Repository navigation
Plus API Reference
Shizuku+ extends the standard Shizuku binder with a family of Plus interfaces — privileged system bridges that a third-party app can call directly, without shelling out. They are exposed through a single facade class, ShizukuPlusAPI, shipped in the ShizukuPlus-API library.
This page is the catalog of that facade. Each nested class below maps to one AIDL interface on the server (or, for Shell/Settings/PackageManager/Dhizuku, to a small convenience helper).
Everything here depends on the connected server being a Shizuku+ build with the enhanced API enabled:
if (!ShizukuPlusAPI.isEnhancedApiSupported()) {
// Connected to stock Shizuku, or Plus API disabled — Plus calls will no-op.
}-
Thread-safe: every binder-touching method is safe to call from any thread.
executeShell(...)blocks, so keep it off the main thread. -
Fail-soft: when Shizuku isn't connected, the enhanced API is unsupported, or a transient IPC error occurs, methods return
null/false/ empty-list rather than throwing. - Privilege level: all operations run at the shell UID (2000, ADB-level) — the same as the rest of Shizuku+. Anything shell can do works; genuinely root-only operations do not (see Root Compatibility Hub).
-
Some methods fall back to shell: a few (e.g.
OverlayManager.enableOverlay,ActivityManager.deepForceStop) try the fast binder path first, then fall back to the equivalentcmd/amcommand if the Plus service is unavailable.
Synchronous command execution returning a CommandResult { int exitCode; String output; String error; boolean isSuccess() }. Drains stdout and stderr on separate threads to avoid pipe-buffer deadlock; 30-second timeout.
| Method | Notes |
|---|---|
executeShell(String command) |
Runs sh -c <command>. |
executeShell(String[] cmd) |
Runs an explicit argv (no shell parsing). |
Thin wrappers over settings put/get.
putSystem · putSecure · putGlobal · getSystem · getSecure · getGlobal
installPackage(apkPath) · uninstallPackage(pkg) · clearPackageData(pkg)
getBinder() · isAvailable() — access to the Device-Owner compatibility binder (see Dhizuku Mode).
Rootless control of connectivity, power, display, audio, and appearance. Backs the Device Control screen.
| Group | Methods |
|---|---|
| Connectivity |
setAirplaneModeEnabled · setWifiEnabled · setBluetoothEnabled · setMobileDataEnabled · setNfcEnabled
|
| USB | setUsbFunction("mtp"|"adb"|"charging"|"none"|"rndis"|"midi") |
| Power |
reboot(reason) — reason: null, "recovery", "bootloader", "fastboot", "quiescent" · shutdown()
|
| Display |
setScreenBrightness(0–255) · setAutoBrightnessEnabled · setScreenTimeout(ms) · setAutoRotateEnabled
|
| Audio |
setStreamVolume(stream, level) · getStreamVolume(stream)
|
| Appearance |
setFontScale(0.70–2.00) · setAnimationsEnabled
|
| Settings |
putSetting(namespace, key, value) · getSetting(namespace, key)
|
rebootrejects unknown reasons."edl"is intentionally not accepted — it can hard-brick some devices.
Resolution/DPI override, equivalent to wm size / wm density as a clean IPC surface.
setDisplaySize(w, h) · resetDisplaySize · setDisplayDensity(dpi) · resetDisplayDensity · getDisplaySize · getDisplayDensity · getPhysicalDensity
forceResizable(pkg, enabled) — force apps into freeform/multi-window · setAlwaysOnTop(taskId, enabled)
Privileged status-bar and Quick Settings control.
disableExpansion · enableExpansion · collapse · expandSettings · clickTile(component) · getCurrentTiles · setTiles(list) · addTile(spec) · removeTile(spec) · moveTileToPosition(spec, position)
Tile specs: system ("wifi", "bt", "airplane", "dnd", "flashlight", "rotation", "nfc", "internet") or custom ("custom(com.pkg/.TileService)").
Runtime-permission management plus privileged package ops.
| Group | Methods |
|---|---|
| Permissions |
grantPermission · revokePermission · getGrantedPermissions
|
| Lifecycle |
uninstallForUser · restoreSystemApp · suspendApp · unsuspendApp · isAppSuspended · installApk
|
| Inspection |
isAppDebuggable · isBackupAllowed · getAppDataDir
|
deepForceStop(pkg) (falls back to am force-stop) · killAllBackgroundProcesses · setAppStandbyBucket(pkg, bucket)
setPrivateDns(mode, hostname) · restrictAppNetwork(pkg, restricted) · isAppNetworkRestricted(pkg)
Runtime resource overlay (RRO) management — the engine behind Overlay Manager Plus.
enableOverlay · disableOverlay · setHighestPriority · getAllOverlays · injectResourceOverlay(targetPkg, resourceName, type, value)
(Enable/disable fall back to cmd overlay when the binder path is unavailable.)
The workhorse behind App Backup & Restore. Streams data over ParcelFileDescriptors.
| Group | Methods |
|---|---|
| Enumerate |
listInstalledPackages(includeSystem) · getApkPaths · listApkSplits · getPackageMetadata · getAppDataSize
|
| APK stream |
streamApk · streamApkSplit(pkg, fileName)
|
| ADB backup (Android ≤ 11) |
backupAppData(pkg, includeApk, includeShared) · restoreAppData(stream)
|
| External / OBB |
backupExternalData · restoreExternalData · backupObbData · restoreObbData
|
| Install session |
createInstallSession · writeApkToSession · commitInstallSession · abandonInstallSession
|
| Permissions |
getPermissionState · restorePermissions · grantRuntimePermission · revokeRuntimePermission
|
| BackupManager |
isBackupEnabled · requestBmgrBackup · listBmgrBackupSets · getActiveBackupTransport
|
| Settings |
dumpSettings(namespace) · restoreSettings(namespace, bundle)
|
| Freeze |
freezeApp · unfreezeApp · isAppFrozen
|
| Lifecycle |
forceStop · clearAppData
|
| SMS | insertSmsMessages(list) |
The "temp-debug" trick: repackage a non-debuggable app as debuggable so run-as can read its private data, then restore the original.
prepareTempDebug(pkg) → streamDataDir / restoreDataDir → restoreOriginal(pkg). Also streamOriginalApk · isTempDebugging · cleanupAllTempDebug (recovers packages stuck in temp-debug after a crash).
Privileged filesystem access over binder.
exists · delete · openFile(path, mode) · listFiles · getFileInfo · copyFile · openContentUri · tarDirectory(dir, pkg) · restoreTarDirectory(dir, pkg, pfd)
tarDirectory/restoreTarDirectoryaccept an optional package name to route throughrun-asfor a debuggable app's private dir. The package name is validated against a strict pattern before use.
Read-only observation surfaces that shell UID can reach.
backupViaSystemAgent · dumpHeap(pid, dest) · readLogcat(pkg, maxLines) · getOpenFiles(pid) · getExportedProviders(pkg) · callContentProvider(uri, method, arg) · queryContentProvider(uri, projection) · getDumpsys(service) · readProcFile(pid, filename) · getRunningAppPids
readProcFile is whitelisted to: maps, status, cmdline, comm, oom_score, oom_adj, smaps_rollup, net/tcp, net/tcp6, net/unix, net/udp6.
Surfaces the SYSTEM_FIXED permissions that uid 2000 holds. Powerful — treat as sensitive.
| Group | Methods |
|---|---|
| Input / capture |
screenshotAsPfd · injectTap · injectText · injectSwipe · injectKeyEvent
|
| Telephony |
getSmsMessages(folder, max) · sendSms(to, body) · getCallLog(max) · getPhoneInfo
|
| Personal data |
getContacts(max) · getCalendarEvents(max) · getAccounts · getLastKnownLocation
|
| AppOps |
setAppOpsMode(pkg, op, mode) · getAppOpsMode(pkg, op)
|
| System |
dismissKeyguard · getSavedWifiNetworks · getClipboard · setClipboard · getNotifications
|
Each method documents the underlying permission (e.g. READ_SMS, READ_WIFI_CREDENTIAL, ACCESS_FINE_LOCATION) in the library source.
Screen-aware primitives. Note these are gated behind the tiered feature flags described in AICore+ Automation Bridge — the input-injection and hierarchy methods require the experimental tier.
getPixelColor(x, y) · captureLayer(layerId) · getSystemContext · getWindowHierarchy · scheduleNPULoad(bundle) · simulateTouch(x, y) · simulateSwipe(x1, y1, x2, y2, ms) · simulateText(text)
Android Virtualization Framework (Microdroid) VM management.
list · start(name) · stop(name) · create(name, config) · delete(name) · getStatus(name)
listEligibleDevices() — multi-device continuity discovery.
Versioning: the Plus API is versioned alongside the server. Always guard calls with
isEnhancedApiSupported(); a method returning its fail-soft default may mean the connected server predates that method. Full javadoc for every method lives in the ShizukuPlus-API repository.