मैसेज, मंजूरियां और पोस्ट उन mobile apps के अंदर होते हैं जिनकी कोई API नहीं, इसलिए ज्यादातर automation browser पर ही रुक जाती है। और बिना guardrails के AI को unlocked phone देना बिल्कुल नहीं चलता।
Melaya इसे governed बनाता है: एजेंट आपके phone को एक explicit per-app allowlist के तहत चलाते हैं, जिसे एक tap में रद्द किया जा सकता है और स्क्रीन पर live देखा जा सकता है।
Android पर Melaya app install करें, QR code scan करें, और वे permissions दें जिन्हें आप कभी भी रद्द कर सकते हैं।
app by app access दें। allowlist से बाहर की हर चीज़ पहुंच से दूर रहती है।
एजेंट स्क्रीन देखते हैं, एक-एक कदम action लेते हैं और हर नतीजे की जांच करते हैं। किसी भी वक्त live देखें, मंजूरी दें या रोकें।
Melaya एक रिमोट MCP सर्वर है, इसलिए एक ही एंडपॉइंट किसी भी MCP क्लाइंट को इस पेज के फ़ोन टूल्स देता है। आप OAuth से साइन इन करते हैं और तय करते हैं कि क्या देना है। सुरक्षा-सीमाएँ वैसी ही रहती हैं, क्योंकि उन्हें फ़ोन लागू करता है।



api.melaya.org/mcp OAuth 2.1एक एंडपॉइंट पर 35 टूल्स। कुछ इंस्टॉल नहीं करना, कोई SDK नहीं। Melaya सेटिंग्स में डिसकनेक्ट करें और कनेक्शन खुद को नवीनीकृत नहीं कर पाएगा।
Device Control agents को paired Android phone एक tool surface की तरह देता है. Agent observe करता है, छोटा action चुनता है, phone result का इंतजार करता है और उसी logs, HITL, model routing और run history के साथ आगे बढ़ता है.
phone.open_app()Read the accessibility tree when structured labels are available, or capture a screenshot when visual layout matters.
phone.read_screen()Tap, click text, input text, scroll, swipe, go home, go back, open apps, open URLs, and wait for UI state changes.
phone.tap()Run phone workflows from the workspace where teams already manage agents, templates, approvals, connectors, and history.
User installed apps देखता है, search करता है और per-app access देता है. Server command queue से पहले allowlist check करता है. Android execution से पहले foreground app फिर check करता है.
Search installed apps
Server checks the allowlist. The phone checks the foreground app again before executing.
Phone UI is dynamic. The correct automation pattern is observe, act, verify, then continue. Melaya avoids blind tap chains from memory.
Read the current app, screen tree, or screenshot so the agent knows what is actually visible.
Choose the smallest safe next action and check app scope before the command is accepted.
Android Accessibility performs the tap, gesture, text input, app launch, or global action.
The phone posts the result, the UI updates, and the run pauses for HITL when the action is sensitive.
APK के अंदर users को recursive phone preview नहीं चाहिए. उन्हें visible working overlay, immediate stop, HITL state और run finish, kill या pause होने पर Melaya app में return चाहिए.

लाइवपूरा नियंत्रण दिखता है, तुरंत रोकने का विकल्प है, और रन खत्म होते ही आपका ऐप पहले जैसा हो जाता है।
Android जरूरी steps user के control में रखता है. Melaya इसे clear path बनाता है.
Install or open the Melaya Android app.
Pair the phone with QR or deep link.
Allow restricted settings if Android asks because the app is sideloaded.
Enable Melaya Phone Control in Accessibility settings.
Grant the apps agents may access from Apps on your phone.
Device Control is intentionally explicit about ownership, scope, visibility, and revocation. It does not rely on prompt wording as the only safety layer.
Android AI एजेंट्स, ऐप एक्सेस, मानवीय स्वीकृति, गोपनीयता, पेयरिंग, लाइव दृश्यता, बैटरी उपयोग और मोबाइल ऑटोमेशन की सीमाओं पर स्पष्ट उत्तर।
नहीं। अवरुद्ध ऐप्स को सर्वर पॉलिसी नकारती है और एक्शन चलने से पहले डिवाइस पर फिर से जांच होती है।
नहीं। Android में Accessibility उपयोगकर्ता को मैन्युअली चालू करनी होती है। साइडलोडेड APK के लिए प्रतिबंधित सेटिंग्स की अनुमति भी देनी पड़ सकती है।
नहीं। मिरर का इरादा Socket.IO के साथ बाइनरी फ्रेम, canvas रेंडरिंग, और दबाव में लेटेस्ट-फ्रेम-जीतता है ड्रॉपिंग का है।
नहीं। iOS थर्ड-पार्टी ऐप्स को Android जैसा Accessibility नियंत्रण नहीं देता। iOS का कोई भी वर्जन चाहिए तो उसके लिए अलग Shortcuts या App Intents डिज़ाइन चाहिए होगा।
वर्किंग ओवरले हमेशा ऊपर रहता है जिसमें रोकें बटन होता है। एक टैप से रन कैंसल होता है और फोन पहले वाली स्थिति में वापस आ जाता है।
लाइव मिरर केवल तभी एक प्रमाणित सॉकेट पर स्ट्रीम होता है जब आप देख रहे हों, और फ्रेम कभी स्टोर नहीं होते। एजेंट केवल उन्हीं ऐप्स को पढ़ते हैं जिन्हें आप अनुमति देते हैं।
हां। हर डिवाइस में एक रद्द करने योग्य टोकन होता है जिसे आप Device Control से कभी भी डिलीट कर सकते हैं, जिससे तुरंत उसकी पहुंच खत्म हो जाती है।
कैप्चर और पोलिंग केवल एक्टिव रन के दौरान चलते हैं और खत्म होते ही बंद हो जाते हैं, इसलिए बैटरी पर असर न्यूनतम रहता है।
डाउनलोड से पहले सुपरवाइज़्ड रन तक दस मिनट।
मुफ़्त शुरुआत · अंतर्निहित मानव नियंत्रण · मॉडल लॉक-इन नहीं