
PubShip
io.github.pubshipv0.24.0更新于 Oct 7, 2026
Google Play reads and explicitly opted-in operations using your own local Google access.
概览
让助手使用你本地的服务账号凭据,查看并准备对你自己的 Google Play 应用所做的更改。
- 功能
- PubShip 通过 stdio 提供 Google Play 开发者工作流:读取发布版本、评论、Android vitals 和限定范围的批量报告,并查看商品目录、订阅、商品和账号资源。它还能准备和审阅写入操作,需要明确的应用与方法权限,且执行为一次性。读取是默认行为;可选的写入和敏感读取需要显式配置。
- 适用场景
- 当你维护自己的 Google Play 应用,并希望助手从 MCP 客户端汇总发布版本、评论或 vitals,或暂存并审阅分发变更时使用。它仅适用于你或你的组织拥有的应用和开发者账号。
- 运行要求
- 需要能通过 uvx 运行该 PyPI 包的本地 Python 环境,以及一个对你的应用拥有 Play Console 权限的 Google 服务账号。将 GOOGLE_APPLICATION_CREDENTIALS 设为私有服务账号 JSON 的绝对路径,将 GOOGLE_PLAY_PACKAGES 设为你的包名。可用 uvx pubship --check 做无需凭据的检查。
安装
在 SourceWeft 中
- 打开 控制台中的 PubShip,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
PubShip
Google Play developer workflows, from your own computer. Inspect releases, understand reviews and reports, and prepare explicitly authorized changes from your MCP client.
[CI] [Release] [AGPL-3.0-only] [PubShip MCP server – quality and maintenance score on Glama]
Start locally
Use your own service account with permissions for your apps in Play Console. Keep its private JSON outside this repository. Grant only the permissions needed for your intended operations. Never paste credentials into an assistant conversation.
This starts the stdio server, which waits for an MCP client. For a credential-free installation check:
The commands above install the published PyPI package. A source checkout may contain changes that are not yet published; after uv sync, use uv run pubship --check to check the local version.
Connect an assistant
Claude Code
Set the environment variables above in the shell launching your client. Restart the client after changing its environment.
Codex
Cursor and Gemini CLI
Client manifests in this repository declare the local service-account key path and package names. See client setup for configuration and the Gemini CLI installation command. For agent-assisted installation, read llms-install.md. Provide only the key file path, never its contents.
Generic MCP harness
Configure a stdio server with executable uvx, argument pubship, and your local environment. For clients that require explicit configuration:
Client configuration stays on your computer. Consult setup for alternate authentication modes, enabled APIs, reports and permission boundaries.
What can it do?
The pinned inventory contains 172 method definitions. 170 have implementations, one subscription-archive method is unsupported by Google, and voided-purchases access is deliberately disabled by project policy. Disabled operations cannot be called through local or self-host tools.
- Read releases, reviews, Android vitals and scoped bulk reports.
- Inspect catalog, subscription, product and account resources with separate sensitive-data grants.
- Prepare and review writes with explicit app/method permissions and single-use execution.
- Keep local file transfers bounded and separate publication from edit staging.
Reads are the default. Optional writes and sensitive reads require explicit configuration. Provider text is untrusted data. Missing data is not zero; a submitted change is not necessarily published. No operation count is a claim of live Google verification.
Explore the contracts and boundaries
Self-hosting for your own accounts
pubship-server retains the HTTP implementation for infrastructure you control. It refuses to start without PUBSHIP_SERVER_ALLOWED_EMAILS. Sign-in requires a signed Google ID token, a verified exact email match and nonce binding before any Google credentials are persisted. Removing an account from the allowlist invalidates its stored grants on next use. Legacy grants without verified identity must reconnect. Enrollment stays closed until the operator explicitly enables it.
There is no project-run Google-connected service. See the local-first decision and self-host setup.
Development
Tests use fake providers. Browser tests require installed Playwright engines; backup integration tests require age. Record unavailable platform checks honestly. See contribution policy, release process, and security reporting.
Intended use
PubShip helps developers automate their own Google Play distribution work. It runs on your computer or on infrastructure you control, with your own Google credentials and Play Console permissions. The PubShip project does not run a hosted service and never receives your credentials. Use it only for apps and developer accounts that you or your organization own, and follow Google's Play Developer API Terms. Hosted PubShip instances run by others are not provided or endorsed by the PubShip project.
PubShip is an independent open-source project and is not affiliated with, endorsed by, or sponsored by Google. Google, Google Play and Android are trademarks of Google LLC.
License
PubShip is free software under the GNU Affero General Public License v3.0 only (AGPL-3.0-only). Copyright (C) 2026 Denys Vorobyov. For other license terms, contact [email protected].
来源:README.md,提交 7da6b2b
工具
0版本历史
1- v0.24.0最新Oct 7, 2026


