How to publish to the Microsoft Store from GitHub Actions

Add a step to your workflow that sends the MSIX to Partner Center, with your credentials saved as repository secrets. Microsoft's own action installs the msstore CLI for that, and the StoreFast action does it with one API key and translates your release notes too. Either way, the app's first submission has to be made in Partner Center by hand.

Pick Microsoft's action if your app is free and you're happy keeping listing text in a JSON file. Pick the StoreFast action if you want release notes in every language without writing them, or a review step before anything goes to Microsoft.

  • Microsoft's route is free and uses four secrets from your Microsoft Entra application. App updates through it work for free products only for now.
  • StoreFast's route needs one API key secret. It takes What's new from your changelog or GitHub release and translates it into every listing language.
  • Both need the app to exist already, with its first submission made in Partner Center.
  • After the workflow, the update still goes through certification, which Microsoft says can take up to three business days.

What you need before the workflow runs

  • An app that's already live. Microsoft's GitHub Actions guide lists that as a prerequisite.
  • A Microsoft Entra application with the Manager role in Partner Center, on a tenant that's associated with your developer account. Both routes use one. StoreFast's connection guide walks through creating it.
  • A build that makes the .msix. The version has four numbers, and Microsoft's package rules reserve the last one for the Store, so it has to be 0, like 1.4.0.0.

How to publish with Microsoft's action

Microsoft's action, microsoft/microsoft-store-apppublisher, installs the msstore CLI on the runner. Add these four repository secrets under Settings, Secrets and variables, Actions.

  • AZURE_AD_APPLICATION_CLIENT_ID
  • AZURE_AD_APPLICATION_SECRET
  • AZURE_AD_TENANT_ID
  • SELLER_ID

This is the package workflow from Microsoft's guide. It runs when release/package.msix changes and publishes it to the app with the Store product ID you fill in.

name: AppPackageAutoUpdate

on:
  push:
    paths:
      - 'release/package.msix'

jobs:
  build:
    runs-on: windows-latest

    steps:
      - name: Checkout repository
        uses: actions/checkout@v4

      - name: Configure Microsoft Store CLI
        uses: microsoft/microsoft-store-apppublisher@v1.1

      - name: Reconfigure store credentials
        run: msstore reconfigure `
              --tenantId ${{ secrets.AZURE_AD_TENANT_ID }} `
              --sellerId ${{ secrets.SELLER_ID }} `
              --clientId ${{ secrets.AZURE_AD_APPLICATION_CLIENT_ID }} `
              --clientSecret ${{ secrets.AZURE_AD_APPLICATION_SECRET }}

      - name: Publish App package
        run: msstore publish '${{ github.workspace }}/release/package.msix' -id <Store product Id>

To change listing text such as What's new, the same guide has you run msstore submission get once, save the JSON it prints as metadata/metadata.json, and add a second workflow that sends the file whenever you push a change to it. Every language's text lives in that file, and you write each one yourself.

Two things to know from Microsoft's docs. The msstore CLI is in preview, and app updates through it and through the GitHub action work for free products only, with paid products promised in a future release.

How to publish with the StoreFast action

  1. 1

    Create an API key

    In StoreFast's Settings, create an API key that can publish, and save it as a repository secret named STOREFAST_API_KEY.

  2. 2

    Add the step

    This workflow runs when you publish a GitHub release, downloads the .msix attached to it and sends it to StoreFast. If your workflow builds the package, put the step right after the one that makes it.

    name: Microsoft Store
    
    on:
      release:
        types: [published]
    
    jobs:
      store:
        runs-on: ubuntu-latest
        permissions:
          contents: read
        steps:
          - uses: actions/checkout@v4
    
          - name: Download the MSIX from the release
            env:
              GH_TOKEN: ${{ github.token }}
            run: gh release download "${{ github.event.release.tag_name }}" --pattern '*.msix'
    
          - uses: legendaryspy/storefast-publish@v1
            with:
              api-key: ${{ secrets.STOREFAST_API_KEY }}
              app: 9PJWF4W8V4WG
              package: '*.msix'
  3. 3

    Review and submit

    The update waits on your app's page in StoreFast with the package uploaded and the notes translated. Read them over and click Submit. When you trust the workflow, add submit: true and it goes to Microsoft straight away.

The version is read from the package. The notes come from the first of these that has some: the release-notes input, a release-notes-file, the matching section of CHANGELOG.md, then the GitHub release description. Markdown is turned into plain text. Notes over 1,500 characters or with Markdown headings are rewritten by StoreFast into a short What's new, aiming for about 1,150 characters so translations fit too, and changes that only concern other platforms like macOS are left out.

The full list of inputs, outputs and error messages is in the action's README, and the GitHub Action docs cover the setup.

Errors you might see

MessageWhat to do
This key can only readCreate a StoreFast API key that can publish and update the secret.
The new version has to be higher than ...Raise the version in your package.
already has an update in progressFinish or discard it on the dashboard, or set replace-open: true.
This app already has a submission in progress in Partner CenterWait for it to finish certification, or finish or delete it in Partner Center.
Publish the first version in Partner CenterSubmit the first version by hand once.

Which action should you use?

FeatureStoreFast actionMicrosoft's action
Secrets to addOne API keyFour Entra and seller values
Publish an MSIX updateYesYes
EXE and MSI appsNocomingYes
What's new in every languageYestranslated from one English draftNoyou write each in JSON
Review before it goes to MicrosoftYesthe defaultNot in the example workflow
RunnersLinux, Windows, macOSwindows-latest in the examples
PriceIndie, Studio or the trialFree

Who it's for

StoreFast is a good fit if

  • You publish a GitHub release for every version and want the Store to follow.
  • Your listing has several languages and you want What's new in all of them.
  • You want a person to approve each update, or you want it to ship on its own once you trust it.

Look elsewhere if

  • Your app is free and you'd rather keep everything in Microsoft's own tools. Use their action.
  • Your app ships as an EXE or MSI. Microsoft's action handles those today.

Questions

Can GitHub Actions publish the first version of my app?
No. Microsoft's GitHub Actions guide says the app must already be published and live in the Microsoft Store. You reserve the name and make the first submission in Partner Center, and a workflow can publish every update after that.
Does the workflow wait for certification?
The StoreFast action doesn't. With wait: true it waits until Partner Center has the submission, usually a few minutes, and StoreFast's dashboard follows certification from there. Microsoft's guide says updates appear in the Store after certification in Partner Center is complete.
Do I need a Windows runner?
Microsoft's example workflows use windows-latest. The StoreFast action runs on Linux, Windows and macOS runners and installs nothing. You still need a Windows machine or runner to build the MSIX itself.
Can I review the update before it goes to Microsoft?
With the StoreFast action, yes, and that is the default. The update waits on the app's page with the package uploaded and the notes translated, and nothing reaches Partner Center until you click Submit. Set submit: true to skip that.
Does the StoreFast action handle .msixbundle files?
Not yet. It takes one .msix of up to 4000 MB.

Ship your next release from GitHub

Connect Partner Center, create an API key and add one step to your workflow. The 7-day trial includes the GitHub Action and needs no card.

Sources

Facts about Microsoft's tools were checked against these pages on October 2, 2026.