Pony: AI Agents Get Control Over an Android Smartphone
Published: 2026-10-03 · Author: AI Release · @ai_release1
⚡ The gist in 5 seconds - What it is: Pony is a layer for Android that lets AI agents (Claude, Grok, Gemini, OpenAI, and others) see the screen and interact with apps without an API. - Availability: An APK for sideloading on Android 11+, code on GitHub (MIT license), version 0.6.4 (versionCode 11). - Limitation: Dangerous actions (sending, payments, deletion, calls, etc.) require explicit user confirmation; passwords are hidden and entering them is forbidden. ### 🔍 What was found Pony is the oroplex/pony project on GitHub. The current version is 0.6.4, versionCode 11, MIT license. A signed APK is published in GitHub Releases, and latest.json includes a SHA-256 for verification. Android 11 or newer is required. To run the MCP server yourself, you need Node.js 20+. Architecture: the phone opens an outbound WebSocket to a relay (Pony Cloud by default), the assistant connects the same way, and a one-time code pairs them. Screenshots and commands are encrypted at the ends of the connection, so the relay cannot read them. Pony can take screenshots, read the accessibility tree, perform taps, swipes, long presses, drag-and-drop, pinch, and text input, open apps by package name, and navigate to settings screens. It can work on a hidden display (launching other apps there requires Shizuku). There are three ways to connect the "brain": your own API key on the phone (Claude, OpenAI, Gemini, xAI Grok, OpenRouter, or any OpenAI-compatible endpoint), any MCP host (Claude Desktop, Claude Code, Cursor) via the MCP server, or Grok Bot via a template. Keys are stored in the Android Keystore and never leave the device, except for calls to the chosen provider. ### 💡 Why it matters Pony enables AI agents to work with apps that have no API — Uber, Postmates, Resy, phone settings — without vendor SDK integrations. The user chooses the model or MCP host themselves and stays in control: before sending, paying, purchasing, deleting, calling, transferring, or changing security settings, Pony asks for confirmation. Passwords are masked as [password] and entering them is forbidden; the agent cannot accept, decline, or end calls and does not interact with the call screen. It's a practical bridge between Android and modern AI agents via the standard MCP protocol. ### 🧩 Context The project is published on GitHub under the MIT license. It is distributed via a sideloaded APK rather than Google Play — the repository includes a PLAY_POLICY.md. The code and signed releases are available, and the APK's integrity can be verified via the SHA-256 from latest.json. The repository also lets you run a private relay (e.g., via Tailscale or on your own server), with end-to-end encryption preserved in all modes.
⚡ The gist in 5 seconds - What it is: Pony is a layer for Android that lets AI agents (Claude, Grok, Gemini, OpenAI, and others) see the screen and interact with apps without an API.
- Availability: An APK for sideloading on Android 11+, code on GitHub (MIT license), version 0.6.4 (versionCode 11).
- Limitation: Dangerous actions (sending, payments, deletion, calls, etc.) require explicit user confirmation; passwords are hidden and entering them is forbidden.
🔍 What was found Pony is the oroplex/pony project on GitHub.
The current version is 0.6.4, versionCode 11, MIT license.
A signed APK is published in GitHub Releases, and latest.json includes a SHA-256 for verification.
Android 11 or newer is required.
To run the MCP server yourself, you need Node.js 20+.