Overview
Developed by Rikka and open-sourced under the Apache-2.0 license, Shizuku represents a fundamental architectural breakthrough in how Android applications interact with privileged operating system internals.
Traditionally, root applications requiring elevated privileges—such as package managers, app freezers, and file browsers—rely on spawning interactive superuser shell processes (su). Every operation translates into executing terminal commands (e.g. pm disable-user <package> or dumpsys activity). This pattern suffers from severe engineering drawbacks:
- High Latency: Spawning shell processes repeatedly incurs significant CPU and fork/exec overhead.
- Fragile Text Parsing: Command outputs must be serialized to string text and deserialized via regex, creating vulnerability to OEM output formatting changes.
- Restricted Scope: Applications are limited strictly to CLI tools compiled into the OS image.
Shizuku eliminates the shell intermediary entirely by establishing an inter-process communication (IPC) broker directly across Android’s native Binder framework.
Technical Architecture & How Shizuku Works
Android’s system architecture organizes core OS capabilities into system services running inside system_server (e.g., PackageManagerService, ActivityManagerService, AppOpsService). User applications interact with these services by obtaining IBinder handles:
- Client App (e.g. Canta, Hail, Material Files): Authenticates via Shizuku IPC binder token with user approval.
- Shizuku Server (
app_processdaemon): Runs under UID 2000 (Shell) or UID 0 (Root) and brokers privileged Binder handles. - Android
system_server: Receives direct AIDL system calls (PackageManager, ActivityManager, AppOps) delegated by the Shizuku server on behalf of the client app.
- Daemon Spawning: Shizuku launches a standalone Java process using Android’s native
app_processbinary running under either theshellUID (2000via ADB) or therootUID (0via su). - Binder Delegation: Once the daemon is active, it obtains privileged Binder interfaces from the system server.
- IPC Brokerage: When an authorized client application (such as Hail, Canta, or Material Files) connects, Shizuku verifies the client’s UID against the user-approved permission list and returns a proxied Binder wrapper (
ShizukuBinderWrapper). - Direct Method Invocation: The client app invokes native AIDL methods directly in Java/Kotlin with near-zero latency and type safety.
Activation Methods
Shizuku supports three distinct operational modes depending on whether your device is rooted or stock:
1. Root Mode (Magisk / KernelSU / APatch)
If your device has root access, Shizuku requires zero manual ADB commands:
- Sideload and install
shizuku-v*.apk. - Open the Shizuku application.
- Locate the Start via Root card and tap Start.
- When prompted by your root manager (Magisk, KernelSU, or APatch), grant Superuser permissions permanently.
- Shizuku will spawn the background daemon and display
Shizuku is running (root).
2. Wireless Debugging Mode (Android 11+ Rootless)
On unrooted Android devices running Android 11 or newer:
- Connect your device to a local Wi-Fi network.
- Enable Developer Options by tapping Build Number seven times in Settings -> About Phone.
- In Developer Options, enable Wireless debugging.
- Open Shizuku and tap Pairing under Start via Wireless Debugging.
- Split-screen or open Developer Options in a floating window, navigate to Wireless debugging -> Pair device with pairing code.
- Enter the 6-digit pairing code shown on screen into Shizuku’s notification prompt.
- Return to the Shizuku app and tap Start. Shizuku will automatically connect to the internal wireless port and initialize the server.
3. Cable ADB Mode (Computer)
For stock devices on Android 10 or older, or when Wi-Fi is unavailable:
- Connect your phone to your computer via USB with USB debugging turned on.
- Open a terminal on your computer and execute:
adb shell sh /sdcard/Android/data/moe.shizuku.privileged.api/start.sh - The terminal will output confirmation of
app_processexecution, and Shizuku will displayShizuku is running (adb).
Using Rish (Root/Shell Interactive Shell)
Shizuku includes rish (Rikka Shell), a tool that converts Shizuku’s Binder token into an interactive root or ADB terminal session on your Android device without needing a computer:
- In Shizuku, tap Use Shizuku in terminal apps.
- Tap Export files to save
rishandrish_dex.jarto a local directory. - In Termux or your preferred Android terminal emulator, invoke:
chmod +x ./rish ./rish - You will immediately obtain a shell with UID 2000 (
shell) or UID 0 (root), ready for automation scripts.
OEM Quirks & Troubleshooting
Xiaomi HyperOS / MIUI
- Issue: Shizuku closes or permissions time out immediately.
- Fix: Open Developer Options and enable both:
- USB debugging (Security settings) (Requires SIM card verification)
- Disable permission monitoring (Prevents MIUI from intercepting runtime Binder checks)
- Navigate to Settings -> Battery -> Background app management, locate Shizuku, and select No restrictions.
Samsung OneUI
- Issue: Shizuku stops working after Wi-Fi disconnect.
- Fix: Samsung Knox automatically disables Wireless Debugging upon disconnecting from known Wi-Fi networks. Whenever reconnecting, re-toggle Wireless debugging in Developer Options.
Emergency Recovery & Stopping Daemon
If a malfunctioning client app consumes excessive resources or if you wish to terminate the Shizuku daemon:
# Terminate the Shizuku daemon from root shell or ADB:
pkill -f moe.shizuku.privileged.api
# Verify process termination:
ps -ef | grep shizuku
Frequently Asked Questions
Why does Shizuku stop running whenever I turn off my screen on HyperOS or MIUI?
HyperOS and MIUI enforce aggressive background process reclamation. To keep the Shizuku daemon alive, navigate to Settings -> Apps -> Shizuku -> Battery Saver and select 'No restrictions'. Furthermore, ensure 'USB debugging (Security settings)' remains enabled under Developer Options.
Do I have to re-pair Wireless Debugging every time I reboot?
No. Pairing is a one-time cryptographic handshake. However, Android randomizes the wireless debugging port upon every reboot and Wi-Fi reconnection. You only need to toggle Wireless Debugging off and on, open Shizuku, and tap 'Start' to re-bind to the new dynamic port.
What is the manual ADB command to start Shizuku from a computer?
Connect your device via USB with USB debugging enabled, then execute: adb shell sh /sdcard/Android/data/moe.shizuku.privileged.api/start.sh. The Shizuku daemon will spawn and bind immediately.