asc-workflow
rorkai/app-store-connect-cli-skills
Define and run multi-step iOS app automation workflows with validation, resumption, and safe TestFlight/App Store releases.
What is asc-workflow?
asc-workflow enables lane-style automation for iOS app distribution via repo-local `.asc/workflow.json` files. Use it to orchestrate complex release and TestFlight workflows with step outputs, conditional execution, retry policies, and resumable runs.
- Validate workflow structure and references with `asc workflow validate`
- Run multi-step workflows with `asc workflow run`, supporting dry-run and resume modes
- Extract and reference step outputs using JSON path selectors (e.g., `${steps.step_name.OUTPUT_NAME}`)
- Define conditional steps based on environment variables or runtime parameters
- Configure retry policies and per-step timeouts for safe command repetition
- Support sub-workflow calls with environment variable overrides via `with`
How to install asc-workflow
npx skills add https://github.com/rorkai/app-store-connect-cli-skills --skill asc-workflow- asc CLI installed and authenticated (`asc auth status`)
- `.asc/workflow.json` file in the repository root or custom path
How to use asc-workflow
- 1.Author `.asc/workflow.json` with workflow definitions, steps, and environment variables
- 2.Run `asc workflow validate` to check syntax and step references
- 3.Use `asc workflow list` to discover available workflows
- 4.Execute `asc workflow run --dry-run <name>` to preview without side effects
- 5.Run `asc workflow run <name> [KEY:VALUE ...]` with runtime parameters to execute
- 6.If a step fails and supports retry, resume with `asc workflow run <name> --resume <run-id>`
Use cases
- Automate TestFlight beta distribution by resolving latest builds and adding them to test groups
- Stage and submit App Store releases with validation, metadata, and review submission in one workflow
- Resume interrupted releases using persisted run state and output checkpoints
- Parameterize workflows for different environments (beta, release, staging) from the CLI
- Implement safety gates with dry-run preview before executing mutating operations
- iOS app developers automating release pipelines
- DevOps engineers managing App Store Connect integrations
- Teams using `asc` CLI for build distribution and review submission
asc-workflow FAQ
Declare `outputs` on a `run` step with a JSON path selector (e.g., `"outputs": {"BUILD_ID": "$.data.id"}`), then reference it as `${steps.step_name.BUILD_ID}` in subsequent steps. The command must emit JSON on stdout.
Yes, add `"if": "VAR_NAME"` to a step. It runs only if the variable is truthy (1, true, yes, y, on). The lookup checks merged workflow env/params first, then the process environment.
If the step has `retry` configured, it will retry up to `max_attempts` times with a fixed delay. Otherwise, the workflow stops and the run ID is saved for resumption. Use `asc workflow run <name> --resume <run-id>` to continue from the last successful checkpoint.
Use `asc workflow run <name> KEY:VALUE` or `KEY=VALUE` syntax. Parameters override workflow env variables and are accessible in shell commands via `$KEY` expansion.
Yes, use a `workflow` step to call a sub-workflow. You can override its environment variables with the `with` field, and the caller's env/params take precedence over the sub-workflow's defaults.
Full instructions (SKILL.md)
Source of truth, from rorkai/app-store-connect-cli-skills.
name: asc-workflow
description: Define, validate, run, resume, and audit repo-local multi-step automations with current asc workflow and .asc/workflow.json, including step outputs and safe release/TestFlight workflows.
asc workflow
Use this skill when you need lane-style automation inside the CLI using:
asc workflow validateasc workflow listasc workflow run
Workflows are repo-local automation files. They run trusted shell commands, stream step output to stderr, and keep stdout as machine-readable JSON.
Command discovery
Always verify flags with:
asc workflow --help
asc workflow validate --help
asc workflow list --help
asc workflow run --help
End-to-end flow
- Author
.asc/workflow.json. - Validate structure and references:
asc workflow validate
- Discover public workflows:
asc workflow list
asc workflow list --all
- Preview execution:
asc workflow run --dry-run beta BUILD_ID:123456789 GROUP_ID:abcdef
- Execute:
asc workflow run beta BUILD_ID:123456789 GROUP_ID:abcdef
- If a recoverable run fails, resume with the run ID from the JSON result:
asc workflow run release --resume "release-20260312T120000Z-deadbeef"
Do not pass extra KEY:VALUE params with --resume; the saved workflow file, params, and persisted outputs are reused.
File location and format
- Default path:
.asc/workflow.json - Override path:
asc workflow run --file ./path/to/workflow.json <name> - JSONC comments are supported.
- Top-level hooks:
before_all,after_all,error - Workflow keys:
description,private,env,steps - Step forms:
- string shorthand:
"echo hello" runshell commandworkflowsub-workflow callnamelabelifconditional var namewithenv overrides for workflow-call stepsoutputsmap for JSON stdout extraction from named run stepsretryfixed-delay retry policy for arunsteptimeoutpositive per-attempt duration for arunstep
- string shorthand:
Outputs
Run steps can declare outputs. The command must emit JSON on stdout, so pass --output json for asc commands that produce outputs.
Output references use:
${steps.step_name.OUTPUT_NAME}
Rules:
- A step that declares
outputsmust have a reference-safename. - Outputs are allowed on
runsteps, not workflow-call steps. - Output-producing names must be unique across workflows that can execute together in the same run graph.
- Persisted outputs are stored in workflow run state, so do not map secrets into outputs.
Bounded retry and timeout
Add retry only to commands you have determined are safe to repeat. The runner does not classify commands or retry mutations on its own.
{
"name": "resolve_build",
"run": "asc builds info --app $APP_ID --latest --platform IOS --output json",
"retry": {
"max_attempts": 3,
"delay": "5s"
},
"timeout": "2m"
}
retry.max_attempts counts the first attempt and must be between 2 and 100. Retry delays and timeouts must be positive durations no longer than 24 hours. Both fields work only on run steps, not workflow calls or lifecycle hooks.
A timeout without retry is terminal because the command may have completed remotely. Pairing retry and timeout is the explicit signal that another attempt is safe. Resume requires either a successful checkpoint or a retry-enabled failed step; output-extraction failures cannot be resumed.
Runtime params
asc workflow run <name> [KEY:VALUE ...] supports both separators:
asc workflow run beta VERSION:2.1.0
asc workflow run beta VERSION=2.1.0
Repeated keys are last-write-wins. In shell commands, reference params through shell expansion like $VERSION.
Env precedence
Main workflow run:
definition.env < workflow.env < CLI params
Sub-workflow call with with:
sub-workflow env < caller env and params < step with
Conditionals
Add "if": "VAR_NAME" to a step. Truthy values are 1, true, yes, y, and on, case-insensitive. Lookup checks merged workflow env/params first, then process environment.
Example workflow
{
"env": {
"APP_ID": "123456789",
"VERSION": "1.0.0",
"GROUP_ID": ""
},
"before_all": "asc auth status",
"after_all": "echo workflow_done",
"error": "echo workflow_failed",
"workflows": {
"beta": {
"description": "Resolve the latest build and distribute it to TestFlight",
"steps": [
{
"name": "resolve_build",
"run": "asc builds info --app $APP_ID --latest --platform IOS --output json",
"outputs": {
"BUILD_ID": "$.data.id"
}
},
{
"name": "list_groups",
"run": "asc testflight groups list --app $APP_ID --limit 20 --output json"
},
{
"name": "add_build_to_group",
"if": "GROUP_ID",
"run": "asc builds add-groups --build-id ${steps.resolve_build.BUILD_ID} --group $GROUP_ID"
}
]
},
"release": {
"description": "Validate, stage, and submit an App Store version",
"steps": [
{
"name": "validate",
"run": "asc validate --app $APP_ID --version $VERSION --platform IOS --output json"
},
{
"name": "stage",
"run": "asc release stage --app $APP_ID --version $VERSION --build-id $BUILD_ID --metadata-dir ./metadata/version/$VERSION --confirm --output json"
},
{
"name": "submit",
"if": "SUBMIT_FOR_REVIEW",
"run": "asc review submit --app $APP_ID --version $VERSION --build-id $BUILD_ID --confirm --output json"
}
]
},
"publish-appstore": {
"description": "High-level upload plus App Store review submission",
"steps": [
{
"name": "publish",
"run": "asc publish appstore --app $APP_ID --ipa ./build/MyApp.ipa --version $VERSION --wait --submit --confirm --output json"
}
]
}
}
}
Useful invocations
asc workflow validate | jq -e '.valid == true'
asc workflow list --pretty
asc workflow list --all --pretty
asc workflow run --dry-run beta BUILD_ID:123 GROUP_ID:grp_abc
asc workflow run beta BUILD_ID:123 GROUP_ID:grp_abc | jq -e '.status == "ok"'
asc workflow run release BUILD_ID:123 SUBMIT_FOR_REVIEW:true
asc workflow run release --resume "release-20260312T120000Z-deadbeef"
Safety rules
- Treat
.asc/workflow.jsonlike code; only run trusted workflow files. - Avoid running workflows from untrusted PRs with secrets.
- Keep workflow files in version control.
- Validate first, dry-run next, then run.
- Use explicit IDs and
--confirmfor mutating steps. - Use
asc validate,asc release stage,asc review submit, andasc publish appstore; do not use removed submission commands.
Related skills
More from rorkai/app-store-connect-cli-skills and the wider catalog.

asc-xcode-build
Build, archive, and export Xcode projects for App Store Connect, TestFlight, and device testing.

asc-app-create-ui
Automate App Store Connect app creation via browser UI when no public API is available.

asc-apple-ads
Manage Apple Ads campaigns, targeting, and reports via asc CLI with Platform API v1 and legacy v5 support.

asc-aso-audit
Run offline ASO audits on App Store metadata and surface keyword gaps using Astro MCP.

app-planner
Plans macOS apps and analyzes existing projects with comprehensive architecture and design documents.

rsbuild-best-practices
Configure, review, and optimize Rsbuild applications with build, dev, and bundle best practices.