Mac App Store¶
- ID
mas- Link
- Upstream stars
⭐ 12,364
- Last commit
2026-08-25
- Version requirement
>= 7
- Cooldown
✓
- Platforms
🍎 macOS
- Operations
installed·outdated·search·install·upgrade·upgrade_all·remove- purl types
pkg:mas/- CLI name
mas- Issues and PRs
- Source
mas drives the Mac App Store from the command line.
Packages are Mac App Store applications, keyed by the numeric adamID Apple
assigns each title (the id in an App Store link). mpm reads and writes
that ID; the display name rides along only as a label.
Every query reads --json output, the supported programmatic interface
since the >=7.0.0 floor added --json to list, outdated and
search.
Note
mas self-escalates: it asks for root itself when a store mutation
needs it, so mpm never wraps install, upgrade or uninstall in
its own sudo.
What mpm adds to mas¶
Through mpm, mas gains --exact and --extended search, to narrow to exact names or match descriptions.
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover mas alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your mas commands, in mpm¶
You already know mas: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
|
|
Remove a package |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✅ |
|
|
✅ |
|
|
||
|
✅ |
Exact and extended search backfilled by |
|
✅ |
|
|
✅ |
|
|
✅ |
|
|
✅ |
|
|
||
|
||
|
Configuration¶
Ignore
mason thempmCLI by passing the--no-masoption.Ignore it for every run in your configuration:
[mpm] mas = false
Raise the timeout of all
mascalls:[mpm.overrides.mas] timeout = 900
Run
mpm config-template masto print all overridable settings for your configuration file:[mpm.overrides.mas] cli_names = [ "mas", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [] pre_cmds = [] requirement = ">=7.0.0" stop_on_error = false unmaintained = false version_cli_options = [ "version", ] version_regexes = [ "(?P<version>\\S+)", ]
Recipes¶
A few jobs you would otherwise script around mas, one mpm command each:
Snapshot and clone a machine:
mpm --mas dump mas.toml, thenmpm restore mas.tomlon the next one.Export a Brewfile entry instead:
mpm --mas dump --brewfile Brewfile.Export a compliance SBOM:
mpm --mas sbom(CycloneDX by default,--spdxfor SPDX).
Privilege escalation¶
mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.
None of its operations is privileged.
See privilege escalation for the full policy.
Cooldown¶
mpm enforces its release-age cooldown on Mac App Store with its own per-package probe: before an install or upgrade, it reads the publication date of the package’s latest release and holds back any release younger than the window (mpm --cooldown 7 --mas upgrade --all skips anything published in the last 7 days): a guard against a compromised or yanked fresh release landing before anyone notices.
Status: ✅ Enforced (
mpmper-app probe)Mechanism: App Store
currentVersionReleaseDateread bymas lookup --json, each too-fresh app heldReference: iTunes Search API
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: Mac App Store
Publish date: ✅ server-set
currentVersionReleaseDatein the catalog recordmas lookup --jsonrelays, stamped when a reviewed version goes live: the clock ofmpm’s per-app probe (iTunes Search API)
Reference traces¶
A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Mac App Store well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ mas list --json
{"adamID":1569813296,"bundleID":"com.1password.1password-safari","name":"1Password for Safari","version":"2.3.5"}
{"adamID":1295203466,"bundleID":"com.microsoft.rdc.macos","name":"Microsoft Remote Desktop","version":"10.7.6"}
{"adamID":409183694,"bundleID":"com.apple.iWork.Keynote","name":"Keynote","version":"12.0"}
$ mas outdated --json
{"adamID":409183694,"name":"Keynote","newVersion":"12.0","version":"11.0"}
{"adamID":1176895641,"name":"Spark","newVersion":"2.11.21","version":"2.11.20"}
Version check¶
The version is extracted from the output of mas version with:
r"(?P<version>\S+)"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Gate the Mac App Store under
--cooldownwith the same per-app probe, reading each app’s release date frommas lookup --json.
6.5.0(2026-05-25)Bump minimum required
masversion from1.8.7to7.0.0, switchinstalled,outdated, andsearchto parse--jsonoutput, updatehomepage_urltohttps://github.com/mas-cli/mas, and drop the explicitsudowrapper aroundmas uninstall.
5.19.0(2024-11-14)Implement
removeoperation.Bump minimal requirement to
1.8.7.Reactivate
mastests.
5.3.0(2022-06-25)Fix parsing of variable-length output in
installedandoutdatedoperations.
3.1.0(2020-04-02)Retrieve version in search results.
Bump minimal version to
1.6.1.
2.4.0(2017-01-28)Fix upgrade of
maspackages. Closes #32.
1.10.0(2016-10-04)Let
masreport its own version.Bump minimal requirement of
masto 1.3.1.Fetch currently installed version from
mas. Closes #4.Fix parsing of
maspackage versions after the 1.3.1 release.
1.5.0(2016-07-25)Add support for
mas.