Lists installed packages, optionally with the APK path, uid, version code and installer.
pm list packages [-f] [-U] [--show-versioncode] [-i] [-s | -3 | -e | -d | -u] [--user <id>] [<name filter>]| Token | Meaning |
|---|---|
| -f | Also print the APK path the package was installed from. |
| -UAndroid 8.0+ | Also print the uid. |
| --show-versioncodeAndroid 8.0+ | Also print the version code. |
| -i | Also print the installer package. One extra binder call per package. |
| -s | System packages only. |
| -3 | Third-party packages only. |
| -e | Packages currently enabled for the queried user. |
| -d | Packages currently disabled for the queried user. |
| -u | Include packages uninstalled with data kept, which makes this list a superset of the default one. |
| --user <id> | Ask about one Android user. Without it the shell command queries every user, so a package disabled for user 0 but enabled in a work profile lands in both the -e and -d lists. |
pm list packages -3Everything you installed yourself.
pm list packages -f -U --show-versioncodeThe full inventory in one pass: path, uid and version code per package.
pm list packages -d --user 0What is currently disabled for the primary user.
pm list packages -uIncludes packages removed with `pm uninstall -k`, which is how you find what can still be restored.
Sample output
package:/data/app/~~kO7bJ9w==/com.example-Ay8s2Q==/base.apk=com.example versionCode:4711 installer=com.android.vending uid:10234One line per package, built left to right by the platform: the literal `package:` prefix, the APK path when you asked for it, then the package name, then the optional suffixes. Read it from the right — peel off `uid:`, `installer=`, `stopped=` and `versionCode:` in turn and what remains is the name, because a modern APK path contains `=` characters of its own.
| Field | Meaning |
|---|---|
| package: | Fixed prefix on every line. |
| <path>= | The APK path, present only with -f. Ends at the last `=`. |
| versionCode:<n> | The long version code, with --show-versioncode. |
| stopped=<bool> | Whether the package is in the stopped state. |
| installer=<pkg> | Who installed it, with -i. Preceded by two spaces, not one, and printed as the four letters `null` for a preinstalled app. |
| uid:<n>[,<n>] | The uid, with -U. A comma-separated list when the package exists for more than one Android user. |
Android Debloat Tool runs this command over USB and parses what comes back — a Chromium browser, no SDK, nothing uploaded.
Commands that turn up in the same session as pm list packages.
| Command | What it does |
|---|---|
| pm path | Prints the absolute paths of the APK files that make up an installed package. |
| pm uninstall | Removes a package, or removes it for one Android user only — which is how a preinstalled app is disposed of without root. |
| pm disable-user | Switches a package off for one Android user without removing it — the reversible alternative to uninstalling. |
| dumpsys package | Everything the package manager knows about one app: version, paths, flags, install source and per-user state. |
| Command | What it does |
|---|---|
| pm clear | Wipes an app's data — or, on Android 13 and later, only its cache. |
| pm trim-caches | Asks the system to drop cached files until the given amount of free space exists. |
| pm install | Installs one APK that is already on the device, which is what `adb install` does under the hood. |
| pm install-create | Opens an install session so several APKs — a base plus its splits — are installed as one atomic unit. |
Checked against AOSP, toybox and kernel sources while writing the parsers behind our Web ADB tools. Where a behaviour genuinely varies by Android version or manufacturer, this page says so instead of giving a number that would be wrong on half the phones out there.
Switch on developer options and USB debugging on the phone, plug it in, then run `adb shell <command>` from a machine with platform-tools installed — or run `adb shell` on its own to get an interactive prompt and type the command without the prefix. If the command produces binary output, such as a screenshot, use `adb exec-out` instead of `adb shell`: the plain shell service attaches a terminal, which rewrites newline bytes and corrupts the data.
Not the ones on this reference. They run as the `shell` user, which can manage packages for its own Android user, read most `dumpsys` services, write the settings provider, inject input and read shared storage. Root is only needed for things this reference deliberately avoids — reading another app's private data (except through `run-as` on a debuggable build), writing system partitions, or reading `/data/anr` directly.
Either the Android version or the manufacturer. Some flags and fields arrived in a specific release, and those are noted per command. The rest is OEM patching, which hits `dumpsys` hardest: a dump is debug output whose text is whatever the service author last printed, and manufacturers change it and backport their changes. Read fields by name rather than by position, and treat an unfamiliar shape as a difference rather than as a failure.
For many commands, yes — the Web ADB tools on this site talk to a phone over WebUSB from a Chromium-based desktop browser, with no SDK installed and nothing uploaded. Each page links to the tool that runs its command, when one exists. Two limits are worth knowing: only one program can hold the ADB interface at a time, so a desktop `adb server` has to be stopped first, and `adb forward` and `adb reverse` cannot work in a browser at all.
Would rather click than type? The Web ADB Toolkit runs commands like this from a browser over USB. Or browse every command.