Skip to content

Plus API Reference

thejaustin edited this page Sep 19, 2026 · 1 revision

Plus API Reference

Shizuku+ extends the standard Shizuku binder with a family of Plus interfaces — privileged system bridges that a third-party app can call directly, without shelling out. They are exposed through a single facade class, ShizukuPlusAPI, shipped in the ShizukuPlus-API library.

This page is the catalog of that facade. Each nested class below maps to one AIDL interface on the server (or, for Shell/Settings/PackageManager/Dhizuku, to a small convenience helper).


Contract & gating

Everything here depends on the connected server being a Shizuku+ build with the enhanced API enabled:

if (!ShizukuPlusAPI.isEnhancedApiSupported()) {
    // Connected to stock Shizuku, or Plus API disabled — Plus calls will no-op.
}
  • Thread-safe: every binder-touching method is safe to call from any thread. executeShell(...) blocks, so keep it off the main thread.
  • Fail-soft: when Shizuku isn't connected, the enhanced API is unsupported, or a transient IPC error occurs, methods return null / false / empty-list rather than throwing.
  • Privilege level: all operations run at the shell UID (2000, ADB-level) — the same as the rest of Shizuku+. Anything shell can do works; genuinely root-only operations do not (see Root Compatibility Hub).
  • Some methods fall back to shell: a few (e.g. OverlayManager.enableOverlay, ActivityManager.deepForceStop) try the fast binder path first, then fall back to the equivalent cmd/am command if the Plus service is unavailable.

Convenience helpers

Shell

Synchronous command execution returning a CommandResult { int exitCode; String output; String error; boolean isSuccess() }. Drains stdout and stderr on separate threads to avoid pipe-buffer deadlock; 30-second timeout.

Method Notes
executeShell(String command) Runs sh -c <command>.
executeShell(String[] cmd) Runs an explicit argv (no shell parsing).

Settings

Thin wrappers over settings put/get.

putSystem · putSecure · putGlobal · getSystem · getSecure · getGlobal

PackageManager

installPackage(apkPath) · uninstallPackage(pkg) · clearPackageData(pkg)

Dhizuku

getBinder() · isAvailable() — access to the Device-Owner compatibility binder (see Dhizuku Mode).


Device & system control

DeviceControl — IDeviceControlPlus

Rootless control of connectivity, power, display, audio, and appearance. Backs the Device Control screen.

Group Methods
Connectivity setAirplaneModeEnabled · setWifiEnabled · setBluetoothEnabled · setMobileDataEnabled · setNfcEnabled
USB setUsbFunction("mtp"|"adb"|"charging"|"none"|"rndis"|"midi")
Power reboot(reason) — reason: null, "recovery", "bootloader", "fastboot", "quiescent" · shutdown()
Display setScreenBrightness(0–255) · setAutoBrightnessEnabled · setScreenTimeout(ms) · setAutoRotateEnabled
Audio setStreamVolume(stream, level) · getStreamVolume(stream)
Appearance setFontScale(0.70–2.00) · setAnimationsEnabled
Settings putSetting(namespace, key, value) · getSetting(namespace, key)

reboot rejects unknown reasons. "edl" is intentionally not accepted — it can hard-brick some devices.

DisplayTuner — IDisplayTunerPlus

Resolution/DPI override, equivalent to wm size / wm density as a clean IPC surface.

setDisplaySize(w, h) · resetDisplaySize · setDisplayDensity(dpi) · resetDisplayDensity · getDisplaySize · getDisplayDensity · getPhysicalDensity

WindowManager — IWindowManagerPlus

forceResizable(pkg, enabled) — force apps into freeform/multi-window · setAlwaysOnTop(taskId, enabled)

StatusBarGovernor — IStatusBarGovernorPlus

Privileged status-bar and Quick Settings control.

disableExpansion · enableExpansion · collapse · expandSettings · clickTile(component) · getCurrentTiles · setTiles(list) · addTile(spec) · removeTile(spec) · moveTileToPosition(spec, position)

Tile specs: system ("wifi", "bt", "airplane", "dnd", "flashlight", "rotation", "nfc", "internet") or custom ("custom(com.pkg/.TileService)").


Packages, permissions & apps

PackageGovernor — IPackageGovernorPlus

Runtime-permission management plus privileged package ops.

Group Methods
Permissions grantPermission · revokePermission · getGrantedPermissions
Lifecycle uninstallForUser · restoreSystemApp · suspendApp · unsuspendApp · isAppSuspended · installApk
Inspection isAppDebuggable · isBackupAllowed · getAppDataDir

ActivityManager — IActivityManagerPlus

deepForceStop(pkg) (falls back to am force-stop) · killAllBackgroundProcesses · setAppStandbyBucket(pkg, bucket)

NetworkGovernor — INetworkGovernorPlus

setPrivateDns(mode, hostname) · restrictAppNetwork(pkg, restricted) · isAppNetworkRestricted(pkg)

OverlayManager — IOverlayManagerPlus

Runtime resource overlay (RRO) management — the engine behind Overlay Manager Plus.

enableOverlay · disableOverlay · setHighestPriority · getAllOverlays · injectResourceOverlay(targetPkg, resourceName, type, value)

(Enable/disable fall back to cmd overlay when the binder path is unavailable.)


Backup, restore & APK patching

BackupRestorePlus — IBackupRestorePlus

The workhorse behind App Backup & Restore. Streams data over ParcelFileDescriptors.

Group Methods
Enumerate listInstalledPackages(includeSystem) · getApkPaths · listApkSplits · getPackageMetadata · getAppDataSize
APK stream streamApk · streamApkSplit(pkg, fileName)
ADB backup (Android ≤ 11) backupAppData(pkg, includeApk, includeShared) · restoreAppData(stream)
External / OBB backupExternalData · restoreExternalData · backupObbData · restoreObbData
Install session createInstallSession · writeApkToSession · commitInstallSession · abandonInstallSession
Permissions getPermissionState · restorePermissions · grantRuntimePermission · revokeRuntimePermission
BackupManager isBackupEnabled · requestBmgrBackup · listBmgrBackupSets · getActiveBackupTransport
Settings dumpSettings(namespace) · restoreSettings(namespace, bundle)
Freeze freezeApp · unfreezeApp · isAppFrozen
Lifecycle forceStop · clearAppData
SMS insertSmsMessages(list)

ApkPatcher — IApkPatcher

The "temp-debug" trick: repackage a non-debuggable app as debuggable so run-as can read its private data, then restore the original.

prepareTempDebug(pkg) → streamDataDir / restoreDataDir → restoreOriginal(pkg). Also streamOriginalApk · isTempDebugging · cleanupAllTempDebug (recovers packages stuck in temp-debug after a crash).

StorageProxy — IStorageProxy

Privileged filesystem access over binder.

exists · delete · openFile(path, mode) · listFiles · getFileInfo · copyFile · openContentUri · tarDirectory(dir, pkg) · restoreTarDirectory(dir, pkg, pfd)

tarDirectory / restoreTarDirectory accept an optional package name to route through run-as for a debuggable app's private dir. The package name is validated against a strict pattern before use.


Inspection & privileged data

AppInspector — IAppInspector

Read-only observation surfaces that shell UID can reach.

backupViaSystemAgent · dumpHeap(pid, dest) · readLogcat(pkg, maxLines) · getOpenFiles(pid) · getExportedProviders(pkg) · callContentProvider(uri, method, arg) · queryContentProvider(uri, projection) · getDumpsys(service) · readProcFile(pid, filename) · getRunningAppPids

readProcFile is whitelisted to: maps, status, cmdline, comm, oom_score, oom_adj, smaps_rollup, net/tcp, net/tcp6, net/unix, net/udp6.

PrivilegedDataSource — IPrivilegedDataSource

Surfaces the SYSTEM_FIXED permissions that uid 2000 holds. Powerful — treat as sensitive.

Group Methods
Input / capture screenshotAsPfd · injectTap · injectText · injectSwipe · injectKeyEvent
Telephony getSmsMessages(folder, max) · sendSms(to, body) · getCallLog(max) · getPhoneInfo
Personal data getContacts(max) · getCalendarEvents(max) · getAccounts · getLastKnownLocation
AppOps setAppOpsMode(pkg, op, mode) · getAppOpsMode(pkg, op)
System dismissKeyguard · getSavedWifiNetworks · getClipboard · setClipboard · getNotifications

Each method documents the underlying permission (e.g. READ_SMS, READ_WIFI_CREDENTIAL, ACCESS_FINE_LOCATION) in the library source.


AI, virtualization & continuity

AICore — IAICorePlus

Screen-aware primitives. Note these are gated behind the tiered feature flags described in AICore+ Automation Bridge — the input-injection and hierarchy methods require the experimental tier.

getPixelColor(x, y) · captureLayer(layerId) · getSystemContext · getWindowHierarchy · scheduleNPULoad(bundle) · simulateTouch(x, y) · simulateSwipe(x1, y1, x2, y2, ms) · simulateText(text)

VirtualMachine — IVirtualMachineManager

Android Virtualization Framework (Microdroid) VM management.

list · start(name) · stop(name) · create(name, config) · delete(name) · getStatus(name)

Continuity — IContinuityBridge

listEligibleDevices() — multi-device continuity discovery.


Versioning: the Plus API is versioned alongside the server. Always guard calls with isEnhancedApiSupported(); a method returning its fail-soft default may mean the connected server predates that method. Full javadoc for every method lives in the ShizukuPlus-API repository.

Clone this wiki locally