AppFactory
An MCP server that lets your coding agent take a SwiftUI iOS subscription app from idea to the App Store.
What it does: idea harvesting and validation, design, SwiftUI code from a template, Supabase backend, App Store Connect + RevenueCat setup, localization, analytics, ASO, screenshots and TestFlight. Every stage has a gate the agent must pass. You do the final App Store submission.
Quickstart
Requires a Mac, Python 3.12+ and uv.
1. Add the MCP to your agent
One line, no installer. The server command is uvx --from git+https://github.com/gbatistuta0/appfactory appfactory-mcp.
| Agent | How |
|---|---|
| Claude Code | claude mcp add --scope user appfactory -- uvx --from git+https://github.com/gbatistuta0/appfactory appfactory-mcp |
| Codex CLI | ~/.codex/config.toml: [mcp_servers.appfactory] with command = "uvx", args = ["--from", "git+https://github.com/gbatistuta0/appfactory", "appfactory-mcp"] |
| Gemini CLI | ~/.gemini/settings.json: "mcpServers": {"appfactory": {"command": "uvx", "args": ["--from", "git+https://github.com/gbatistuta0/appfactory", "appfactory-mcp"]}} |
| Cursor | ~/.cursor/mcp.json: same shape as Gemini |
2. Ask your agent: "Set up AppFactory"
The agent calls setup_status, asks which services you want, and turns them on. Keys never go through the chat:
for secrets it opens a local page in your browser (127.0.0.1 only, one-time token) where you type them; they are
stored in ~/.appfactory/config.toml (mode 0600). appfactory doctor shows what is configured.
Then try this first prompt. It needs no accounts:
Find 3 underserved iOS app niches in Health & Fitness and validate the best one
Works with
Claude Code, Codex CLI, Gemini CLI and Cursor. The run playbook is served by the MCP server itself (tool
playbook(), prompt appfactory_run, resource appfactory://playbook), so any MCP-capable agent can follow it.
Choose what you use
Every service is optional. Tools for a disabled service do nothing and the pipeline skips those stages
(appfactory services enable|disable NAME).
| Service | What it enables | Needs |
|---|---|---|
| research | Idea harvesting, ASO research (always on) | nothing |
| apple | App Store Connect: apps, in-app purchases, metadata, TestFlight | ASC API key, asc CLI |
| xcode | Local builds, simulator, archives | Xcode, xcodegen |
| supabase | Backend: database, edge functions, credits | access token, supabase, deno |
| revenuecat | Subscriptions and entitlements | RevenueCat secret key |
| ai | AI features through a server-side proxy | optional provider keys |
| firebase | Firebase Analytics setup | firebase CLI |
| github | A repo and issues per app | gh |
| design | Screen design through the claude-design MCP | claude-design MCP |
| maestro | End-to-end UI tests on the simulator | Maestro, Java 17+ |
| lottie | Lottie animations | node |
Details and credential steps: docs/SETUP.md.
Safety
- Approvals. Irreversible or outward actions (submission, store/backend/RevenueCat writes, GitHub pushes,
uploads) do not run when an agent calls them. They wait for
appfactory approve <id>in your terminal. - Dry run by default for deploys, repo creation, uploads and issue writes.
- Secrets stay local and are scrubbed from every tool result.
- Untrusted content (App Store listings, reviews) is labelled as data, not instructions.
Full threat model and limits: SECURITY.md.
How a run works
- Interview. Before any work the agent calls
run_options(), asks you about every optional part, and saves your answers. Anything you turn off is skipped. - Pipeline with gates.
scaffold, design, features, backend, store setup, localize, analytics, ASO, metadata, screenshots, TestFlight. A stage is done only whenpipeline_markpasses its gate; blockers stop the run with aNEEDS_HUMAN.md. - You submit. App Store submission is always human, in the App Store Connect web UI.
Docs
- docs/SETUP.md: credentials and per-app choices
- docs/PIPELINE_PLAYBOOK.md: the why, order and gotchas of every stage
- docs/TOOLS.md: every tool (generated)
- CONTRIBUTING.md, SECURITY.md, AGENTS.md
License
Release files for appfactory 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| appfactory-0.1.0.tar.gz | 795.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| appfactory-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.5 MB
Release files / appfactory-0.1.0.tar.gz
| Download URL | appfactory-0.1.0.tar.gz |
|---|---|
| Size | 795.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
54b3530f3b50619e4f5c4ac771ca74678b43b300153b899fac7e86034ccd1b6e
|
|
BLAKE2b-256 checksum How to use checksums |
2042699f1dddb0d04862f10cb432f84cc0bdb9279ad309e00ec7e1ac73a58eea
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency logRelease files / appfactory-0.1.0-py3-none-any.whl
| Download URL | appfactory-0.1.0-py3-none-any.whl |
|---|---|
| Size | 717.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9202abdd455b67ee9203e33eafebc928a72e018c49b1ccb0df714558349ea77e
|
|
BLAKE2b-256 checksum How to use checksums |
6dc2e7bfbb3fe30635b4e1c44c01b92daf39b3fec87a76e6845e248dfe24e826
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency log