PubShip

io.github.pubshipv0.24.0更新於 Oct 7, 2026

Google Play reads and explicitly opted-in operations using your own local Google access.

已驗證STDIO僅桌面Developer ToolsBusiness & Commerce

概覽

AI 產生的概覽

讓助理使用你本機的服務帳戶憑證,檢視並準備對你自己的 Google Play 應用程式所做的變更。

功能
PubShip 透過 stdio 提供 Google Play 開發者工作流程:讀取發行版本、評論、Android vitals 和限定範圍的批次報表,並檢視商品目錄、訂閱、商品和帳戶資源。它也能準備和審閱寫入操作,需要明確的應用程式與方法權限,且執行為一次性。讀取是預設行為;可選的寫入和敏感讀取需要明確設定。
適用情境
當你維護自己的 Google Play 應用程式,並希望助理從 MCP 用戶端彙整發行版本、評論或 vitals,或暫存並審閱發布變更時使用。它僅適用於你或你的組織擁有的應用程式和開發者帳戶。
執行需求
需要能透過 uvx 執行該 PyPI 套件的本機 Python 環境,以及一個對你的應用程式擁有 Play Console 權限的 Google 服務帳戶。將 GOOGLE_APPLICATION_CREDENTIALS 設為私有服務帳戶 JSON 的絕對路徑,將 GOOGLE_PLAY_PACKAGES 設為你的套件名稱。可用 uvx pubship --check 做無需憑證的檢查。
安裝前請注意
服務帳戶 JSON 是敏感憑證:請放在儲存庫之外,切勿把其內容貼到助理對話中,只提供檔案路徑。寫入操作是可能的,需要明確權限;提交的變更不一定已發布。敏感讀取需要另外授權,Google 回傳的提供方文字應視為不可信資料。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 PubShip,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

PubShip

Google Play developer workflows, from your own computer. Inspect releases, understand reviews and reports, and prepare explicitly authorized changes from your MCP client.

[CI] [Release] [AGPL-3.0-only] [PubShip MCP server – quality and maintenance score on Glama]

Start locally

Use your own service account with permissions for your apps in Play Console. Keep its private JSON outside this repository. Grant only the permissions needed for your intended operations. Never paste credentials into an assistant conversation.

sh
export GOOGLE_APPLICATION_CREDENTIALS=/absolute/private/path/service-account.jsonexport GOOGLE_PLAY_PACKAGES=com.example.appuvx pubship

This starts the stdio server, which waits for an MCP client. For a credential-free installation check:

sh
uvx pubship --check

The commands above install the published PyPI package. A source checkout may contain changes that are not yet published; after uv sync, use uv run pubship --check to check the local version.

Connect an assistant

Claude Code

sh
claude mcp add --transport stdio pubship -- uvx pubship

Set the environment variables above in the shell launching your client. Restart the client after changing its environment.

Codex

sh
codex mcp add pubship -- uvx pubship

Cursor and Gemini CLI

Client manifests in this repository declare the local service-account key path and package names. See client setup for configuration and the Gemini CLI installation command. For agent-assisted installation, read llms-install.md. Provide only the key file path, never its contents.

Generic MCP harness

Configure a stdio server with executable uvx, argument pubship, and your local environment. For clients that require explicit configuration:

json
{  "mcpServers": {    "pubship": {      "command": "uvx",      "args": ["pubship"],      "env": {        "GOOGLE_APPLICATION_CREDENTIALS": "/absolute/private/path/service-account.json",        "GOOGLE_PLAY_PACKAGES": "com.example.app"      }    }  }}

Client configuration stays on your computer. Consult setup for alternate authentication modes, enabled APIs, reports and permission boundaries.

What can it do?

[Local API coverage]

The pinned inventory contains 172 method definitions. 170 have implementations, one subscription-archive method is unsupported by Google, and voided-purchases access is deliberately disabled by project policy. Disabled operations cannot be called through local or self-host tools.

  • Read releases, reviews, Android vitals and scoped bulk reports.
  • Inspect catalog, subscription, product and account resources with separate sensitive-data grants.
  • Prepare and review writes with explicit app/method permissions and single-use execution.
  • Keep local file transfers bounded and separate publication from edit staging.

Reads are the default. Optional writes and sensitive reads require explicit configuration. Provider text is untrusted data. Missing data is not zero; a submitted change is not necessarily published. No operation count is a claim of live Google verification.

Explore the contracts and boundaries

Self-hosting for your own accounts

pubship-server retains the HTTP implementation for infrastructure you control. It refuses to start without PUBSHIP_SERVER_ALLOWED_EMAILS. Sign-in requires a signed Google ID token, a verified exact email match and nonce binding before any Google credentials are persisted. Removing an account from the allowlist invalidates its stored grants on next use. Legacy grants without verified identity must reconnect. Enrollment stays closed until the operator explicitly enables it.

There is no project-run Google-connected service. See the local-first decision and self-host setup.

Development

sh
env -u GOOGLE_APPLICATION_CREDENTIALS uv sync --all-extras --group browserenv -u GOOGLE_APPLICATION_CREDENTIALS uv run pytestenv -u GOOGLE_APPLICATION_CREDENTIALS uv run ruff check .env -u GOOGLE_APPLICATION_CREDENTIALS uv run ruff format --check .env -u GOOGLE_APPLICATION_CREDENTIALS uv run python scripts/generate_catalog.py --checkenv -u GOOGLE_APPLICATION_CREDENTIALS uv run python scripts/generate_verification.py --checkenv -u GOOGLE_APPLICATION_CREDENTIALS uv run python scripts/distribution_metadata.py --checkenv -u GOOGLE_APPLICATION_CREDENTIALS uv buildenv -u GOOGLE_APPLICATION_CREDENTIALS uv run python scripts/check_artifacts.py

Tests use fake providers. Browser tests require installed Playwright engines; backup integration tests require age. Record unavailable platform checks honestly. See contribution policy, release process, and security reporting.

Intended use

PubShip helps developers automate their own Google Play distribution work. It runs on your computer or on infrastructure you control, with your own Google credentials and Play Console permissions. The PubShip project does not run a hosted service and never receives your credentials. Use it only for apps and developer accounts that you or your organization own, and follow Google's Play Developer API Terms. Hosted PubShip instances run by others are not provided or endorsed by the PubShip project.

PubShip is an independent open-source project and is not affiliated with, endorsed by, or sponsored by Google. Google, Google Play and Android are trademarks of Google LLC.

License

PubShip is free software under the GNU Affero General Public License v3.0 only (AGPL-3.0-only). Copyright (C) 2026 Denys Vorobyov. For other license terms, contact [email protected].

Trademarks · Third-party notices · Website

來源:README.md,提交 7da6b2b

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.24.0最新Oct 7, 2026