Provider connections
A connection establishes which identity accesses which platform. It is separate from your Fox Store license, and there is no charge per connection.
Apple App Store
Use an App Store Connect API Key: Issuer ID, Key ID, and a .p8 private key. Create a purpose-specific Key with minimal permissions for Fox Store. The private key is written to local credential storage; the frontend does not retain plaintext long term.
Google Play
Use a Google Cloud Service Account JSON and grant it the necessary app and feature permissions in Play Console. Reading an app does not imply permission to submit Edits, upload packages, or manage testers.
Huawei AppGallery
HarmonyOS uses a Service Account; Huawei Android automated publishing uses an API Client. These credentials are not interchangeable. Project ID, APP ID, and developer resources belong to different contexts. HarmonyOS certificate private keys are generated and stored locally; only the CSR or other required public materials are submitted to the platform.
WeChat Mini Programs
Use the AppID, project path, and private key required by the official local CI. Execution calls local tools; capabilities depend on WeChat's official CI, member permissions, and the local Node environment.
Chinese Android app stores
- Tencent MyApp: main-account User ID and Access Secret, used to update existing apps.
- Honor App Market: Client ID and API Secret, linking existing apps by package name.
- vivo: Access Key and Access Secret for the mainland China open platform; live availability depends on platform authorization.
- Xiaomi App Store: account email, API secret, and the public-key certificate registered with the platform.
- OPPO / HeyTap: Client ID and Client Secret; live availability depends on platform authorization.
Samsung Galaxy Store
Use Samsung Service Account credential JSON and exchange a JWT for an access token. Content ID identifies the app for publishing and status queries.
Pgyer
Use an API Key and User Key. After connecting, access workspaces for apps, versions, distribution settings, feedback, certificates, and multi-format uploads.
Object storage
Alibaba Cloud OSS, Tencent Cloud COS, Amazon S3, and MinIO have independent Provider IDs, endpoints, and credentials, but share a desktop file workspace. Grant access keys only the required Bucket and object permissions. For custom S3/MinIO endpoints, also check TLS, region, and path-style settings.
Deleting connections
Read the prompt before deleting: local connection metadata, private keys, certificates, and associated assets may have different deletion controls. Deleting a Provider connection does not delete apps or resources in the official console unless the operation explicitly says it performs a remote deletion.
