claudeers.
// MCP Servers

jadx-mcp

MCP (Model Context Protocol) server as a jadx-gui plugin. Lets an AI client (Claude Code, Claude Desktop, or any MCP client) analyze the app currently loaded…

// MCP Servers[ cli ][ api ][ desktop ][ web ][ mobile ][ claude ]#claude#android#jadx-gui#mcp-server#reverse-engineering#mcp-servers$open-sourceupdated about 1 month ago
Actively maintained
100/100
last commit about 1 month ago
last release about 1 month ago
releases 1
open issues 0
// star history

Install with your AI

Paste into Claude Code, Cursor, or any agent — it reads the repo and wires the tool into your project.

Install and set up jadx-mcp (release-binary project) into my current project.
Found on https://claudeers.com/jadx-mcp
Repo: https://github.com/0xdad0/jadx-mcp
Homepage/docs: —
Detected install method: release-binary → inspect the README
Category: mcp-servers. Platforms: cli, api, desktop, web, mobile.
Read the repo's README for exact setup and env vars, then install it and wire it into my project.

Claudeers Health Verdict:
active; community-verified: false. Confirm the source before running anything.
// or install directly (release-binary)

Grab the latest release asset from GitHub.

# download a build from https://github.com/0xdad0/jadx-mcp/releases
// or clone
git clone https://github.com/0xdad0/jadx-mcp

// compatibility

Platformscli, api, desktop, web, mobile
Operating systems—
AI compatibilityclaude
License—
Pricingopen-source
LanguageJava

Get your FREE $2.50 API credits to access TickAtlas financial data ↗

jadx-mcp

MCP (Model Context Protocol) server as a jadx-gui plugin. Lets an AI client (Claude Code, Claude Desktop, or any MCP client) analyze the app currently loaded in jadx-gui: list/search classes, fetch decompiled Java or smali, per-method source, manifest components (main activity, application package), resources and strings.xml, cross-references (class/method/field level), and renames (class/method/field/package/variable) for deobfuscation loops.

Native implementation on the official MCP Java SDK - no Python shim, no external process. Server runs inside jadx-gui over streamable HTTP; host and port are configurable in the plugin's settings dialog (127.0.0.1:8090 by default).

Requirements

  • jadx-gui 1.5.6 (plugin API target).
  • jadx-gui running on Java 17+ (the MCP SDK and the plugin jar are Java 17 bytecode). The jadx-gui-x.y.z-with-jre-win bundle ships a recent JRE and works out of the box. If you launch jadx-gui.bat with a system JDK, check java -version first: on an older JVM jadx cannot load the plugin (UnsupportedClassVersionError in the jadx log).
  • To build: JDK 17+ and Gradle (or use the Gradle wrapper).

Launching the right JVM (Windows)

  • jadx-gui.exe (with-JRE bundle) uses its bundled JRE - always Java 17+, use this.
  • jadx-gui.bat uses the system JAVA_HOME. If yours is older than 17, point it at a recent JDK first:
$env:JAVA_HOME = "<custom_dir_location>"
jadx-gui.bat

The plugin is Java 17 bytecode by design: the official MCP Java SDK (2.x) is records-based and requires Java 17+, and mixing bytecode levels caused classloader issues in jadx's plugin loader. Keep jadx-gui on a JVM >= 17.

Build

Prerequisites: JDK 17+ (toolchain pinned to 21, any newer JDK works) and Gradle 9.x on the PATH. jadx-core and slf4j are compileOnly - no jadx install needed to build.

PowerShell:

cd jadx-mcp

# if your default JAVA_HOME is not a JDK 17+, point Gradle at one:
$env:JAVA_HOME = "<custom_dir_location>"

gradle jar      # fat jar -> build/libs/jadx-mcp-0.1.0.jar
gradle smoke    # headless e2e check: loads a real jar into jadx, starts the server on an
                # ephemeral port, runs raw JSON-RPC calls (initialize, tools/list for all
                # 27 tools, status, get_all_classes, get_class_source, get_method_by_name,
                # xrefs, renames, non-APK error paths) and stops it; prints "SMOKE OK"

What the jar contains:

  • Own classes (jadxmcp/*), compiled with --release 17.
  • MCP Java SDK 2.0.1 + Jackson 3 + Reactor + embedded Jetty 12 (ee11, servlet 6.1), unpacked into one fat jar (no shadow plugin; signatures and module-info.class stripped). Jetty instead of Tomcat because the jadx with-JRE bundle ships a stripped jlink runtime without java.management, which Tomcat requires.
  • META-INF/services/jadx.api.plugins.JadxPlugin — the ServiceLoader entry jadx picks up.
  • Transitive org.slf4j:slf4j-api is excluded so jadx's own slf4j binding wins.

Build layout:

src/main/java/jadxmcp/        JadxMcpPlugin (entry), McpServerManager (Jetty + MCP lifecycle),
                              JadxTools (all MCP tools), Settings (host+port persistence)
src/main/resources/META-INF/services/jadx.api.plugins.JadxPlugin
src/test/java/jadxmcp/        SmokeTest (run by gradle smoke)

Gradle details worth knowing if you touch the build:

  • gradle clean jar smoke for a from-scratch verify.
  • Toolchain comes from java.toolchain in build.gradle.kts — Gradle auto-downloads JDK 21 if JAVA_HOME doesn't provide it; setting JAVA_HOME just makes it instant.
  • To bump versions: val jadxVersion (plugin API target) and the mcp / jetty-ee11-servlet coordinates in build.gradle.kts. requiredJadxVersion in JadxMcpPlugin must match the jadx line you target.
  • gradle smokeLimited runs the same smoke test restricted to the jadx with-JRE module set (no java.management, no jdk.unsupported) — use it after any dependency change to make sure the server still loads in the stripped runtime.

Install

jadx plugins --install-jar jadx-mcp-0.1.0.jar

or copy the jar to ~/.jadx/plugins/ and restart jadx-gui. If an older version is installed, delete it first (same plugin id, duplicate jars in the plugins dir).

Use

  1. jadx-gui → open an APK/DEX/JAR.
  2. Menu Plugins → jadx-mcp: Settings... opens the single settings dialog:
    • Host (default 127.0.0.1) and Port (default 8090) — saved to ~/.jadx/jadx-mcp.properties on Start.
    • Start starts (or restarts with new host/port) the server; Stop stops it; the status line shows the running URL. No need to close the dialog: status updates live.
    • Warning: binding a non-loopback host (e.g. 0.0.0.0 or a LAN IP) exposes the server to the network — there is no authentication.
  3. Register with your MCP client (URL from the status line).

Claude Code (one-shot, no config editing):

claude mcp add --transport http jadx-mcp http://localhost:8090/mcp

With a non-default host/port, use the URL from the status dialog. Scope flag as needed: --scope project writes .mcp.json in the repo, default is user-local.

Claude Desktop - edit claude_desktop_config.json (Settings → Developer → Edit Config) and add under mcpServers:

{
  "mcpServers": {
    "jadx-mcp": {
      "type": "http",
      "url": "http://localhost:8090/mcp"
    }
  }
}

Restart Claude Desktop after editing. Both clients speak streamable HTTP, which is what the plugin serves.

  1. Stop with the Stop button in the same dialog (server also stops on jadx exit).

Smoke test (no client)

PowerShell:

$h = @{ Accept = "application/json, text/event-stream" }
$b = '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"smoke","version":"0"}}}'
$r = Invoke-WebRequest -Method Post http://localhost:8090/mcp -ContentType "application/json" -Headers $h -Body $b
$r.Headers["mcp-session-id"]   # session id -> server works

Tools

27 tools, all validated against a JSON schema by the SDK. Paginated tools take optional offset/limit (default 50, max 500).

ToolNotes
statusapp loaded, class/package/resource counts, manifest package
Classes
get_all_classespaginated, optional package prefix filter
search_classesclass name contains, case-insensitive
get_class_sourcedecompiled Java source (original or alias name)
get_smali_of_classDEX disassembly
search_classes_by_keywordfull-text over decompiled code (class:line:source matches), paginated; expensive on large apps
fetch_current_classclass the analyst is viewing in jadx-gui (node under caret), with source
Methods / fields
get_method_by_namesingle method source; signature fragment disambiguates overloads
search_method_by_namemethod name contains across all classes, paginated
get_methods_of_classmethods with flags, signatures, return types
get_fields_of_classfields with flags and types
Manifest (APK)
get_android_manifestdecoded AndroidManifest.xml
get_manifest_componentone component type (activity, activity-alias, service, receiver, provider), optional name filter
get_main_activity_classMAIN/LAUNCHER activity, with source
get_main_application_classes_namesclass names in the manifest application package, paginated
get_main_application_classes_codetheir full sources, paginated (default 10 per page — token heavy)
Resources
get_stringsdecoded res/values/strings.xml
get_all_resource_file_namespaginated, optional path filter
get_resource_filedecoded content of one resource
Renames (mutate the jadx project)
rename_classshort new name, GUI refresh included
rename_methodsignature fragment disambiguates overloads
rename_field
rename_packagefull new package name, cascades to all classes in it
rename_variablelocal var in a method; session-local (not persisted to saved jadx metadata)
Xrefs
xrefs_to_classall references to the class, paginated
xrefs_to_methodreferences + override-related methods, paginated
xrefs_to_fieldmethods accessing the field, paginated

Domain errors (class not found, no app loaded, binary resource, ambiguous overload) come back as isError tool results so the LLM can self-correct.

Security

  • Binds 127.0.0.1 by default; Origin/Host allowlist is built from the configured host.
  • Origin/Host header validation (http://localhost:* / localhost:*) to block DNS-rebinding and cross-origin requests from web pages.
  • No auth: keep it on localhost. Do not port-forward.

Known limits

  • No get_selected_text — the jadx plugin API (1.5.6 JadxGuiContext) exposes the node under the caret, not the raw text selection. fetch_current_class is the closest equivalent.
  • No debug_get_* tools (stack frames, threads, variables) — the plugin API has no debugger access. Use the jadx-gui debugger UI directly.
  • rename_variable is session-local: the new name shows in reloaded code but is not written to saved jadx metadata (.jadx files), unlike the class/method/field/package renames which go through the standard deobfuscation alias system.
  • Comments and headless (jadx-cli) operation are not implemented.

// faq

What is jadx-mcp?

MCP (Model Context Protocol) server as a jadx-gui plugin. Lets an AI client (Claude Code, Claude Desktop, or any MCP client) analyze the app currently loaded in jadx-gui.. It is open-source on GitHub.

Is jadx-mcp free to use?

jadx-mcp is open-source, so it is free to use.

What category does jadx-mcp belong to?

jadx-mcp is listed under mcp-servers in the Claudeers registry of Claude-compatible tools.

22 views
★ 14 stars
unclaimed
updated about 1 month ago

// embed badge

jadx-mcp on Claudeers
[![Claudeers](https://claudeers.com/api/badge/jadx-mcp.svg)](https://claudeers.com/jadx-mcp)

// retro hit counter

jadx-mcp hit counter
[![Hits](https://claudeers.com/api/counter/jadx-mcp.svg)](https://claudeers.com/jadx-mcp)

// reviews

// guestbook

0/500

// related in MCP Servers

🔓

f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete…

// mcp-serversf/⟨HTML⟩★ 171,127◷ NOASSERTION[ claude ]
🔓

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Gemini CLI & Hermes Agent. Only official website: ccswitch.io

// mcp-serversfarion1231/⟨Rust⟩★ 136,484◷ MIT[ claude ]
🔓

🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman

// mcp-serversJuliusBrussee/⟨JavaScript⟩★ 107,719◷ MIT[ claude ]
🔓

An open-source AI agent that brings the power of Gemini directly into your terminal.

// mcp-serversgoogle-gemini/⟨TypeScript⟩★ 107,167◷ Apache-2.0[ claude ]
→ see how jadx-mcp connects across the ecosystem