Atlas of Systems Atlas
MMXXVI

Phone MCP

A model on the internet, holding a real Android device at the other end of a tunnel.

MCP · Cloudflare Tunnel · ADB · Samsung SM-S731U
Phone MCP — a look inside, on desktop and phone
on desktop and phone
The hop

Four links, and any one can break

Nothing here is a managed service. It's a tunnel to a laptop to a USB cable to a phone, and each junction fails in its own way with its own unhelpful error.

Tunnel

A Cloudflare Quick Tunnel gives a throwaway https URL with no account. Convenient, and the hostname changes every restart — the MCP config goes stale silently.

MCP layer

Tool schemas wrap shell invocations. The schema is the contract — a vague description gets a model calling the wrong tool confidently.

ADB

Authorisation is per host key and lives on the phone. Replug into a different port and you're re-approving the fingerprint on the device screen.

The device

Doze and battery optimisation will kill a background listener without telling anyone. It looks like a network fault and isn't.

Scope

This is a lot of access

Screen capture, input injection, app launching, file transfer, log access. ADB was built for developers holding their own hardware, and every bit of that surface is now reachable from a chat window.

Own device only

The phone is yours, the tunnel is yours, the endpoint is yours. Nothing about this generalises to a device you don't own.

Tunnel URL is the key

An unauthenticated Quick Tunnel URL is the credential. Anyone with the string has the phone. Named tunnels with access policies are the real answer.

No standing state

The server holds no session. Kill the tunnel and the whole capability disappears — which is the intended off switch.

Read before write

Inspection tools are safe to call freely. Anything that injects input or moves files deserves a gate, the same way Pi gates SMS.

It pairs with Pi from the other direction: Pi is a model living on the phone reaching outward; this is a model living outside reaching in.

Server v1.0

The laptop left the chain

The current server runs in Termux on the phone itself, talking to its own ADB over wireless debugging. Tunnel, server and device are now one object in your pocket.

No SDK

MCP is implemented by hand — JSON-RPC 2.0 over both transports: legacy HTTP+SSE and the single-endpoint Streamable HTTP. The official Python SDK was out: its cryptography dependency ships a broken native wheel on Termux's Python 3.14.

15 tools

Screenshot, tap, swipe, type, key events, launch and list apps, foreground app, SMS send and list, battery, GPS, clipboard read and write, notifications.

The SMS quirk

termux-sms-send often hands the message off and then hangs. A timeout is reported as likely sent, never as failed — so the model doesn't retry and double-text someone.

Auth is a formality

Some MCP clients refuse any server without OAuth discovery metadata, so there is a spec-shaped OAuth layer that approves everyone. It says so in its own header comment: the tunnel URL is the only real secret.