FunnelHound / Guides / API Key ID
App Store Connect API Key ID: where to find it
Fast answer: the Key ID is the 10-character code in the "Key ID" column of the Team Keys table, at App Store Connect → Users and Access → Integrations → App Store Connect API. It looks like 2X9R4HXF34. The same ten characters are baked into the private key file Apple gave you, AuthKey_2X9R4HXF34.p8. Every key has its own, and the rest of this page covers the cases where the table isn't showing it.
Click-path to the Key ID
- 1. Sign in at appstoreconnect.apple.com and open Users and Access.
- 2. Click the Integrations tab.
- 3. Choose App Store Connect API in the sidebar.
- 4. Stay on Team Keys, or switch to Individual Keys for a personal key.
- 5. Each row is one key. The Key ID column holds the ten characters you're after. Copy, paste, move on.
Nothing to generate and nothing to download at this step: an active key keeps showing its Key ID for as long as it exists. Only the private key file is a one-time event, and that's a different column entirely.
Lost track of which .p8 goes with which key? Read the filename
At download time Apple names the private key after its Key ID: AuthKey_2X9R4HXF34.p8. Three keys in a folder means three filenames and zero guessing. Match the suffix to the row in the table and you know exactly which key that file unlocks. Rename the file and you throw that breadcrumb away, so leave it alone.
What the Key ID does inside a request
Every call to the App Store Connect API carries a signed token (a JWT). Apple needs two things from that token before it bothers checking the signature: which key signed it, and which team owns the key. The Key ID answers the first question, in the token header as kid. The Issuer ID answers the second, in the payload as iss.
| Token part | Field | Value |
|---|---|---|
| Header | kid | 2X9R4HXF34 (your Key ID) |
| Header | alg | ES256 |
| Payload | iss | 57246542-96fe-1a63-e053-0824d011072a (your Issuer ID) |
| Payload | aud | appstoreconnect-v1 |
Apple takes the kid, looks up the public half of that key on its side, and verifies your signature against it. Wrong Key ID means wrong public key, which means a 401 that tells you nothing. So the Key ID is not a password. It's the label Apple uses to decide which lock your .p8 is supposed to open.
One key, one Key ID
Generate a second key and you get a second Key ID. Revoke a key and its Key ID dies with it; Apple never hands the same string out again. That's the part people miss when rotating keys: swapping the .p8 file is half the job, and the other half is updating the Key ID in every config that referenced the old one. The three values (Key ID, Issuer ID, .p8) travel together. The first two are identifiers you could print on a billboard without much harm; the file is the secret, and it downloads exactly once.
Four Apple IDs that look alike
- Key ID: 10 characters, one per API key. Team Keys table, and the AuthKey_ filename.
- Team ID: also 10 characters, one per developer account. Found on developer.apple.com under Membership details. Used for signing, entitlements and associated domains, never for the API token. Full map in the Team ID guide.
- Issuer ID: a UUID, one per team, shared by all of that team's keys. Sits at the top of the same API page. Details in the Issuer ID guide.
- Vendor Number: digits only, one per team. Lives in Payments and Financial Reports and goes into sales report requests.
The Key ID versus Team ID mix-up is the costly one. Same length, same uppercase alphanumeric alphabet, both labelled "ID" in Apple's own tools. Paste a Team ID into kid and the API rejects the token without saying which of the ten characters it disliked. If a tool asks for a Key ID and you're reading it off the Membership page, you're on the wrong site.
Key ID not showing? Four things to check
- Your role. Team Keys are visible to Admin users and the Account Holder. Any other role sees an empty Integrations tab, or no tab at all.
- Individual key. A personal key is listed only for the user who created it. Someone else's individual key will never appear in your view.
- Revoked. Revoked keys drop out of the table. If a tool still references a Key ID you can't find, that key is probably gone and needs replacing.
- Wrong team. Member of several teams? Check the team switcher in the top-right corner before concluding the key doesn't exist.
And if the table is empty because nobody has made a key yet, the API key setup guide walks through generating one, choosing a role and surviving the single .p8 download.
Where the Key ID gets pasted
fastlane's app_store_connect_api_key(key_id: "2X9R4HXF34", issuer_id: "YOUR-ISSUER-ID", key_filepath: "AuthKey_2X9R4HXF34.p8"); CI secrets in Xcode Cloud or GitHub Actions; RevenueCat and most analytics tools that read from Apple. FunnelHound asks for the Key ID once, together with the Issuer ID and the .p8, then keeps the bundle in your iPhone's Keychain, so you never type the ten characters again.
Key ID in hand? The funnel is three fields away
Key ID, Issuer ID, .p8: FunnelHound takes those once and shows impressions, taps, installs and deletions for every app on your iPhone, pulled straight from Apple.
Get FunnelHoundData notes: paths, column names and the AuthKey_ filename pattern verified against App Store Connect and Apple's App Store Connect API documentation as of 2026. 2X9R4HXF34 and the UUID are Apple's documentation samples; the other identifiers in the figures are made up for illustration. If the tabs have been rearranged since, the search field inside Users and Access gets you to the keys page anyway.