ShizuStore

Haven

GlassHaven

5.89.17 · GitHub

Download APK
Terminals Android 8.0+ 8 hours ago AGPL-3.0
269 ShizuStore
34k GitHub
1.3k Stars
155 MB Size

More about this app

Terminal, SSH, VNC, RDP, SFTP & cloud storage client for Android

Haven icon

Haven

Free, open-source remote access & mobile workspace for Android —
SSH · Mosh · VNC · RDP · SFTP · SMB · email · cloud storage, a local Linux shell, mesh networking, and a consent-gated AI-agent endpoint

"Haven is an interesting vibe coding experiment. Let's see what comes out of it." — DBP

Release F-Droid Build License Android 8.0+ Downloads Ko-fi

GitHub Releases • F-Droid

Terminal transparency over a live device wallpaper — click for full-quality video

▶ Watch: the terminal — and every Haven screen — made translucent over the device wallpaper (new in 5.60.4). Live wallpaper: MagicFluids.


         


At a glance

  • Terminal — Mosh / Eternal Terminal / SSH, tmux-aware session restore, configurable keyboard toolbar, OSC 7/8/9/52/133/777 integration.
  • Desktops — VNC (RFB 3.8 / VeNCrypt), RDP (IronRDP + EGFX), a GPU-accelerated native Wayland compositor, and a multi-distro local-desktop manager.
  • Files & cloud — unified browser for SFTP/SCP, SMB, and 60+ cloud providers; cross-filesystem copy/move, editor and image tools; plus on-device FFmpeg transcode, HLS streaming, and DLNA.
  • Connections — port forwarding (-L/-R/-D/-J), SOCKS/HTTP/Tor proxies, per-app WireGuard & Tailscale tunnels, port knocking and fwknop SPA, and SSH keys (incl. FIDO2/SK).
  • Email — ProtonMail (bridge protocol) and any IMAP/SMTP mailbox; compose / reply / forward, multi-account, attachments; plus Mail Rules inbound automation.
  • AI chat — chat with self-hosted or API models (OpenAI-compatible, Ollama, Anthropic, Gemini) over per-profile tunnel routing; image attach for vision models, clipboard copy/paste both ways, opt-in encrypted saved transcripts.
  • Local Linux — a Linux userland via PRoot (no root, any Android 8+ device): Alpine, Debian, Arch, or Void, side-by-side.
  • USB forwarding — broker an attached USB device through Android and re-expose it to the agent, into the Linux guest, or over USB/IP to a remote host (e.g. a phone-hosted YubiKey, touch on the phone).
  • Reticulum — rnsh shell, file transfer, and -L/-D port forwarding over Reticulum mesh, pure Kotlin. The one transport that keeps working with no internet at all.
  • Agent transport (MCP) — an optional MCP server exposing ~130 consent-gated, audited tools; the agent can even see and operate Haven itself for a self-hosting build → install → verify loop.
  • Security — biometric lock, no telemetry, encrypted backup/restore (AES-256-GCM).

See docs/FEATURES.md for the full feature index.

Why one app

The list above is the parts; the point is how they compose. Each of these is one flow inside Haven — no second app, no curl | ssh incantation:

  • Tap a 4K MKV in Google Drive → FFmpeg transcodes it over HTTP and the result lands back in the same Drive folder, never touching local disk.
  • SSH to a box, forward its port, tap the VNC profile that targets localhost — the desktop opens in the same app, keyboard and clipboard shared.
  • Cut a log directory from an S3 bucket, switch tabs, paste it onto an SFTP server — rclone does the server-side copy when it can, otherwise Haven streams it through.
  • Run your agent CLI in the on-device Linux shell; it pushes over the SSH agent you forwarded from your laptop while you watch on the same screen.
  • Cast a cloud video to the TV across the room over HLS, copy the LAN URL from the snackbar, send it to a friend so they can watch too.

The phone is the thin client, Haven is the thin-client OS, and the cloud, your servers, and your agents are the computer. Width is sufficient; composition is the point. (Vision.)

Languages

Available in 12 languages: English, Chinese (simplified), Spanish, Hindi, Arabic (with RTL support), Portuguese, Bengali, Russian, Japanese, Korean, French, and German. The UI follows the device language.

Want to help translate? Improve a translation or add a new language straight from the web translation page — no cloning or setup; your changes become a GitHub pull request. See Languages & translation for details.

Install

Channel
GitHub Releases Signed APK, all features
F-Droid Built from source, all features

Both builds have the same features — SSH, Mosh, Eternal Terminal, VNC, RDP, SFTP, SMB, email, and cloud storage. IronRDP (Rust) is built from source via cargo-ndk. rclone (Go) is built from source via gomobile.

Pick one channel and stay on it. The two channels are signed with different keys — GitHub Releases use Haven's own release key; F-Droid builds from source and signs with F-Droid's per-app key. Android treats different signing keys as different apps, so you can't update in place from one channel to the other — switching means uninstall + reinstall, which clears app data (back up first via Settings → Backup). Direct sideloads and Obtainium track the GitHub Releases key.

Signing certificate SHA-256 (to verify a sideloaded APK with apksigner verify --print-certs):

  • GitHub Releases: ea03a3a70e1c11d0a78932f959b21f20d8735d9cd750997657cb7f7d7c2b90b3
  • F-Droid: ea05a89431961b8ac53c36725452673c2be1c2d7b6e48771617b974e6092b332

Build from source

Requires Rust with Android targets, cargo-ndk, Go 1.26+, and gomobile:

# Rust (for RDP)
rustup target add aarch64-linux-android x86_64-linux-android
cargo install cargo-ndk

# Go (for rclone cloud storage)
go install golang.org/x/mobile/cmd/gomobile@latest
go install golang.org/x/mobile/cmd/gobind@latest

git clone --recurse-submodules https://github.com/GlassHaven/Haven.git
cd Haven
./gradlew assembleDebug

Output: app/build/outputs/apk/debug/haven-*-debug.apk

Documentation

Third-party libraries

Library Purpose License
rclone Cloud storage engine (60+ providers) MIT
IronRDP RDP protocol (Rust/UniFFI) MIT / Apache-2.0
JSch SSH/SFTP protocol BSD
smbj SMB/CIFS protocol Apache-2.0
ConnectBot termlib Terminal emulator Apache-2.0
reticulum-kt Reticulum mesh network transport (Kotlin) MPL-2.0
rnsh-kt Reticulum remote shell client (Kotlin) AGPL-3.0
FFmpeg Media conversion and streaming LGPL-2.1 / GPL-2.0
PRoot Local Linux shell (userspace chroot) GPL-2.0
labwc Wayland compositor (native desktop) GPL-2.0
wlroots Wayland compositor library MIT
virglrenderer GPU virtualization (OpenGL passthrough to PRoot apps) MIT
Jetpack Compose UI toolkit Apache-2.0

Backing

Haven sits on top of the projects listed in the table above — the heavy lifting was done long before this repo existed.

Most of the direction Haven has taken has come from the user base, not from a roadmap: bug reports, screenshots of edge cases, "have you tried…” comments on long issue threads. Qwen3.8-Flash running locally writes most of the actual code; the maintainer's role is closer to that of a messenger between the user group and the model: listening, setting the agenda, and quality-checking.

A small recurring amount comes in via Ko-fi and Liberapay. It helps offset the electricity costs of running the work above, and it's a clear signal that the work is useful to people. The project continues regardless of donations.

License

AGPLv3

Close

How Shizuku is used

Can install apps, grant location and camera access, read logs, enable wireless debugging and adb over TCP, and share desktop via `Shizuku newProcess` shell.

This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.

How this app uses Shizuku

Haven uses Shizuku to run privileged shell commands that support its terminal, desktop and automation features.

  • Install apps silently: APKs downloaded from a link or pulled from a connected server or cloud backend install quietly with the pm install shell command through Shizuku.
  • Grant location access: precise location fixes and continuous GPS logging grant themselves location permission with the pm grant shell command through Shizuku when the action is approved.
  • Grant camera access: camera frame capture grants itself camera permission with the pm grant shell command through Shizuku when the action is approved.
  • Read system logs: recent system log output for troubleshooting and automation reviews is collected with the logcat shell command through Shizuku, including filtering by app (resolved to a user id with the pm list packages shell command), process and text or time.
  • Save diagnostic logs: extended log recording to a file in Downloads uses the logcat shell command through Shizuku for all process logs when available.
  • Turn on wireless debugging: wireless adb pairing is enabled and its port and address are read back with the settings shell command through Shizuku.
  • Expose adb over network: classic adb over TCP on a chosen port is started and stopped with system property and adb server shell commands through Shizuku, then shared over the app tunnel.
  • Enable notification access: notification history access is granted with the notification shell command through Shizuku.
  • Keep connections awake: battery optimization is disabled for the app with the deviceidle shell command through Shizuku.
  • Share Linux desktop outside: the built in Wayland desktop socket is published under shared temporary storage with file system shell commands through Shizuku so external clients can connect.
  • Reach local virtual machine: the on device terminal virtual machine is reached by relaying a local port to its guest channel with a socat relay started through Shizuku, and its direct address is found by reading the system route table through Shizuku.

Android APIs or commands used

  • pm install -S
  • pm grant
  • pm list packages -U
  • logcat -d
  • logcat -t
  • logcat -T
  • logcat --uid
  • logcat --pid
  • logcat -v threadtime
  • logcat -c
  • cmd settings put global adb_wifi_enabled
  • cmd settings get global adb_wifi_port
  • cmd notification allow_listener
  • cmd deviceidle whitelist
  • setprop service.adb.tcp.port
  • getprop service.adb.tcp.port
  • setprop ctl.restart adbd
  • stop adbd
  • start adbd
  • socat TCP-LISTEN
  • VSOCK-CONNECT
  • pkill -f socat TCP-LISTEN
  • cat /proc/net/route
  • mkdir -p /data/local/tmp/haven-wayland
  • chmod 0755
  • ln -s
  • rm -f

Notable details

Installs still work without Shizuku by opening the standard Android installer for a tap to confirm. Log recording without Shizuku captures only the app own logs. Other privileged actions need Shizuku running and approved, otherwise they report that Shizuku is required.

Close

Changelog

What's new for version 5.89.17

  • Inline images in the terminal. SSH programs that speak the Kitty or iTerm2 graphics protocol — image viewers, chart tools, preview generators — can now display raster images inline where the cursor is. Each image asks first: a consent dialog with Deny, Allow, and an always-allow latch for the session. Terminal settings carry the policy (Off / Ask / Always, Ask by default), and it is readable and writable over MCP as terminal_inline_images. (#583)
  • Dependency updates. Tailscale 1.102.5 in the rclone bridge; uniffi 0.32.2 and smallvec 1.16.2 in the RDP native code.

Which APK?

haven-<version>-<abi>-release.apk — the full app, and what F-Droid carries. If in doubt, take this one.

haven-<version>-<abi>-terminal-release.apk — the same app with the desktop and media parts left out, for people who only use Haven for SSH, terminals, files and storage. Less than half the size on arm64. It drops RDP and SPICE remote desktop, the native Wayland desktop, and ffmpeg — so no media conversion, and no video previews or streaming in the file browser. VNC is kept, so a Linux desktop running inside Haven's guest still works.

Both are signed with the same key and carry the same version number, so you can install either over the other without losing connections, keys or your Linux guest. The shared version number does mean an updater will not offer to move you between them — switching is a deliberate download.

<abi> is your device's CPU: arm64 for essentially every modern phone, armv7 for older 32-bit devices, x64 for emulators.

Full Changelog: https://github.com/GlassHaven/Haven/compare/v5.89.16...v5.89.17

Close

Permissions

25 permissions requested

  • android.permission.INTERNET
  • android.permission.ACCESS_NETWORK_STATE
  • android.permission.FOREGROUND_SERVICE
  • android.permission.FOREGROUND_SERVICE_SPECIAL_USE
  • android.permission.USE_BIOMETRIC
  • android.permission.POST_NOTIFICATIONS
  • android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
  • android.permission.WAKE_LOCK
  • android.permission.NFC
  • android.permission.REQUEST_INSTALL_PACKAGES
  • android.permission.CHANGE_WIFI_MULTICAST_STATE
  • android.permission.READ_EXTERNAL_STORAGE
  • android.permission.MANAGE_EXTERNAL_STORAGE
  • android.permission.ACCESS_COARSE_LOCATION
  • android.permission.ACCESS_FINE_LOCATION
  • android.permission.FOREGROUND_SERVICE_LOCATION
  • android.permission.CAMERA
  • android.permission.BLUETOOTH_CONNECT
  • android.permission.BLUETOOTH
  • android.permission.BLUETOOTH_SCAN
  • android.permission.BLUETOOTH_ADMIN
  • android.permission.USE_FINGERPRINT
  • android.permission.RECEIVE_BOOT_COMPLETED
  • sh.haven.app.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
  • moe.shizuku.manager.permission.API_V23
Close

Sources

4 sources

5.89.17 armeabi-v7a GitHub · sh.haven.app
Selected Download
5.89.17 x86_64 GitHub · sh.haven.app
Download
5.89.17 arm64-v8a GitHub · sh.haven.app
Download
5.89.14 arm64-v8a F-Droid · sh.haven.app · sh.haven.app
Download