Use your Android phone from any AI assistant: read the screen, open apps, tap, type, swipe.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Let an AI assistant use your Android phone, your browser, and the rest of your Melaya account.
Also listed on mcp.so Β· mcpserver.dev Β· mcpmarket Β· cursor.directory Β· Glama
Documentation Β· Melaya Β· Device Control Β· MCP Server
Melaya pairs a phone to your account and gives an agent the same view of it a person has: it reads the screen through Android's accessibility tree, then taps, types, swipes, and moves between apps. No per-app integration, no vendor API. If you can use the app, so can the agent.
This is a remote Model Context Protocol server. MCP is a vendor-neutral standard, so one endpoint works everywhere:
Nothing to install, no SDK required.
Claude Code | |
Codex CLI |
Direct HTTP needs |
Cursor |
|
Claude |
claude.ai, Desktop and mobile: Settings β Connectors β Add custom connector, paste |
ChatGPT |
Settings β Connectors β Developer mode, paste the same endpoint |
Le Chat |
Connectors β Add custom MCP connector |
| VS Code | |
| Everything else |
Windsurf, Zed, Cline, Goose, Lovable, Gemini CLI, Qwen Code and any other MCP client take the same block, in whichever file that client uses for MCP servers: |
Authentication is OAuth 2.1 with PKCE. You choose which permissions to grant on a Melaya consent page; the assistant receives a scoped token. Your password is never shared.
Then just ask:
Connect my phone and go through my unread Instagram DMs.
Read the screen, open apps, tap, type, scroll, swipe, screenshot. You watch it work, and one control stops everything.
Melaya ships navigation playbooks for common apps, so the agent arrives knowing where things are instead of exploring blindly.
The same read-act-verify loop on a desktop site, through the Melaya extension on Chrome or Edge. You attach the tab; the model never picks one.
It can also debug the page it is on: network activity, console output, and a performance diagnosis that ranks causes with the file and the number behind each, rather than handing over a raw panel. Credential values are redacted at capture, before anything reaches the model.
List the template library and instantiate a validated template, or author a pipeline from scratch, validate it before saving, schedule it, and watch it run. Hand a long or recurring job to an autonomous agent on your own machine, on your own model subscription, that carries on after the conversation ends.
Mail, documents, your ERP. Read-only, structurally: the write path is blocked in two independent places, so a write stays blocked even if Melaya's own tool catalog is out of date.
Runs, transcripts, tool traces, failure diagnosis, cost, and what your agents have learned across runs.
Enforced on the device itself, not on the server, so no prompt and no agent instruction can move them.
Apps on the phone, origins in the browser. The agent can hand access back, narrowing the list or clearing it, but only you can grant it.
That asymmetry is deliberate. The agent reads text off your screen, and text can be written by anyone: a message, a comment, a web page. A boundary it could widen in response to what it reads would not be a boundary.
You see the exact text before it goes out, and approvals reach you even when the phone is locked.
Β
On the phone overlay and in the Melaya app. It halts everything immediately, across every agent and every connected assistant.
The gate exists to put a human between an agent and a consequential action, and the caller here is a model reading untrusted content. You approve in the Melaya app or on your phone.
Password fields are excluded from screen reads.
Also deliberately absent, and enforced by tests rather than by convention: trading (it writes against live exchange keys), administration (no honest consent sentence exists for it), and credential values of any kind.
Eight scopes, one per domain. You grant them individually.
| Scope | What it allows |
|---|---|
melaya:read | Your workspace: pipelines, runs, traces, evaluations, pending approvals |
melaya:platform | Your account and plan: tier, usage against limits, subscription |
melaya:runner | Set up and check the Melaya runner on your computer |
melaya:phone | Operate your paired Android phone, inside apps you allow-listed |
melaya:browser | Operate a connected browser, on sites you allowed |
melaya:pipelines | Create, edit, schedule, run and cancel agent pipelines |
melaya:connectors | Read data from connected services. Read only |
melaya:team | Read project membership, and invite people you name |
The tool list your assistant receives is filtered to what you granted, so connecting for phone control alone shows 23 tools rather than all 80. If a capability seems missing, you declined it; reconnect and approve it.
[!NOTE] If you also use the Melaya SDK, "connectors" means something different there. In the SDK it is project credential storage. Here,
melaya:connectorsis reading data from services you already connected. This surface cannot store, read or delete a credential.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/melaya)<a href="https://allmcps.com/mcp/melaya"><img src="https://allmcps.com/api/badge/melaya?style=directory" alt="Melaya on AllMCPs" /></a>