FunnelHound / Guides / API Key ID

App Store Connect API Key ID: where to find it

Fast answer: the Key ID is the 10-character code in the "Key ID" column of the Team Keys table, at App Store Connect → Users and Access → Integrations → App Store Connect API. It looks like 2X9R4HXF34. The same ten characters are baked into the private key file Apple gave you, AuthKey_2X9R4HXF34.p8. Every key has its own, and the rest of this page covers the cases where the table isn't showing it.

Team Keys Users and Access · Integrations · App Store Connect API NAME KEY ID ACCESS CREATED Analytics (FunnelHound) 2X9R4HXF34 Sales and Reports Mar 3, 2026 CI (fastlane) 7K3PQ2M9ZD App Manager Jan 19, 2026 AuthKey_2X9R4HXF34.p8
The Key ID column in the Team Keys table, and the same ten characters repeated in the .p8 filename.

Click-path to the Key ID

Nothing to generate and nothing to download at this step: an active key keeps showing its Key ID for as long as it exists. Only the private key file is a one-time event, and that's a different column entirely.

Lost track of which .p8 goes with which key? Read the filename

At download time Apple names the private key after its Key ID: AuthKey_2X9R4HXF34.p8. Three keys in a folder means three filenames and zero guessing. Match the suffix to the row in the table and you know exactly which key that file unlocks. Rename the file and you throw that breadcrumb away, so leave it alone.

What the Key ID does inside a request

Every call to the App Store Connect API carries a signed token (a JWT). Apple needs two things from that token before it bothers checking the signature: which key signed it, and which team owns the key. The Key ID answers the first question, in the token header as kid. The Issuer ID answers the second, in the payload as iss.

Token partFieldValue
Headerkid2X9R4HXF34 (your Key ID)
HeaderalgES256
Payloadiss57246542-96fe-1a63-e053-0824d011072a (your Issuer ID)
Payloadaudappstoreconnect-v1

Apple takes the kid, looks up the public half of that key on its side, and verifies your signature against it. Wrong Key ID means wrong public key, which means a 401 that tells you nothing. So the Key ID is not a password. It's the label Apple uses to decide which lock your .p8 is supposed to open.

One key, one Key ID

Generate a second key and you get a second Key ID. Revoke a key and its Key ID dies with it; Apple never hands the same string out again. That's the part people miss when rotating keys: swapping the .p8 file is half the job, and the other half is updating the Key ID in every config that referenced the old one. The three values (Key ID, Issuer ID, .p8) travel together. The first two are identifiers you could print on a billboard without much harm; the file is the secret, and it downloads exactly once.

Four Apple IDs that look alike

Key ID 2X9R4HXF34 10 characters · one per API key Lives in: Team Keys table, AuthKey .p8 filename Team ID A1B2C3D4E5 10 characters · one per developer account Lives in: developer.apple.com, Membership Issuer ID 57246542-96fe-1a63-e053-0824d... UUID · one per team, shared by all keys Lives in: top of the API keys page Vendor Number 88123456 Digits only · one per team Lives in: Payments and Financial Reports
Same vocabulary, four different jobs. The Key ID and Team ID share a format, which is where most mix-ups start.

The Key ID versus Team ID mix-up is the costly one. Same length, same uppercase alphanumeric alphabet, both labelled "ID" in Apple's own tools. Paste a Team ID into kid and the API rejects the token without saying which of the ten characters it disliked. If a tool asks for a Key ID and you're reading it off the Membership page, you're on the wrong site.

Key ID not showing? Four things to check

And if the table is empty because nobody has made a key yet, the API key setup guide walks through generating one, choosing a role and surviving the single .p8 download.

Where the Key ID gets pasted

fastlane's app_store_connect_api_key(key_id: "2X9R4HXF34", issuer_id: "YOUR-ISSUER-ID", key_filepath: "AuthKey_2X9R4HXF34.p8"); CI secrets in Xcode Cloud or GitHub Actions; RevenueCat and most analytics tools that read from Apple. FunnelHound asks for the Key ID once, together with the Issuer ID and the .p8, then keeps the bundle in your iPhone's Keychain, so you never type the ten characters again.

Key ID in hand? The funnel is three fields away

Key ID, Issuer ID, .p8: FunnelHound takes those once and shows impressions, taps, installs and deletions for every app on your iPhone, pulled straight from Apple.

Get FunnelHound

Share this on X

Data notes: paths, column names and the AuthKey_ filename pattern verified against App Store Connect and Apple's App Store Connect API documentation as of 2026. 2X9R4HXF34 and the UUID are Apple's documentation samples; the other identifiers in the figures are made up for illustration. If the tabs have been rearranged since, the search field inside Users and Access gets you to the keys page anyway.