惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
www.infosecurity-magazine.com
www.infosecurity-magazine.com
L
LINUX DO - 最新话题
N
News | PayPal Newsroom
S
Security Affairs
W
WeLiveSecurity
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Webroot Blog
Webroot Blog
Spread Privacy
Spread Privacy
A
Arctic Wolf
T
Troy Hunt's Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
Cybersecurity and Infrastructure Security Agency CISA
T
Threat Research - Cisco Blogs
V2EX - 技术
V2EX - 技术
Scott Helme
Scott Helme
Google Online Security Blog
Google Online Security Blog
Schneier on Security
Schneier on Security
F
Fortinet All Blogs
U
Unit 42
爱范儿
爱范儿
腾讯CDC
S
Security @ Cisco Blogs
PCI Perspectives
PCI Perspectives
Hacker News - Newest:
Hacker News - Newest: "LLM"
Apple Machine Learning Research
Apple Machine Learning Research
C
CERT Recently Published Vulnerability Notes
Security Latest
Security Latest
Y
Y Combinator Blog
S
Schneier on Security
Cisco Talos Blog
Cisco Talos Blog
T
The Blog of Author Tim Ferriss
Hugging Face - Blog
Hugging Face - Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
IT之家
IT之家
K
Kaspersky official blog
Security Archives - TechRepublic
Security Archives - TechRepublic
博客园 - 聂微东
Cloudbric
Cloudbric
V
V2EX
H
Help Net Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
小众软件
小众软件
TaoSecurity Blog
TaoSecurity Blog
T
Tor Project blog
G
Google Developers Blog
人人都是产品经理
人人都是产品经理
GbyAI
GbyAI
MyScale Blog
MyScale Blog

Hacker News

Introducing Claude Opus 4.7 Qwen Studio The Future of Everything is Lies, I Guess: Where Do We Go From Here? GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis Moving a large-scale metrics pipeline from StatsD to OpenTelemetry / Prometheus GitHub - Nightmare-Eclipse/RedSun: The Red Sun vulnerability repository GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. GitHub - macOS26/Agent: Any AI, replaces Claude Code, Cursor, OpenClaw. Over 18 LLM providers (Claude, OpenAI, Gemini, Ollama, Zai, HF, Qwen) wired into a native Mac app that writes code, builds Xcode projects, bumps versions, manages git, automates Safari, use AppleScript, JS or Accessibility, extend Agent! w/ MCP Servers, run tasks from your iPhone via Messages. YouTube now lets you turn off Shorts I Made a Terminal Pager Burgers | マクドナルド公式 Commands — HackerNews CLI documentation ChatGPT for Excel PiCore - Raspberry Pi Port of Tiny Core Linux Live Nation illegally monopolized ticketing market, jury finds Google Broke Its Promise to Me. Now ICE Has My Data. Founding Engineer at Adaptional | Y Combinator CRISPR takes important step toward silencing Down syndrome’s extra chromosome GitHub - saffron-health/libretto: The AI toolkit for building reliable browser automations US v. Heppner (S.D.N.Y. 2026) no attorney-client privilege for AI chats [pdf] Unexpected €54k billing spike in 13 hours: Firebase browser key without API restrictions used for Gemini requests Retrofitting JIT Compilers into C Interpreters IPv6 – Google The Accursèd Alphabetical Clock Cybersecurity Looks Like Proof of Work Now Fragments: April 14 Cal.com Goes Closed Source: Why AI Security Is Forcing Our Decision | Cal.com - Scheduling Software for Online Bookings Laravel raised money and now injects ads directly into your agent When moving fast, talking is the first thing to break Too much Discussion of the XOR swap trick – Heather Cafe Introduction to Spherical Harmonics for Graphics Programmers The Grand Line Building a Z-Machine in the worst possible language High-Level Rust: Getting 80% of the Benefits with 20% of the Pain GitHub - duguyue100/midnight-captain: Inspired by Midnight Commander, tailored to my taste. How to build a `git diff` driver · Jamie Tanna | Software Engineer Center for Responsible, Decentralized Intelligence at Berkeley The Local Universe’s Expansion Rate Is Clearer Than Ever, but Still Doesn’t Add Up - A new synthesis of astronomical measurements confirms a persistent mismatch that could point to physics beyond current models The air throughout our homes is infused with microplastics. But there are things you can do to breathe less of them The disturbing white paper Red Hat is trying to erase from the internet – OSnews The Future of Everything is Lies, I Guess: Annoyances ‘Abhorrent’: the inside story of the Polymarket gamblers betting millions on war Productive procrastination — Max van IJsselmuiden maps, territory and LMs 447 Terabytes per Square Centimetre at Zero Retention Energy: Non-Volatile Memory at the Atomic Scale on Fluorographane Show HN: Pardonned.com – A searchable database of US Pardons 20 Years on AWS and Never Not My Job The Seasons are Wrong Artemis II crew splashes down near San Diego after historic moon mission We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs How a dancer with ALS used brainwaves to perform live On filing the corners off my MacBooks Installing every* Firefox extension OpenClaw’s memory is unreliable, and you don’t know when it will break Steve Blank Nowhere Is Safe Chimpanzees in Uganda locked in vicious 'civil war', say researchers watgo - a WebAssembly Toolkit for Go linux/Documentation/process/coding-assistants.rst at master · torvalds/linux GitHub - callumlocke/json-formatter: Makes JSON easy to read. Founding Product Engineer at Bild AI | Y Combinator A compelling title that is cryptic enough to get you to take action on it GitHub - Keychron/Keychron-Keyboards-Hardware-Design: Industrial design files for Keychron keyboards and mice. 100+ models with CAD assets in STEP, DXF, DWG, and PDF. Source-available, with commercial use allowed for original compatible accessories within the license terms. [ANNOUNCE] WireGuardNT v0.11 and WireGuard for Windows v0.6 Released 1D-Chess Helium Is Hard to Replace Cooperative Vectors Introduction | Evolve Keeping a Postgres queue healthy — PlanetScale Our response to the Axios developer tool compromise Do Americans read print books, e-books or audiobooks more? The Zettelkasten Method in Obsidian: A Practical Setup Guide Artemis II Is Competency Porn and We Are Starving For It WeakC4 Flight Viz — Cockpit View A Mexican surveillance giant you’ve never heard of is now watching the U.S. border Surelock: Deadlock-Free Mutexes for Rust RISC-V 101 – what is it and what does it mean for Canonical? | Ubuntu The Problem That Built an Industry How Much Linear Memory Access Is Enough? | Solidean Investigating Split Locks on x86-64 Simplest hash functions Sybilproof reputation mechanisms (2005) [pdf] What is a property? How Complex is my Code? Static code analysis in Kotlin — tools overview Toffoli gates are all you need PGLite evangelism dcmake: a new CMake debugger UI Clojure on Fennel part one: Persistent Data Structures Fragments: April 2 Python Release Python install manager 26.1 The Life and Death of the Book Review - Liberties Introducing Database Traffic Control — PlanetScale Bitcoin miners are losing $19,000 on every BTC produced as difficulty drops 7.8% God sleeps in the minerals Building slogbox Apple Silicon and Virtual Machines: Beating the 2 VM Limit Who was “Not Even Wrong” first? Pokemon Evolution Vs Darwinian Evolution The APL Programming Language Source Code
GitHub - jo-duchan/tapflow: Self-hosted iOS & Android simulator streaming for the whole team
duchanjo · 2026-06-10 · via Hacker News

tapflow

A self-hosted Appetize / BrowserStack alternative for mobile QA teams

Run iOS simulators and Android emulators in any browser — no toolchain setup, no device pool, no cloud uploads.
Your builds, streams, and recordings stay on infrastructure you control.

MIT License Node.js ≥ 20 macOS Agent Latest release Last commit Roadmap

📖 Docs  ·  🚀 Quick Start  ·  🎥 Demo  ·  🎬 Setup

new-demo.mp4

v0.x: tapflow is under active development. Breaking changes may appear in minor versions until v1.0.0. See ROADMAP for the full plan.


Why tapflow?

Mobile QA usually depends on access to simulators, emulators, or physical devices — and that access is uneven across a team.

For mobile developers it means opening Xcode or Android Studio on a Mac. For everyone else, it often means asking a mobile developer every single time:

Backend developer — "How do I install the sandbox build to check what was deployed?"

Product manager — "I keep installing and removing versions just to compare behavior."

Designer — "I need to check the layout across screen sizes, but I don't have the right devices."

Physical devices add their own overhead — OS-version coverage, availability, charging, storage, handoff. Cloud simulator services solve access, but they require uploading internal builds to a third-party service and paying for remote devices while your own Macs can already run the same simulators.

We hit this exact problem, so we built tapflow.

Solution The catch
Appetize / BrowserStack Recurring cost — and app builds are uploaded to a third-party cloud
Physical devices Cost, availability, OS coverage, management overhead
Xcode / Android Studio Each teammate needs a Mac and a full mobile toolchain
tapflow Reuse your own Macs — data stays on infrastructure you control, and the whole team does QA from a browser

What tapflow does

tapflow connects three parts:

  1. A self-hosted relay server (Linux or Mac)
  2. A macOS agent that drives iOS simulators and Android emulators
  3. A browser dashboard for the rest of the team

The agent connects outbound to the relay. Teammates open the dashboard, pick an available device, and interact with it remotely — while the simulators and emulators keep running on your own Macs.

What tapflow is not

tapflow doesn't replace native mobile development tools. Mobile developers still use Xcode, Android Studio, and their build tooling. tapflow makes the running simulators and emulators accessible to the rest of the team through a browser — it isn't an automation framework or a device farm.

How it works

Browser (your team)  ←─ WebSocket ─→  Relay Server  ←─ WebSocket (outbound) ─→  Mac Agent
                                    (Linux / Mac)                           (iOS · Android)
  1. The Mac Agent connects outbound to the relay — no inbound firewall rules needed.
  2. Anyone on the team opens the dashboard in any browser and sees all available devices.
  3. Touch events are forwarded in real time; the screen streams back to the browser.
  4. The relay also serves the dashboard SPA on the same port — no separate web server needed.

Quick Start

1. Install

npm install -g tapflow
# or: yarn global add tapflow  |  pnpm add -g tapflow

2. Set up the environment

On the Mac that will run an agent, install the simulator/emulator prerequisites in one step:

Skip this on a relay-only server (Linux). See Environment Setup for details.

3. Start relay + agent

tapflow start
# ✓ Relay started on http://localhost:4000
# ✓ iOS Agent connected (3 simulators available)

This starts both the relay and the agent on the same Mac (local mode).

4. Create the first admin account

Open http://localhost:4000 in your browser. tapflow redirects you to /setup to create the admin account.

Headless server? Use tapflow admin init to create the admin account via CLI instead.

5. Open the dashboard

Navigate to http://localhost:4000 and sign in with the account you just created.

Having issues? Run tapflow doctor to re-check prerequisites at any time.

Requirements

Component Requirements
Relay server Node.js ≥ 20, any OS (Linux/macOS), ~512 MB RAM
iOS Agent macOS, Xcode + iOS Simulator runtime (or run tapflow setup ios), Node.js ≥ 20
Android Agent macOS, Java + Android SDK with an AVD (or run tapflow setup android), Node.js ≥ 20
Browser (QA) Any modern browser — Chrome, Firefox, Safari, Edge

Agents run on macOS only (they drive the iOS Simulator and Android emulator on a Mac). The relay runs anywhere.

Features

  • No mobile toolchain for QA users — teammates test from a browser without installing Xcode, Android Studio, or local simulator tooling.
  • Self-hosted by default — app builds, device streams, recordings, and account data stay on infrastructure you control.
  • Use your existing Mac setup — run agents on Macs that already have the iOS Simulator or Android emulator available.
  • API-first — REST endpoints and Personal Access Tokens support CI/CD and AI-agent workflows.

What's included:

  • Browser streaming — iOS & Android at ~30 fps, no extra app on the device. Both stream H.264 through a 2-tier decoder (WebCodecs on secure contexts, WASM/tinyh264 on plain HTTP), which removes the media-element buffer from the decode path. Resolution adapts to the connection — native on a secure context, downscaled on plain-HTTP LAN.1
  • Codec fallback — the stream negotiates the codec per client and falls back to JPEG when a hardware or WASM decoder isn't available, so older browsers still work.
  • Touch, swipe & pinch — real-time input forwarded to the simulator or emulator.
  • Deeplink toolbar — open supported deeplinks directly from the QA toolbar.
  • Keyboard shortcuts — trigger simulator toolbar actions from the keyboard.
  • App Center — upload .app.zip / .apk and track builds by status (Backlog / In Progress / Done / Rejected).
  • Session recordings — record and share QA sessions, kept on the relay for ~72 hours, then purged automatically.
  • Screenshot REST endpointGET /api/v1/sessions/:sessionId/screenshot for CI and AI agents.
  • Mac resource monitoring — CPU & RAM per agent, to spot overloaded hosts before assigning sessions.
  • Team management — invite links, roles (Admin / Developer / QA / Viewer), and Personal Access Tokens.
  • MCP Server (experimental)@tapflowio/mcp-server lets Claude Code and other LLM agents control simulators as native tools.

1 On a real LAN, decode-to-present measures in the low tens of milliseconds (p50 ~11–17 ms with the WASM software decoder; faster with WebCodecs on HTTPS); end-to-end "glass-to-glass" latency adds your network's round trip on top. See the performance & latency reference for the full measurements, conditions, and known limitations.

Security & Privacy

tapflow is self-hosted by design — build files, device streams, and session recordings stay on infrastructure you control, never sent to a third-party service.

Data Where it stays
App binaries (.app.zip / .apk) Relay storage
Device streams (video · touch) The relay ↔ browser path you host
Session recordings Relay storage; expire after 72h, then purged
Account & team data The relay's SQLite DB
Third-party simulator cloud Not required
  • LAN-first — the agent ↔ relay leg is internal traffic; the device stream never transits a third party.
  • Authenticated by default off-host — the relay accepts unauthenticated connections only from its own machine (localhost). Browsers reaching it from elsewhere sign in; agents on another machine present an agent-scope token.
  • PAT + roles — Personal Access Tokens carry scopes (builds:write for CI uploads, agent for remote agents), and team roles (Admin / Developer / QA / Viewer) govern dashboard access.

Found a vulnerability? See SECURITY.md. For the full model, read Security & Privacy.

Self-Hosting

Local (single Mac)

Relay and agent on the same machine — ideal for a single developer or small team.

Team (separate relay server)

Run the relay on a Linux server or dedicated Mac. Each Mac with simulators runs the agent.

Relay server:

# Recommended: PM2 for automatic restarts
npm install -g pm2 tapflow
JWT_SECRET=$(openssl rand -hex 32) pm2 start tapflow --name relay -- relay start
pm2 save && pm2 startup

Each Mac agent:

tapflow agent start --relay wss://your-relay-url --token <agent-token>

A relay on a different machine accepts an agent only with an agent-scope token — create one in Settings → Tokens (Admin only). Agents on the relay's own machine (tapflow start) need no token. See Remote relay authentication.

For nginx / Caddy reverse proxy setup and external access, see Self-Hosting the Relay.

CLI Reference

Command Description
tapflow start Start relay + agent together (local mode)
tapflow relay start Start relay only
tapflow agent start --relay <url> [--token <pat>] Start agent and connect to a relay (remote relays need an agent-scope token)
tapflow init Scaffold tapflow.config.json
tapflow admin init Create the first admin account (CLI fallback)
tapflow doctor [platform] Diagnose prerequisites (Node, iOS, Android)
tapflow setup [platform] Install & configure the local environment
tapflow devices List available simulators and emulators
tapflow boot <name|udid> Boot a simulator or emulator
tapflow status Show connected agents, devices, active sessions
tapflow reset Shut down all simulators and emulators
tapflow logs Show recent relay log entries

Full reference → CLI docs

Documentation

www.tapflow.dev

Getting Started

Setup

Dashboard

AI Agent

Reference

Troubleshooting

Contributing

tapflow is actively developed and PRs are welcome — see CONTRIBUTING.md for branch strategy, commit conventions, and an architecture overview. For deep dives, the contributor notes cover the SimulatorKit reverse-engineering and the streaming render pipeline.

Requirements: Node.js ≥ 20, pnpm ≥ 9

git clone https://github.com/jo-duchan/tapflow.git
cd tapflow
pnpm install
pnpm dev

License

MIT — Copyright © 2026-present tapflow contributors

tapflow bundles scrcpy-server (Apache-2.0) for Android screen streaming. See NOTICE for full attribution.