Repository navigation
Permission Manager
The Permission Manager lets you grant and revoke permissions for any installed app directly from Shizuku+ — including privileged, signature-level permissions that Android's own Settings screen won't let you touch. Because the service runs at shell UID (2000), it can grant a whole class of PROTECTION_SIGNATURE permissions that are normally reserved for system apps but are still shell-grantable.
Open it from the Shizuku+ home screen under Permission Manager. Developers can call the same grant/revoke through
ShizukuPlusAPI.PackageGovernor.
- Open Permission Manager — you get a searchable list of every installed app (search by name or package).
- Tap an app to see its permissions, split into two sections:
- Privileged — shell-grantable signature permissions the app declares (see the list below). A note explains these are normally system-only.
- Runtime — the standard dangerous/runtime permissions (location, camera, storage, …).
- Flip a switch to grant or revoke. The change is applied immediately and the toggle reflects the new state.
Only permissions the app actually declares in its manifest appear — you can't grant a permission an app never requested.
Android's Settings UI only exposes runtime (dangerous) permissions. Many backup, automation, and power-user apps also declare signature/privileged permissions that are technically grantable by the shell but invisible in Settings. The Permission Manager surfaces those and grants them via the privileged service.
Privileged permissions it recognizes as shell-grantable include:
-
READ_LOGS,DUMP— read system logs / dumpsys output -
PACKAGE_USAGE_STATS,OBSERVE_APP_USAGE— usage access -
WRITE_SECURE_SETTINGS— write secure/global settings -
READ_FRAME_BUFFER— screen capture pipelines -
INTERACT_ACROSS_USERS,INTERACT_ACROSS_USERS_FULL— cross-profile access -
MANAGE_USB— USB device/function control -
BATTERY_STATS— battery statistics -
MOUNT_UNMOUNT_FILESYSTEMS— mount operations -
INSTALL_PACKAGES,DELETE_PACKAGES— silent install/uninstall -
CHANGE_NETWORK_STATE,CHANGE_WIFI_STATE,ACCESS_WIFI_STATE,MANAGE_NETWORK_POLICY,CONNECTIVITY_INTERNAL— network control -
GET_APP_OPS_STATS,MANAGE_APP_OPS_MODES— AppOps inspection/control -
CHANGE_COMPONENT_ENABLED_STATE,FORCE_STOP_PACKAGES— component/enable and force-stop control
Grants and revokes go through ShizukuPlusAPI.PackageGovernor, which the privileged server implements as PackageGovernorPlusImpl:
-
Primary path — a direct Binder IPC into the package manager via the Android-17-aware compat layer (
grantRuntimePermission/revokeRuntimePermission), which handles the extradeviceIdparameter newer Android versions require. -
Fallback — if the IPC path fails, it shells out to
pm grant --user 0 …/pm revoke --user 0 ….
The app list and each app's declared-permission state are read with the normal PackageManager (GET_PERMISSIONS), so what you see is the live grant state.
- Revoking a privileged permission may break the app that relies on it — the manager warns via the section note; grant deliberately.
- Some signature permissions still can't be granted by shell on certain OEM builds; if a toggle flips back, the platform rejected the grant (shell UID isn't allowed it on that ROM).
-
Runtime permissions behave exactly like Settings — granting
ACCESS_FINE_LOCATION, for instance, is equivalent to the user allowing it in the system dialog. - Changes apply to the current user (user 0).
- App Backup & Restore — captures and re-grants the permission set as part of a backup.
- Permissions — the permissions Shizuku+ itself needs, and why.
- Knowledgebase & Troubleshooting.