One API key for Apple, one invited email for Google, and nothing posts to a store until you approve it. The exact console clicks, which role to pick, what each level unlocks, and what your workspace shows the moment a store connects.
Connecting a store to Uprate means one thing per store: an App Store Connect API key for Apple, and an invited email address for Google Play. No Google Cloud project, no JSON file, no shared login. Both credentials are created in consoles you already use, and both can be revoked there in one click.
Budget five minutes for Apple, five for Google, and five to pick your apps and tell Uprate what to work on. The one part you do not control is Google applying a new invite, which is why Google comes second.
What you need before you open Uprate
| App Store Connect | Google Play Console | |
|---|---|---|
| Who can do it | A user with the Admin role, or the Account Holder. That is who can create Team keys. | The account Owner, or an Admin who can invite users. |
| What you create | A Team API key with the Admin role, downloaded as a .p8 file. |
Nothing. You invite an email address that Uprate gives you. |
| What you copy | The Issuer ID from the same page. | The service account email from Uprate. |
| What it unlocks | Reviews, replies, listing, pricing, submissions, TestFlight, analytics. | Reviews, replies, listing, in-app pricing, releases, crashes and ANRs. |
If you are not the person with that access, the whole setup is a two-message exchange: ask for a .p8 plus the Issuer ID, and ask for the invite. Uprate cannot request, read or change permissions in either console. You grant them, and you can see exactly what was granted at every step.
App Store Connect: one Team key
In App Store Connect, open Users and Access, then the Integrations tab, then App Store Connect API. Under Team Keys, generate a new key. Name it so you recognise it later, for example Uprate, and choose the Admin role.
Download the .p8 file and copy the Issuer ID shown above the list of keys.
Apple shows the .p8 once There is no second download. If the file is lost, revoke the key and generate a new one. Uprate reads the Key ID from the filename, so keep the name Apple gave it:
AuthKey_ABC123DEFG.p8.
Back in Uprate, drop the file into the App Store Connect panel, paste the Issuer ID, and confirm the Key ID that Uprate filled in from the filename. Uprate then checks what the key can actually do and shows the result capability by capability. Reviews start syncing the moment the check passes.
Which role you pick decides what Uprate can do. Every Team key sees every app in the account, so the role is the only lever.
| Customer Support | Admin | Admin + Vendor Number | |
|---|---|---|---|
| Reviews and replies | Yes | Yes | Yes |
| Store listing and ASO | No | Yes | Yes |
| Pricing and in-app purchases | No | Yes | Yes |
| Submissions, releases, TestFlight | No | Yes | Yes |
| Analytics | No | Yes | Yes |
| Sales reports | No | No | Yes |
Customer Support is enough if all you want is the review inbox. Anything else needs Admin, and the check in Uprate tells you which rows a narrower key misses rather than failing outright. You can keep the narrow key for what it reaches and replace it later.
Individual keys. Apple also issues keys tied to one user rather than the team. They inherit that user's role and app access, have no Issuer ID, and cannot touch Sales and Finance or Expo signing credentials. Use one when you need the key limited to selected apps and your role allows per-app scoping. If the button to generate it is missing from your profile, your Account Holder has to enable individual key access for you first.
Google Play: invite an email, skip the JSON
Google's usual route to an API connection is a Cloud project, an enabled API, a service account and a downloaded JSON key. Uprate runs that part for you. When you open the Google Play panel, it prepares a service account for your workspace and shows you its email address with a copy button.
In Play Console, open Users and permissions and invite a new user with that email. On the App permissions tab, add only the apps Uprate should see and give them Admin (all permissions). Account-level permissions can stay empty. Send the invite, return to Uprate and press Check again.
Google can take up to 24 hours to apply a new invite A failed check right after inviting is almost always propagation, not a wrong setting. Uprate keeps checking in the background after you leave the page, and the apps appear on their own once the grant lands. Most invites land in minutes; plan for the day, not the hour.
Three consequences of doing it this way. The service account belongs to your workspace, so the same email works in every Play developer account you manage, which matters for agencies. Nothing is uploaded from your machine, so there is no key file to store or rotate. And because you choose apps in the invite, the account never sees anything you did not name.
| Reviews only | Full access to selected apps | Plus global reports | |
|---|---|---|---|
| Reviews and replies | Yes | Yes | Yes |
| Store info, listing and ASO | No | Yes | Yes |
| In-app and subscription prices | No | Yes | Yes |
| Test and production releases | No | Yes | Yes |
| Crashes and ANRs | No | Yes | Yes |
| Sales reports | No | No | Yes |
"Reviews only" is the Reply to reviews permission on the app. Sales reports need account-level financial access plus a reports bucket, and Google includes every app in financial reports, which is why that column is separate.
Your app's base price is not on the list on purpose. It stays in Play Console. Uprate manages in-app and subscription prices only, and only with your approval. What those products are and how the two stores price them is covered in What is an in-app purchase?.
What the connection reads, acts on and never touches
Reads: reviews and ratings, store listing, pricing configuration, and sales and finance reports if you added a Vendor Number or a reports bucket.
Acts, after you approve it: replies to reviews, build submissions and releases. Store listing updates are coming.
Never: legal agreements, tax and banking, your Apple ID or Google login. Only your Account Holder can sign an agreement or change banking details, and no API key changes that. Credentials are encrypted at rest, and revoking the key in App Store Connect or removing the user in Play Console cuts Uprate off instantly.
Automatic replies are off by default. Drafts stay inside Uprate until you publish them, and if you later switch automatic replies on, they go out after the delay you set in your review settings. The tone those drafts learn from is yours; review response examples and templates shows what good ones look like.
The first fifteen minutes after connecting
With one account-level key per store, Uprate lists every app the credential can reach, so the next step is a checklist rather than a search. Pick the apps you want in the workspace, then choose what to work on first: replying to reviews, preparing submissions or improving the listing.
Your workspace is ready while the review import is still running. The screen shows reviews read so far, drafts already prepared, and the current App Store and Google Play ratings, and it keeps updating while you look around. A large back catalogue takes longer than the first screen; it does not block you.
Two optional connections sit alongside the stores. GitHub, for builders who want Uprate to work with their code, and revenue reports: a Vendor Number from Payments and Financial Reports in App Store Connect, and a Cloud Storage bucket name from Download reports in Play Console, the pubsite_prod_rev_ part of the URI. Both can be added later from Settings.
When a check does not pass
| What you see | What it means | What to do |
|---|---|---|
| This key works, but it is missing some access | The role is narrower than Admin. | Keep it for what it reaches, or recreate the key with Admin. |
| New keys can take a minute to activate | Apple has not switched the key on yet. | Wait a moment and re-test. |
| We could not validate this key | The Key ID, Issuer ID or app ID does not match, or API access is off. | Check all three against the Integrations page. The Key ID is the part of the filename after the underscore. |
| Permissions are still propagating | Google has not applied the invite yet. | Leave it. Uprate re-checks on its own; come back when Google has caught up. |
| Connected, but Uprate cannot do everything yet | The invite covered fewer permissions than Admin. | Fine if intentional. Otherwise add the missing app permissions in Play Console. |
| This key cannot see any apps yet | An Individual key without app access, or an invite with no apps selected. | Add the apps in the console. Uprate picks them up on the next check. |
You can also start with nothing connected
Both stores are skippable during setup. Uprate finds your apps through public search, one search covers both stores, and reads what is public. Replies, submissions and the real numbers wait until a store is connected, and the connect flow is the same from Settings as it is during onboarding.
That is the whole setup. Once both stores are in, the daily loop described in How to run both stores without a dedicated ops hire runs from one inbox.
Was this article helpful?
