Use an Android phone as a mobile proxy
Pair an Android phone over its own mobile data and point profiles at it. Its carrier address becomes the exit, and you can change it on demand.
On this page
A phone with a SIM is a mobile proxy you already own. Pair one with LoginDeck and its carrier address becomes the exit for any profile you point at it โ a genuine consumer mobile address, which is the kind of exit strict platforms trust most.
The phone dials the LoginDeck server over its own mobile data, and the server hands that connection back as a proxy. Nothing listens on the phone and there is no port to open, which is why it works behind carrier NAT, and why the phone can be anywhere โ in a drawer, in another country, with wifi off.
What you need
An Android phone (Android 8.0 or newer) with mobile data, and a signed-in LoginDeck account. Phones are not limited by plan. There is no iPhone app.
๐ฑ Pair a phone#
- In the left sidebar, under Workspace, click Proxy devices.
- Click + Create device.
- Fill in Device name (required โ for example
Samsung S24 โ carrier), and optionally Model and Notes. - Click Create device. The Connect {name} sheet opens by itself, with two QR codes.
- On the phone, turn wifi off and leave mobile data on. Everything below travels over the SIM.
- Scan the first code to download
LoginDeck.apkand install it. Android will ask you to allow installing unknown apps for your browser. - Scan the second code. It opens that device's own page, which offers Open in the LoginDeck app โ that hands the app its key and port. Pasting the link into the app's pairing box does the same thing.
- In the app, turn the PROXY switch on. The row here flips to Active within a few seconds, and the exit address appears once the first heartbeat lands, about 30 seconds later.
You can reopen this sheet at any time with the row's Setup button.
Android 13 and newer: one extra tap
Android greys out a sideloaded app's accessibility switch โ "Controlled by Restricted Setting" โ and that switch is one of the ways the phone changes its own address. Lift it once per install: in the app tap Open App info, then โฎ at the top right โ Allow restricted settings. The menu item only appears after the blocked switch has been tried once.
If the phone says "Already paired โ unpair first to move this phone", tap Unpair in the app and scan again.
๐ Point a profile at it#
- Open a profile (โฏ โ Edit) and go to the Proxy tab.
- Under Connection, choose Proxy device.
- Pick the phone under Phone, then Save changes.
Or, from the list, click the Proxy & Location cell โ Proxy device โบ โ the phone.
A bound phone wins over a typed proxy: the device's address is the source of truth. Every profile bound to the same phone shares its address, because a phone has one radio โ so use a phone for the accounts that need a mobile exit, not for a whole deck that must look unrelated.
๐ Change its IP#
The phone detaches its radio and reconnects, which asks the carrier for a new address.
- Row button โณ Rotate IP โ "{name}: rotation queued โ the new address lands within ~30s".
- Row button โป Check IP asks the server to fetch the address through the tunnel right now: "{name}: {address} โ moved from {previous}".
- On a profile row, โ in the Proxy & Location cell rotates the bound phone and waits for the new address.
Rotation needs the phone to be able to toggle its own radio. The app tries, in order: a rooted phone's own command; a privileged shell armed once over Android's Wireless debugging (silent, works with the screen off and locked, but has to be re-armed after a reboot); and an accessibility service that flips the airplane-mode switch exactly as a finger would (no root, no wifi, survives reboots โ but Android will not let it act behind a locked screen). If none is available the app reports "Radio control: not available" and Change IP is disabled rather than silently doing nothing.
If the phone is locked on that last route, LoginDeck offers the one-time fix before it queues anything: turn wifi on, Settings โ Developer options โ Wireless debugging โ on, then in the phone app open Change IP setup and pair with the 6-digit code and the port from Android's pairing dialog. After that, rotation works locked with wifi off.
Rotation settings#
The row's Settings button opens Rotation settings โ {name}:
| Setting | What it does | Default |
|---|---|---|
| Airplane-mode hold | How long the radio stays detached before reconnecting. Some carriers hand back the same address unless it is 20โ30 s | 5 seconds |
| Keep trying | Only stop once the address has actually changed, up to a number of attempts per press | On, 3 attempts |
| Unique address | Treat an address the phone held recently as "not changed", looking back a number of minutes | Off, 180 minutes |
| Rotate on a timer | Rotate every N minutes (0 = off). Runs only while the phone is on and reporting in; it does not catch up on missed rotations | 0 |
| Minimum gap | Refuse a rotation asked for sooner than this, rather than queueing it | 0 |
The History button shows every address this phone has held in the last 30 days, how often it changed, how many addresses repeated, and an estimate of how wide the carrier's pool looks. For a phone-bound profile, the same view is on the row โฏ menu as IP history.
๐ The Proxy devices page#
- Proxy status is a live check of the tunnel: Active means it is carrying traffic right now, Inactive means it is not.
- IP, Carrier, Country and Battery come from the phone's own heartbeat. Battery turns red under 20%.
- The chips above the table filter by All devices, Active and Inactive.
- Click a phone's name to rename it (name, model, notes). Renaming does not disturb the tunnel, so a phone working in a drawer keeps working.
- The status pill in the page bar shows the server the phones dial and how many are active.
๐ When the phone drops out#
- The row goes Inactive, and profiles bound to it show (offline).
- Launching such a profile is refused:
phone "{name}" is offline โ start the agent on it first. LoginDeck does not fall back to your own address. - A phone that is only changing its IP still launches โ the browser opens and pages fail until the tunnel is back.
- On the phone: the switch should be on, mobile data on, and the app not "battery optimised" into being killed. The server treats a heartbeat as stale after about 2.5 minutes.
Removing a phone (โ โ Remove) revokes its key, so it stops carrying traffic immediately, and deletes its address history. Profiles bound to it then refuse to launch until you point them somewhere else.
โน๏ธ Good to know#
- Phones belong to the LoginDeck account, so your team members can use them from their own computers. Removing a member cuts off access.
- The Connect sheet also gives you the phone as a plain HTTP proxy (host, port, user, password) for use outside LoginDeck, and a Change IP link you can paste into other tools. Treat both as credentials: anyone holding either can use or rotate the phone.
- Battery and data: the tunnel is idle when nothing is browsing, but a phone carrying real traffic will use both. Keep it on a charger.
- Works the same on Windows and on a Mac โ the phone talks to the LoginDeck server, not to your computer.