DroidBridge
Health Warn
- License — License: Apache-2.0
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 5 GitHub stars
Code Fail
- rm -rf — Recursive force deletion command in magisk/uninstall.sh
Permissions Pass
- Permissions — No dangerous permissions requested
No AI report is available for this listing yet.
On-device MCP server for Android — let ChatGPT and local AI agents operate your phone. App edition (Accessibility/Shizuku) or root edition (Magisk/KernelSU/APatch). No PC, no ADB.
DroidBridge
An on-device MCP server for Android.
Let ChatGPT and local AI agents actually operate your phone — no PC, no ADB.
English · 简体中文
What it is
DroidBridge runs a Model Context Protocol server inside your phone.
An AI agent connected to it can see the screen, tap and type, manage files, run commands, use the
clipboard and notifications, diagnose the network and schedule automations — with exactly the
permissions you granted on the device, and nothing more.
Two ways to connect, side by side:
| Connection | For | How it reaches the phone |
|---|---|---|
| ChatGPT | ChatGPT on the web (developer mode) | OpenAI's Secure MCP Tunnel. The phone polls OpenAI over HTTPS; no port is opened and no public address is needed. |
| Local MCP | Agents on the same device, or on a computer over adb forward |
Streamable HTTP on 127.0.0.1:8765/mcp (root edition: port 8766) with a bearer token. |
What an agent can do
| Tool | What it covers |
|---|---|
context |
DroidBridge status, capabilities and the tool catalog |
visual |
Observe the screen (image and UI hierarchy), tap, long-press, swipe, type text, press keys and key combinations |
android |
Inspect packages, launch apps and intents, clipboard, notifications |
filesystem |
Inspect, read, write, edit, move, delete, archive (ZIP) and download files |
command |
Run shell commands as the app or shell (Shizuku) identity, or as root in the root edition |
network |
Diagnose DNS, TCP and TLS; capture and inject traffic (root edition) |
automation |
Create, update, enable and delete automations that run on a schedule |
task_control |
List, inspect and cancel background tasks |
Every tool carries MCP safety annotations (readOnlyHint, destructiveHint, openWorldHint), so
clients such as ChatGPT ask you to confirm actions that change things.
Choose your edition
DroidBridge comes in two editions:
- DroidBridge is an app that runs everything itself. It works on an ordinary phone and gains
the shell identity when Shizuku is running. - The root edition is a root module. Its backend runs as root on its own, starts at boot and
keeps running whatever happens to any app. It installs the DroidBridge Root app, which shows
the backend's state and settings but runs nothing itself.
Both editions can run on one phone: DroidBridge serves local MCP on port 8765 and the root edition
on port 8766.
| DroidBridge | DroidBridge + Shizuku | Root edition (Magisk / KernelSU / APatch) | |
|---|---|---|---|
| Screen observe / tap / type | Accessibility service | Observe/tap; typing uses Accessibility | ✓ |
| Screen capture | Screen-capture consent | ✓ | ✓ |
| Notifications | Notification access | Notification access | ✓ |
| Shell commands | App identity | App and shell identity | Root identity |
| Network capture / injection | — | — | ✓ |
| Stays alive in the background | Battery and autostart settings | Kept alive until the next reboot | Runs on its own, restored after reboot |
In DroidBridge, the Execution & access page walks you through each switch with a button that
opens the right system page, and tells you when something is already covered by Shizuku.
Requirements
- Android 13 to 17 on an arm64-v8a device.
- For ChatGPT: a plan with web developer mode (Plus or higher), a Secure MCP Tunnel and a Runtime
API key from the OpenAI platform. - Optional: Shizuku, Magisk,
KernelSU or APatch for
the root edition.
Install
DroidBridge
- Download
droidbridge-<version>-arm64-v8a.apkfrom the
latest release (tagapk-v<version>)
and install it. - Open DroidBridge. The first-run guide asks which agent you use and walks through permissions.
The release ships a SHA256SUMS.txt and a signed release.json; the app's Updates page uses
the signature to verify its own updates.
Root edition
- Download
droidbridge-magisk-<version>.zipfrom the newestmagisk-vrelease. - Install it in Magisk, KernelSU or APatch. Installing it also installs the DroidBridge Root app.
- Reboot, then open DroidBridge Root.
Module updates are offered by your root manager.
Connect ChatGPT
- On platform.openai.com create a
Secure MCP Tunnel, and an API key allowed to use it. - In DroidBridge open Agent connection → ChatGPT connection, paste the Tunnel ID and the key,
and turn the tunnel on. The key is never shown again: DroidBridge encrypts it with the Android
Keystore, and the root edition keeps it readable by root only. - On a computer browser, turn on Developer mode in ChatGPT security settings
(it is still rolling out to Plus accounts). Then on ChatGPT plugins
tap Add → Create MCP app, connect it through your tunnel with Authentication set to None.
The app page has links to both. - Ask ChatGPT to use DroidBridge. The first call shows up in the app.
Connect a local agent
In the app open Agent connection → Local MCP, turn it on and copy the token.
Point your MCP client at
http://127.0.0.1:8765/mcp(root edition:8766) withAuthorization: Bearer <token>.
From a computer, forward the port first:adb forward tcp:8765 tcp:8765
Screenshots
| Home | Execution & access | Agent connection | Settings |
|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
Security and privacy
- Everything runs on the phone. DroidBridge has no server of its own and sends no telemetry.
- An agent gets exactly the access you granted on the device; there is no extra remote
permission layer to misconfigure. Only connect agents you trust with that access. - The ChatGPT tunnel speaks only to
api.openai.comover TLS with a pinned WebPKI root store. - The local MCP endpoint listens on loopback only and requires its bearer token.
- Text that the system
inputcommand cannot type (for example Chinese or emoji) is pasted
through the clipboard: the clip is marked sensitive and your previous clipboard is restored.
Please report vulnerabilities privately as described in SECURITY.md.
Build from source
The build is pinned and currently scripted for Windows with PowerShell 7:
- JDK 17, Android SDK platform 37, Build Tools 36.0.0, NDK 29.0.14206865, CMake 3.31.6
- Rust 1.98.0 (
rust/rust-toolchain.toml) andcargo-ndk4.1.2 - libpcap 1.10.6 for the root network tools:
pwsh tools/build-libpcap.ps1
./gradlew :standalone:assembleDebug :root-frontend:assembleDebugMagiskModule
pwsh tools/check-toolchain.ps1 verifies the toolchain. See CONTRIBUTING.md.
Support the project
DroidBridge is built and maintained in spare time. If it is useful to you, you can support it on
Ko-fi. Bug reports and device reports help just as much.
License
DroidBridge is licensed under the Apache License 2.0. Third-party components and their
licenses are listed in THIRD_PARTY_NOTICES.txt.
DroidBridge is an independent project and is not affiliated with or endorsed by OpenAI, Anthropic,
Google, Magisk or Shizuku. Product names are trademarks of their respective owners.
Reviews (0)
Sign in to leave a review.
Leave a reviewNo results found



