
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
icemoon-mcp
Advanced tools
MCP server for controlling real, physical iPhones with AI — no jailbreak. Launcher for the Icemoon macOS app.
Give your AI hands. Icemoon exposes physical iPhones to Claude (and any MCP-compatible client) through a local Model Context Protocol server. The AI reads the device screen, plans multi-step tasks, and executes them with human-like touch — on stock iOS, no jailbreak.
This repository is the official documentation and integration reference for the MCP server that ships inside the Icemoon app. The server itself is bundled with the app (commercial, closed source); everything you need to connect it to your MCP client is documented here.
Website: icemoon.app · MCP overview: icemoon.app/mcp · Install guide: icemoon.app/install
┌────────────┐ MCP (stdio) ┌──────────────────┐ USB ┌────────────┐
│ Claude │ ◄─────────────────► │ Icemoon MCP │ ◄──────────► │ iPhone(s) │
│ (or any │ │ server + app │ │ stock iOS │
│ MCP client)│ │ on your Mac │ │ │
└────────────┘ └──────────────────┘ └────────────┘
automation-studio) in ~/Library/Application Support/Claude/claude_desktop_config.json automatically, with its bundled Python runtime — nothing to install by hand.Ask something like:
Open Settings on my iPhone, turn on Do Not Disturb, and verify it stuck.
icemoon-mcp is a tiny launcher: it finds the installed Icemoon app and hands stdio to the server bundled inside it. No Python to install, no paths to look up.
{
"mcpServers": {
"icemoon": {
"command": "npx",
"args": ["-y", "icemoon-mcp"]
}
}
}
The launcher itself is MIT-licensed and has zero dependencies — read it, it is about a hundred lines. It does nothing on its own: the Icemoon app must be installed and licensed, otherwise it prints where to get it and exits.
| Variable | Default | Purpose |
|---|---|---|
ICEMOON_APP | /Applications/AutomationStudio.app | Path to the app bundle, if installed elsewhere |
ICEMOON_DASHBOARD_URL | http://127.0.0.1:8088 | Where the running Icemoon app listens |
If you would rather not go through npm, any MCP client can run the bundled server directly — point it at the bundle's runtime and script:
{
"mcpServers": {
"automation-studio": {
"command": "/Applications/AutomationStudio.app/Contents/Resources/mcp_python/bin/python3",
"args": ["/Applications/AutomationStudio.app/Contents/Resources/mcp_server.py"],
"env": {
"DASHBOARD_URL": "http://127.0.0.1:8088",
"PYTHONPATH": "/Applications/AutomationStudio.app/Contents/Resources/mcp_libs"
}
}
}
}
Notes:
DASHBOARD_URL is the local Icemoon dashboard (default port 8088); the app must be running.claude_desktop_config.json.50 tools across eight groups — full reference with parameters in docs/tools.md.
| Group | Tools | What the AI gets |
|---|---|---|
| Devices & session | list_devices connect_device disconnect_device device_status get_metrics | Discover running devices, pooled connections, per-call port= targeting |
| Screen understanding | get_visible_elements identify_screen get_screen_info get_screen_map get_element_at_position find_by_id get_nav_map screenshot_save | Structured UI reading — elements, screen fingerprints, app navigation maps |
| Touch & input | tap tap_by_id tap_relative double_tap touch_hold swipe swipe_relative scroll pinch type_text smart_type keyboard_dismiss press_button | Human-like gesture synthesis; typing through the real iOS keyboard |
| Apps & navigation | open_app kill_app get_app_list navigate_to wait_for_screen | navigate_to walks to a target screen in one call: detect → path → execute → verify |
| Batching & plans | run_batch sleep_delay foreach_elements plan_create plan_add_step plan_update_step plan_get | Whole action sequences in one round-trip; live plan progress on the dashboard |
| Device state | lock_device unlock_device set_location pasteboard_get pasteboard_set video_record set_action_recording | Lock/unlock, clipboard, screen recording, simulated GPS, action recording |
| Scheduling & scripts | schedule_task list_scheduled_tasks delete_scheduled_task list_saved_scripts | Fire saved automations later, on a calendar, across the fleet |
| Utilities | http_request | Fetch external data mid-task (with SSRF-safe URL validation) |
127.0.0.1; devices are attached over USB.http_request validates URLs and blocks private-network targets.Is this open source? The docs, examples, and manifest in this repo are MIT. The server ships inside the commercial Icemoon app.
Does it work without the Icemoon app? No — the MCP server is the AI-facing surface of the app's automation engine.
Android? No, iOS only. That focus is where the human-like input and no-jailbreak setup come from.
Which plans include it? Farm and Scale — see pricing.
Icemoon — automate real iPhones with human-like touch, from your Mac, no jailbreak.
FAQs
MCP server for controlling real, physical iPhones with AI — no jailbreak. Launcher for the Icemoon macOS app.
We found that icemoon-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.