Which App Store Connect key role TakeOff needs
Give the key App Manager access. It is the smallest role that lets TakeOff write to App Store Connect. A Developer key can only read, and an Admin key works but can also manage users and agreements, which TakeOff never needs.
What each role can do in TakeOff
| Task | Developer | App Manager | Admin |
|---|---|---|---|
| Read app and version metadata | ✓ | ✓ | ✓ |
| Push store text to a version | — | ✓ | ✓ |
| Upload screenshots | — | ✓ | ✓ |
| Attach a build to a version | — | ✓ | ✓ |
| Submit for review | — | ✓ | ✓ |
What happens with a smaller role
If the key’s role is too small, Apple answers with 403 and TakeOff shows “This key does not have the access TakeOff needs”. Generate a new key with App Manager access and add the new .p8 file; you cannot change the role of an existing key.
One key per Mac
A key is not tied to a machine, but naming one per Mac lets you revoke a single machine later. Removing a key in TakeOff under Settings › Keys only forgets it on that Mac; it stays active at Apple until you revoke it in App Store Connect.