Runs a command as one app's own uid — the way to read a debug build's private files without root.
run-as <package> <command> [<args>]| Token | Meaning |
|---|---|
| <package> | The app to borrow the identity of. It has to be installed and marked debuggable in its manifest. |
run-as com.example.debug idThe probe: it prints the uid it actually became, so the answer is verifiable rather than merely silent.
run-as com.example.debug ls databases/List the app's SQLite files. The working directory is already the app's home.
run-as com.example.debug cat databases/app.db > /sdcard/app.dbCopy a database somewhere you can pull it from.
Whatever the command you ran prints. A refusal comes from `run-as` itself and says which of three things went wrong: the package is not debuggable, the package is unknown, or the helper is not on this build at all.
| Field | Meaning |
|---|---|
| uid=10234(u0_a234) … | The `id` probe succeeded: you are the app now. |
| …is not debuggable | A release build. Nothing to be done without root — this is the platform working. |
| unknown package | A typo, or the app is not installed for this user. |
| run-as: not found | The build ships no helper. Rare, but it happens. |
Android ADB Toolbox runs this command over USB and parses what comes back — a Chromium browser, no SDK, nothing uploaded.
Commands that turn up in the same session as run-as.
| Command | What it does |
|---|---|
| logcat | Streams the system log: the running commentary of everything happening on the phone. |
| dumpsys dropbox | The platform's ring buffer of crashes, ANRs and tombstones — how you read ANR traces without root. |
| pm path | Prints the absolute paths of the APK files that make up an installed package. |
Checked against AOSP, toybox and kernel sources while writing the parsers behind our Web ADB tools. Where a behaviour genuinely varies by Android version or manufacturer, this page says so instead of giving a number that would be wrong on half the phones out there.
Switch on developer options and USB debugging on the phone, plug it in, then run `adb shell <command>` from a machine with platform-tools installed — or run `adb shell` on its own to get an interactive prompt and type the command without the prefix. If the command produces binary output, such as a screenshot, use `adb exec-out` instead of `adb shell`: the plain shell service attaches a terminal, which rewrites newline bytes and corrupts the data.
Not the ones on this reference. They run as the `shell` user, which can manage packages for its own Android user, read most `dumpsys` services, write the settings provider, inject input and read shared storage. Root is only needed for things this reference deliberately avoids — reading another app's private data (except through `run-as` on a debuggable build), writing system partitions, or reading `/data/anr` directly.
Either the Android version or the manufacturer. Some flags and fields arrived in a specific release, and those are noted per command. The rest is OEM patching, which hits `dumpsys` hardest: a dump is debug output whose text is whatever the service author last printed, and manufacturers change it and backport their changes. Read fields by name rather than by position, and treat an unfamiliar shape as a difference rather than as a failure.
For many commands, yes — the Web ADB tools on this site talk to a phone over WebUSB from a Chromium-based desktop browser, with no SDK installed and nothing uploaded. Each page links to the tool that runs its command, when one exists. Two limits are worth knowing: only one program can hold the ADB interface at a time, so a desktop `adb server` has to be stopped first, and `adb forward` and `adb reverse` cannot work in a browser at all.
Would rather click than type? The Web ADB Toolkit runs commands like this from a browser over USB. Or browse every command.