },
        "data_collected": {
          "default": [],
          "type": "array",
          "items": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "description": "Kind of data, e.g. \"email\", \"precise location\", \"photos\", \"purchase history\"."
              },
              "purpose": {
                "type": "string",
                "description": "Why it is collected, e.g. \"account login\", \"analytics\"."
              },
              "shared_with": {
                "description": "Third parties that receive this data.",
                "anyOf": [
                  {
                    "type": "array",
                    "items": {
                      "type": "string"
                    }
                  },
                  {
                    "type": "null"
                  }
                ]
              }
            },
            "required": [
              "type",
              "purpose"
            ]
          }
        },
        "third_party_sdks": {
          "default": [],
          "description": "SDKs found in the dependencies, e.g. \"Firebase Analytics\", \"RevenueCat\", \"Sentry\".",
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "google_oauth_scopes": {
          "default": [],
          "description": "Full Google OAuth scope URLs the app requests, if it uses Sign in with Google or Google APIs.",
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "privacy_policy_url": {
          "description": "Existing privacy policy URL, if any.",
          "anyOf": [
            {
              "type": "string",
              "format": "uri"
            },
            {
              "type": "null"
            }
          ]
        },
        "account_deletion_url": {
          "description": "Existing public page where users can request account deletion, if any.",
          "anyOf": [
            {
              "type": "string",
              "format": "uri"
            },
            {
              "type": "null"
            }
          ]
        },
        "takes_payments": {
          "type": [
            "boolean",
            "null"
          ]
        },
        "auth_providers": {
          "default": [],
          "description": "How users sign in, e.g. \"Sign in with Apple\", \"Google\", \"email and password\", \"Supabase Auth\".",
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "permissions": {
          "default": [],
          "description": "iOS usage-description keys and Android permissions the app declares, e.g. NSCameraUsageDescription, android.permission.READ_CONTACTS.",
          "type": "array",
          "items": {
            "type": "string"
          }
        },
        "bundle_ids": {
          "description": "iOS bundle identifier and Android application id.",
          "anyOf": [
            {
              "type": "object",
              "properties": {
                "ios": {
                  "type": [
                    "string",
                    "null"
                  ]
                },
                "android": {
                  "type": [
                    "string",
                    "null"
                  ]
                }
              }
            },
            {
              "type": "null"
            }
          ]
        },
        "stack": {
          "description": "How the app is built. Expo config plugins add permission strings automatically, so some checks differ.",
          "anyOf": [
            {
              "type": "string",
              "enum": [
                "expo",
                "react-native",
                "flutter",
                "ios",
                "android",
                "web"
              ]
            },
            {
              "type": "null"
            }
          ]
        },
        "android_target_sdk": {
          "description": "targetSdkVersion from build.gradle, if known.",
          "anyOf": [
            {
              "type": "integer",
              "minimum": -9007199254740991,
              "maximum": 9007199254740991
            },
            {
              "type": "null"
            }
          ]
        },
        "play_developer_account": {
          "description": "Google Play account type: personal created after 2023-11-13 (closed-testing requirement applies), personal created before, or organization. Ask the user.",
          "anyOf": [
            {
              "type": "string",
              "enum": [
                "personal-new",
                "personal-old",
                "organization"
              ]
            },
            {
              "type": "null"
            }
          ]
        }
      },
      "required": [
        "app_name",
        "developer_name",
        "support_email",
        "platforms",
        "has_user_accounts"
      ]
    },
    "app_token": {
      "description": "The app_token returned by audit_app. It is stored in .approvekit.json at the project root. Omit on the first audit of an app.",
      "type": "string"
    }
  },
  "required": [
    "inventory"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡create_checkout(app_token, product)

Creates a Stripe Checkout link for one app. Only call this after the user agreed to the purchase. Show the link to the user so they can pay; then call get_order with the returned order_id to receive the documents.

入力スキーマ

{
  "type": "object",
  "properties": {
    "app_token": {
      "type": "string",
      "description": "The app_token returned by audit_app. It is stored in .approvekit.json at the project root."
    },
    "product": {
      "type": "string",
      "enum": [
        "launch_pass",
        "oauth_pack"
      ],
      "description": "launch_pass (US$49) or oauth_pack (US$249)."
    }
  },
  "required": [
    "app_token",
    "product"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_order(app_token, order_id)

Returns the payment status of an order. Once paid, returns every generated document as Markdown plus the public URLs of the hosted privacy policy and account deletion pages, ready to paste into App Store Connect, Play Console or the Google OAuth consent screen.

入力スキーマ

{
  "type": "object",
  "properties": {
    "app_token": {
      "type": "string",
      "description": "The app_token returned by audit_app. It is stored in .approvekit.json at the project root."
    },
    "order_id": {
      "type": "string",
      "description": "The order_id returned by create_checkout."
    }
  },
  "required": [
    "app_token",
    "order_id"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡publish_document(app_token, kind, markdown)

Saves the final version of a document after every [CONFIRM: ...] placeholder has been resolved with the user. For privacy-policy and account-deletion this makes the hosted page live at its public URL; for the other kinds it just stores the final text. Call it again whenever the text needs an update (for example after the app adds a new data type).

入力スキーマ

{
  "type": "object",
  "properties": {
    "app_token": {
      "type": "string",
      "description": "The app_token returned by audit_app. It is stored in .approvekit.json at the project root."
    },
    "kind": {
      "type": "string",
      "enum": [
        "privacy-policy",
        "account-deletion",
        "reviewer-notes",
        "oauth-scope-justifications",
        "oauth-demo-script"
      ]
    },
    "markdown": {
      "type": "string",
      "minLength": 50,
      "description": "The complete final document in Markdown (headings, lists, bold and links only)."
    }
  },
  "required": [
    "app_token",
    "kind",
    "markdown"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 4 件