How to create an App Store Connect API key
In App Store Connect, open Users and Access › Integrations › App Store Connect API and generate a Team key with App Manager access. Download the .p8 file, which Apple lets you do only once, and note the Key ID and Issuer ID shown on the same page.
Open Users and Access › Integrations
Sign in to App Store Connect and choose Users and Access, then the Integrations tab and App Store Connect API. The direct address is appstoreconnect.apple.com/access/integrations/api.
Generate a key and name it
Choose Generate API Key and give it a name you will recognise later. A name per Mac, such as “TakeOff — Studio iMac”, makes it easy to revoke one machine without touching the others.
Set Access to App Manager
App Manager is the smallest role that can read and write store texts, upload screenshots, attach builds and submit for review. Developer cannot edit metadata. Admin works, but grants more than TakeOff needs. The key roles guide has the full table.
Download the .p8 file, once
Next to the new key, choose Download. Apple offers the file exactly once, so keep it somewhere safe before you leave the page. Its name is AuthKey_ followed by the Key ID.
Confirm the file is where you expect it:
$ ls ~/Downloads/AuthKey_*.p8Note the Key ID and Issuer ID
The Key ID is shown in the keys table next to the key, and is also part of the file name. The Issuer ID is shown above the table and is the same for every key of your team. TakeOff asks for both when you add the .p8 file.
TakeOff checks the .p8 file on your Mac first, then verifies the key with Apple before storing it in your Keychain.