We are calling these App Store Connect API endpoints from our server:
curl --request POST \
--url https://api.appstoreconnect.apple.com/v1/gameCenterLeaderboardEntrySubmissions \
--header 'Authorization: Bearer JWT_Token' \
--header 'Content-Type: application/json' \
--data '{
"data": {
"type": "gameCenterLeaderboardEntrySubmissions",
"attributes": {
"bundleId": "bundleId",
"score": "1",
"scopedPlayerId": "scopedPlayerId,
"submittedDate": "date",
"preReleased": true,
"vendorIdentifier": "vendorIdentifier"
}
}
}'
curl --request POST \
--url https://api.appstoreconnect.apple.com/v1/gameCenterPlayerAchievementSubmissions \
--header 'Authorization: Bearer JWT_Token' \
--header 'Content-Type: application/json' \
--data '{
"data": {
"type": "gameCenterPlayerAchievementSubmissions",
"attributes": {
"bundleId": "bundleId",
"vendorIdentifier": "vendorIdentifier",
"percentageAchieved": 1,
"scopedPlayerId": "scopedPlayerId,
"submittedDate": "Date",
"preReleased": true
}
}
}'
According to https://developer.apple.com/documentation/appstoreconnectapi/app-store-connect-api-3-2-release-notes We should be able to set player score and achievements.
We use an active Team App Store Connect API key and generate an unscoped ES256 JWT with aud: appstoreconnect-v1. The key has high-level App Store Connect permissions. We followed documentation: https://developer.apple.com/documentation/appstoreconnectapi
Both requests return:
{
"status": "403",
"code": "FORBIDDEN_ERROR",
"title": "This request is forbidden for security reasons",
"detail": "The API key in use does not allow this request"
}
The player is authorised via GameKit on the mobile app. The API key can read:
https://api.appstoreconnect.apple.com/v1/apps/:idhttps://api.appstoreconnect.apple.com/v2/gameCenterLeaderboards/:id.
Which exact App Store Connect API key role or permission is required for these endpoints? Is server-to-server submission supported using a Team API key?