Android’s public permission manager hides many of the granular controls that power users and privacy‑conscious folks would like to see. App Ops is a hidden subsystem that records every operation an app requests – from accessing the camera to reading your clipboard – and lets you toggle each operation individually. While the UI is hidden, you can reach it through adb (Android Debug Bridge). This guide walks you through enabling ADB, listing an app’s operations, changing them safely, and handling the most common pitfalls.
Android’s Settings > Apps > Permissions page shows only the permission groups (e.g., Camera, Location). Within a group, an app may request multiple low‑level operations, some of which you might not need. App Ops exposes those operations, allowing you to:
Because App Ops changes are stored in the system’s appops database, they survive reboots and do not require root.
Prerequisites
If your device is running Android 12 or newer, the appops command is still present, but the syntax for some operations changed slightly. The steps below cover Android 9–13; later versions are similar.
adb devices. You should see your device’s serial number followed by device.
adb devices
List of devices attached
ABC1234567 device
unauthorized, accept the RSA fingerprint prompt on the phone.Successful connection is essential; otherwise the following commands won’t reach the phone.
You need the app’s package name (e.g., com.whatsapp). You can find it in Settings > Apps, tap the app, then scroll to the bottom where the package name is shown, or use ADB:
adb shell pm list packages | grep -i "keyword", replacing keyword with part of the app name.
adb shell pm list packages | grep -i whatsapp
package:com.whatsapp. The string after the colon is the package name.Now you can see every operation the app has requested and its current mode.
adb shell cmd appops get com.whatsapp
GET_USAGE_STATS: allow
CAMERA: allow
READ_CLIPBOARD: deny
WRITE_CLIPBOARD: deny
ACCESS_FINE_LOCATION: allow
OPERATION: MODE. allow means the operation is permitted, deny blocks it, and default follows the app’s declared permission.If you see default for an operation you care about, the app’s permission group is currently granted, but you can still override it.
Use the set sub‑command to override a specific operation.
READ_CLIPBOARD).adb shell cmd appops set com.whatsapp READ_CLIPBOARD deny
adb shell cmd appops get com.whatsapp | grep READ_CLIPBOARD
Expected output: READ_CLIPBOARD: deny
Replace deny with allow to re‑enable, or ignore to let the system decide based on the app’s foreground/background state (useful for location).
Some devices cache permission decisions until the next reboot. To make sure the new mode takes effect immediately, you can force‑stop the app:
adb shell am force-stop com.whatsapp.If you later decide you want the system to manage the operation again, reset it:
adb shell cmd appops reset com.whatsapp READ_CLIPBOARDadb shell cmd appops get … – the line should now read READ_CLIPBOARD: default.For power users who want to apply the same set of overrides to multiple apps, a short Bash script can save time. Below is an example that blocks clipboard access for a list of messaging apps:
#!/bin/bash
APPS=("com.whatsapp" "org.telegram.messenger" "com.facebook.orca")
for pkg in "${APPS[@]}"; do
echo "Blocking clipboard for $pkg"
adb shell cmd appops set "$pkg" READ_CLIPBOARD deny
adb shell cmd appops set "$pkg" WRITE_CLIPBOARD deny
done
Save the script, make it executable (chmod +x block_clipboard.sh), and run it while your phone is connected. The script loops through each package and applies the same deny mode.
read_clipboard instead of READ_CLIPBOARD will return Unknown operation. Double‑check the exact spelling from the get output.CAMERA). If the app crashes, reset that operation to allow or default.sudo (Linux/macOS). Also verify that USB debugging is still enabled.Changing App Ops can break app functionality. Only modify operations you understand. If an app stops working, reset the operation to default or allow and test again.
Use the regular Settings UI for most cases – it’s simpler and less risky. Reserve App Ops for these scenarios:
App Ops gives you a level of control that the standard permission manager hides. By using ADB you can list, modify, and reset individual operations without rooting your device. Remember to test each change, keep a note of the original state, and revert if you notice instability. With this workflow you can tighten privacy, reduce background activity, and gain a deeper understanding of how Android apps interact with your device.









