Get started

Connect an Apple Ads account

Provision Apple Ads API credentials, paste them in, import your orgs, and run the first sync.

Connecting an account takes four steps: create API credentials in Apple Search Ads, paste them into Tap & Scale, import the orgs you want, and let the first sync run. Apple offers no OAuth consent screen for the Campaign Management API, so the credential step is a manual paste — an agent can drive everything around it, but a human provisions the key.

You need the Account Admin or API role in Apple Search Ads to create API credentials.

1. Create API credentials in Apple Search Ads

In the Apple Search Ads UI, open Account Settings → API and create an API certificate. Apple gives you three identifiers and you generate one private key:

Prop

Type

The private key must be a P-256 (prime256v1) EC key in PKCS#8 PEM form — it begins with -----BEGIN PRIVATE KEY-----. If yours begins with -----BEGIN EC PRIVATE KEY----- (SEC1), convert it:

openssl pkcs8 -topk8 -nocrypt -in ec-key-sec1.pem -out apple-ads-key.pem

2. Paste the credentials

Open Workspace → Settings → Integrations → Apple Ads and paste clientId, teamId, keyId, and the PEM. On save, the app validates the shape, confirms the key can sign an ES256 assertion, and calls Apple's GET /acls to verify access.

Credentials are stored as one encrypted blob (AES-256-GCM); only the non-secret identifiers are kept in the connection status row. The private key is never returned to the browser or written to logs.

One credential set grants access to every org your Apple Ads API role can reach. Scope the API role in Apple Search Ads if you want to limit that.

3. Discover and import orgs

Once connected, discover the orgs available to your credential and import the ones you want to manage. Each imported org becomes one account, keyed by its Apple Ads org id (the value sent as X-AP-Context: orgId on every Apple call). An org can advertise several apps; apps live on campaigns, not on the account.

If you're driving setup over MCP, the flow is asa_discover_ad_accounts → asa_import_ad_account (takes asaOrgId). See the MCP Reference → Setup & sync.

4. Run the first sync

Importing an account queues a sync. Watch its status until data lands — the first run does a 14-day backfill. Reads warn when data is older than 24 hours, so let the initial sync finish before you act on numbers.

Next step

On this page