Using App Ops with ADB to Fine‑Tune Android App Permissions

11 min read Learn how to leverage Android’s hidden App Ops tool with ADB to view and adjust individual app permissions beyond the standard UI, improving privacy and control. September 27, 2026 00:00 How to Use App Ops via ADB to Fine‑Tune Android App Permissions

Android’s public permission manager hides many of the granular controls that power users and privacy‑conscious folks would like to see. App Ops is a hidden subsystem that records every operation an app requests – from accessing the camera to reading your clipboard – and lets you toggle each operation individually. While the UI is hidden, you can reach it through adb (Android Debug Bridge). This guide walks you through enabling ADB, listing an app’s operations, changing them safely, and handling the most common pitfalls.

Why Use App Ops?

Android’s Settings > Apps > Permissions page shows only the permission groups (e.g., Camera, Location). Within a group, an app may request multiple low‑level operations, some of which you might not need. App Ops exposes those operations, allowing you to:

  • Block an app from reading your clipboard while still allowing it to use the camera.
  • Prevent background location polling for a navigation app that only needs GPS while active.
  • Diagnose why an app is misbehaving by checking which operations are actually denied.

Because App Ops changes are stored in the system’s appops database, they survive reboots and do not require root.

Before You Start

Prerequisites

  • A computer with Android Platform‑Tools installed.
  • USB debugging enabled on your phone (Settings > About phone > Tap Build number 7 times, then Settings > System > Developer options > USB debugging).
  • A charged device (ADB operations are low‑power but you don’t want to lose power mid‑process).
  • Wi‑Fi or USB connection to the computer.

If your device is running Android 12 or newer, the appops command is still present, but the syntax for some operations changed slightly. The steps below cover Android 9–13; later versions are similar.

Step 1 – Verify ADB Connection

  1. Connect your phone via USB (or enable Wireless debugging under Developer options for a wireless link).
  2. Open a terminal or command prompt on your computer.
  3. Run adb devices. You should see your device’s serial number followed by device.
    adb devices
    List of devices attached
    ABC1234567    device
  4. If the device shows as unauthorized, accept the RSA fingerprint prompt on the phone.

Successful connection is essential; otherwise the following commands won’t reach the phone.

Step 2 – Identify the Target App

You need the app’s package name (e.g., com.whatsapp). You can find it in Settings > Apps, tap the app, then scroll to the bottom where the package name is shown, or use ADB:

  1. Run adb shell pm list packages | grep -i "keyword", replacing keyword with part of the app name.
    adb shell pm list packages | grep -i whatsapp
  2. The output will include a line like package:com.whatsapp. The string after the colon is the package name.

Step 3 – List All App Ops for the App

Now you can see every operation the app has requested and its current mode.

  1. Execute:
    adb shell cmd appops get com.whatsapp
  2. The output looks like:
    GET_USAGE_STATS: allow
          CAMERA: allow
          READ_CLIPBOARD: deny
          WRITE_CLIPBOARD: deny
          ACCESS_FINE_LOCATION: allow
  3. Each line shows OPERATION: MODE. allow means the operation is permitted, deny blocks it, and default follows the app’s declared permission.

If you see default for an operation you care about, the app’s permission group is currently granted, but you can still override it.

Step 4 – Change an Operation’s Mode

Use the set sub‑command to override a specific operation.

  1. Choose the operation you want to modify (e.g., READ_CLIPBOARD).
  2. Run the command:
    adb shell cmd appops set com.whatsapp READ_CLIPBOARD deny
  3. Verify the change:
    adb shell cmd appops get com.whatsapp | grep READ_CLIPBOARD
    Expected output: READ_CLIPBOARD: deny

Replace deny with allow to re‑enable, or ignore to let the system decide based on the app’s foreground/background state (useful for location).

Step 5 – Apply Changes System‑Wide (Optional)

Some devices cache permission decisions until the next reboot. To make sure the new mode takes effect immediately, you can force‑stop the app:

  1. Run adb shell am force-stop com.whatsapp.
  2. Re‑open the app manually; the new App Ops mode will be enforced.

Step 6 – Reset an Operation to Its Default

If you later decide you want the system to manage the operation again, reset it:

  1. adb shell cmd appops reset com.whatsapp READ_CLIPBOARD
  2. Check with adb shell cmd appops get … – the line should now read READ_CLIPBOARD: default.

Step 7 – Bulk Editing with a Script (Advanced)

For power users who want to apply the same set of overrides to multiple apps, a short Bash script can save time. Below is an example that blocks clipboard access for a list of messaging apps:

#!/bin/bash
APPS=("com.whatsapp" "org.telegram.messenger" "com.facebook.orca")
for pkg in "${APPS[@]}"; do
  echo "Blocking clipboard for $pkg"
  adb shell cmd appops set "$pkg" READ_CLIPBOARD deny
  adb shell cmd appops set "$pkg" WRITE_CLIPBOARD deny
done

Save the script, make it executable (chmod +x block_clipboard.sh), and run it while your phone is connected. The script loops through each package and applies the same deny mode.

Common Mistakes & Troubleshooting

  • Operation name typo: App Ops is case‑sensitive. Using read_clipboard instead of READ_CLIPBOARD will return Unknown operation. Double‑check the exact spelling from the get output.
  • Permission resets after reboot: On some OEM skins (e.g., Xiaomi, OnePlus), a custom battery‑optimization service may revert App Ops changes. In that case, add the app to the device’s “Do not optimize” list under Settings > Battery > Battery optimization.
  • App crashes after denying a critical operation: Some apps assume certain operations are always allowed (e.g., a camera app needing CAMERA). If the app crashes, reset that operation to allow or default.
  • “Permission denied” error from ADB: Ensure you are running the terminal with administrator rights (Windows) or using sudo (Linux/macOS). Also verify that USB debugging is still enabled.

Safety Warning

Changing App Ops can break app functionality. Only modify operations you understand. If an app stops working, reset the operation to default or allow and test again.

When to Use App Ops vs. Standard Permissions

Use the regular Settings UI for most cases – it’s simpler and less risky. Reserve App Ops for these scenarios:

  • You want to block a specific sub‑operation that the UI groups together (e.g., clipboard access while keeping other data‑sharing permissions).
  • You are troubleshooting an app that misbehaves after a permission change and need to isolate the offending operation.
  • You want a temporary deny that can be toggled without navigating deep menus each time.

Wrapping Up

App Ops gives you a level of control that the standard permission manager hides. By using ADB you can list, modify, and reset individual operations without rooting your device. Remember to test each change, keep a note of the original state, and revert if you notice instability. With this workflow you can tighten privacy, reduce background activity, and gain a deeper understanding of how Android apps interact with your device.

User Comments (0)

Add Comment
We'll never share your email with anyone else.