Martin's corner on the web

MCP my iPhone: Claude Code drives it

Some things on my iPhone can only be done by tapping through Settings – there is no export, no API, and Shortcuts can’t read them. Which apps eat the space, which ones can see my location at all times, what drains the battery. My phone was down to 9.3 GB free, and the last time I checked app permissions was probably never. A job for Claude Code, if only it could see and touch the phone. I had already used it to get my Viber messages out of the desktop database and Facebook groups into a daily digest, the phone was the missing piece.

The obvious route, iPhone Mirroring on the Mac, is not available in the EU. Apple withholds it here citing the Digital Markets Act, so every tool built on top of it is out for me.

The second route is WebDriverAgent – a small HTTP server built on Apple’s UI-testing framework that runs on the phone and accepts taps, swipes and “give me the screen” requests. There are already several MCP servers on GitHub built on top of it. appium-mcp from the Appium team is the mature one, and ios-agent arrived at almost exactly the design I ended up with. There is even a paid Mac app that does the same. So why not just install one?

Because whoever’s code drives the phone gets everything I can see on it. Once WebDriverAgent runs on an unlocked phone, the tool can open any app and read what it shows – my banking apps up to their Face ID prompt, further if one is still logged in. It sees mail and chats, and the login codes that arrive by SMS and e-mail.

So I decided to write the smallest thing I can read end to end – a bit of bash and Python on top of three pinned pieces: WebDriverAgent built from source at a fixed commit and signed with my own Apple ID, go-ios for the USB tunnel, and the official Python MCP SDK. Claude Code gets 11 tools – screen, tap, type, scroll, launch an app and a few more – and anything labelled send, pay, delete, call or post needs an explicit confirm before it is tapped. The code is on GitHub.

Writing it myself also taught me a few things the READMEs don’t say. WebDriverAgent has no password, so while it runs, any device on my Wi-Fi can pull a screenshot of the phone. Not great. And when the phone locks, it still sees the lock screen, notifications included. Of course, to you mine is just another repo, and it leans on WebDriverAgent and go-ios like all the others – so read it first, it is short on purpose.

The first job on the list: auditing what all the other apps on the phone are allowed to do. And if you install any of these tools, mine included, remember that Developer Mode is the one switch none of them can get around – turn it off when you’re done.

Tagged on: ,

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.