App Store Connect API authorization for Game Center player score and achievement submissions

We are calling these App Store Connect API endpoints from our server:

curl --request POST \
  --url https://api.appstoreconnect.apple.com/v1/gameCenterLeaderboardEntrySubmissions \
  --header 'Authorization: Bearer JWT_Token' \
  --header 'Content-Type: application/json' \
  --data '{
  "data": {
    "type": "gameCenterLeaderboardEntrySubmissions",
    "attributes": {
      "bundleId": "bundleId",
      "score": "1",
      "scopedPlayerId": "scopedPlayerId,
      "submittedDate": "date",
      "preReleased": true,
      "vendorIdentifier": "vendorIdentifier"
    }
  }
}'
curl --request POST \
  --url https://api.appstoreconnect.apple.com/v1/gameCenterPlayerAchievementSubmissions \
  --header 'Authorization: Bearer JWT_Token' \
  --header 'Content-Type: application/json' \
  --data '{
      "data": {
        "type": "gameCenterPlayerAchievementSubmissions",
        "attributes": {
          "bundleId": "bundleId",
          "vendorIdentifier": "vendorIdentifier",
          "percentageAchieved": 1,
          "scopedPlayerId": "scopedPlayerId,
          "submittedDate": "Date",
          "preReleased": true
        }
      }
    }'

According to https://developer.apple.com/documentation/appstoreconnectapi/app-store-connect-api-3-2-release-notes We should be able to set player score and achievements.

We use an active Team App Store Connect API key and generate an unscoped ES256 JWT with aud: appstoreconnect-v1. The key has high-level App Store Connect permissions. We followed documentation: https://developer.apple.com/documentation/appstoreconnectapi

https://developer.apple.com/documentation/appstoreconnectapi/post-v1-gamecenterplayerachievementsubmissions

https://developer.apple.com/documentation/appstoreconnectapi/post-v1-gamecenterleaderboardentrysubmissions

Both requests return:

{
  "status": "403",
  "code": "FORBIDDEN_ERROR",
  "title": "This request is forbidden for security reasons",
  "detail": "The API key in use does not allow this request"
}

The player is authorised via GameKit on the mobile app. The API key can read:

  • https://api.appstoreconnect.apple.com/v1/apps/:id
  • https://api.appstoreconnect.apple.com/v2/gameCenterLeaderboards/:id.

Which exact App Store Connect API key role or permission is required for these endpoints? Is server-to-server submission supported using a Team API key?

App Store Connect API authorization for Game Center player score and achievement submissions
 
 
Q