Skip to content

Launch week: lifetime is was $67 $34.99 until 15 October. CodeWas $67 $34.99 lifetime until 15 Oct. takes another 10% off.for 10% off. Get it

Automate your own iPhone from a Mac, with approvals

Mobster runs tasks in the apps on your iPhone from your Mac over a USB cable, reads every button by name, and asks before it sends, buys, posts or deletes.

(updated )6 min readThe Mobster team

Most of what you do on a phone happens in apps with no API: Messages, your bank, delivery apps, Settings. Shortcuts covers a little of it, and the rest you do by hand. Mobster’s agent does those taps for you, in the apps you’re already signed in to, from the Mac on your desk. It reads every button by name, and it stops for your OK before anything that counts.

A task, step by step

Type a task the way you’d ask a person: “Turn on Dark Mode” or “Text Alex that I’m running 10 minutes late”. Mobster picks the app from your words, then works one step at a time:

  1. It reads the screen as a list of controls by name: each button, cell, field and switch, with its label and value. These are the labelled controls VoiceOver reads, the accessibility tree.
  2. Its agent picks the next action from those controls, with a small screenshot for what the labels don’t say.
  3. It taps, types or swipes over the cable.
  4. It reads the screen again and checks what changed.

Because it reads controls by name, it taps “Send” as a button, knows whether a switch is on, and reads back what it typed. Tools that work from screenshots tap coordinates and type what a Bluetooth keyboard can.

Try it with no phone and no key

curl -fsSL https://mobster.dev/install.sh | sh
mobster --demo

The terminal UI opens with a scripted phone. The agent, the approvals and the history are real, and the header says DEMO. Type Turn on Dark Mode and Mobster scrolls, taps “Display & Brightness”, taps “Dark” and checks the result. Type Text Alex "on my way" and it opens Messages, types the text and stops before it taps Send. Press y to send or n to stop. Getting started has the rest.

It asks before it sends

In Mobster for Mac and the terminal UI, “Ask before acting” is on by default. Before a tap or submit that can send, buy, post, delete or submit, Mobster stops and shows you the action, the app and the exact text. In the terminal UI:

Tap “Send” in Messages
This control can send, buy, post, delete or submit, so Mobster asks first.

❯ 1. Yes, tap “Send”   (y)
  2. No, stop the task  (n, esc)
Declines itself in 9:58

In the Mac app, the card names the verb: Send or Don’t send, Post or Don’t post, Pay or Don’t pay. Decline, and the task ends with nothing sent. If nobody answers within 10 minutes, the task ends without that action. Under the approval, every action is written to a journal before it’s sent, and an action with an unknown outcome is never retried, so Mobster never repeats a send it couldn’t confirm.

Approvals cover the tasks Mobster’s own agent runs. mobster run, the command for scripts, shows the first decision and sends nothing unless you pass --execute. When another agent drives the phone through Mobster’s MCP server, that agent’s own permission prompts apply. Approvals reduce risk; they don’t remove it, so use accounts you’re comfortable handing to an agent.

Sign-in codes, notifications and the clipboard

When a task reaches a screen that wants a code sent by text or email, Mobster finds it: in the keyboard’s “From Messages” suggestion, then in Notification Center, then in the newest messages. It asks you before it uses the code, types it into the code field, and the model never sees it. It types a code only into a field that looks like a code field, in the app that asked for it, and refuses a code older than 10 minutes.

It can also read Notification Center without tapping anything, and put text on the phone’s clipboard for a task to paste. What Mobster can and can’t do has the details.

Repeat it on a schedule

Save a task as a workflow in Mobster for Mac and run it with one click, or on a schedule: “Every weekday at 8, tell me my first meeting”. Workflows run while your Mac is awake and your iPhone is plugged in and unlocked, and a step that needs your approval waits for you. While a scheduled task is due within 10 minutes, or running, Mobster keeps your Mac from sleeping on its own.

Set a webhook in Settings (Slack, Discord, ntfy or any https address that takes JSON) and Mobster posts there when a scheduled task fails, stops early, or has waited a minute for your approval. The post never holds the answer or anything Mobster typed.

Your phone, your Mac, no cloud in between

  • Commands go from your Mac to the phone over the cable. There’s no relay server and no Mobster account.
  • Mobster’s agent sends each step’s screen text and a small screenshot to the AI provider whose key you gave. Your key stays on the Mac.
  • Task screenshots stay on the Mac, at most 480 pixels on the long side, and go when you delete the task.
  • The Mac app has no analytics and no crash reporting.

Privacy has the full list, down to the App Store lookup for app icons. USB or Wi-Fi for iPhone automation explains why the runner on the phone answers only the cable.

What you need

You needWhy
A Mac with Apple siliconMobster runs on the Mac
Xcode, signed in to an Apple AccountIt builds and signs the small runner Mobster puts on the phone. A free Apple Account works
An iPhone with Developer Mode onThe runner runs only with Developer Mode on (Settings › Privacy & Security › Developer Mode)
A USB data cableMobster talks to the phone over the cable
An OpenAI or Anthropic keyMobster’s agent runs on your own AI account, and you pay the provider directly

The runner is WebDriverAgent, the open-source XCTest runner the Appium project maintains, and it’s what lets Mobster read every control by name. Nothing is jailbroken: the phone runs one extra app that Xcode signed with your account, and Developer Mode is a switch you can turn off again. With a free Apple Account, Apple signs the runner for 7 days at a time, and Mobster for Mac rebuilds it for you while the phone is plugged in and unlocked.

Plan for the first setup to take a while: Xcode is a large download, and the first runner build can take 10 minutes or more. Mobster for Mac walks you through each part, the Mac, your AI account, then the iPhone, Developer Mode and the runner, and it carries its own iPhone connection tools, so you never open Terminal. With the CLI, Device setup has every step.

Mobster can’t get past Face ID or your passcode, and it never pays with Apple Pay: a task on a locked phone stops at once with “Your iPhone is locked. Unlock it and try again. No action was taken.”

The Mac app or the CLI

Mobster CLI is free and open source under MIT, and it has the whole harness: the terminal UI with approvals and history, mobster run for scripts, the MCP server, and the same agent the Mac app runs. Why Mobster is open source explains the split. Mobster for Mac adds guided setup for each phone, a live view with manual control, approvals as cards, history, workflows and schedules.

Start with your own iPhone

Try the agent with no phone and no key, for free:

curl -fsSL https://mobster.dev/install.sh | sh
mobster --demo

Then let Mobster for Mac set up your iPhone: $34.99 one time, or $7.67 a month.

How Mobster compares puts the other ways to automate an iPhone side by side.

Questions

  • Can I automate my iPhone from a Mac without jailbreaking it?

    Yes. Mobster uses Developer Mode and WebDriverAgent, a test runner built on Apple's XCTest that Xcode signs with your own Apple Account. Nothing on the phone is jailbroken.

  • Does Mobster send my screens to a server?

    There's no Mobster server between your Mac and your phone. Mobster's own agent sends each step's screen text and a small screenshot to the AI provider whose key you gave, and nothing else from the phone leaves your Mac.

  • Can a task run while I'm away from the Mac?

    Saved workflows run on a schedule while your Mac is awake and your iPhone is plugged in and unlocked. A step that needs your approval waits for you, and a webhook can tell you it's waiting.

Sources

We read each of these on 8 October 2026. Reviewed by Andy Guo on . Corrections are welcome at the GitHub repo.