Debugging & Profiling
When UI automation is not enough, use these commands to collect runtime evidence from the app or device.
What you can capture
- Session app logs for targeted debugging windows
- Network inspection from recent HTTP(s) entries in app logs via
network dump - Audio-level probes for browser media elements and host-rendered simulator/emulator audio
- Focused performance evidence with
perf frames,perf memory, and native profile reports - Apple crash symbolication with
debug symbols - Screenshots, recordings, and replayable repro flows
React Native component internals
To inspect the React Native component tree, props, state, hooks, or render profiling, use react-devtools:
react-devtools runs a pinned version of agent-react-devtools and passes your arguments to it.
For React Native apps, overlays, Metro/Fast Refresh blockers, and routing to React DevTools or debugging evidence, start with agent-device help react-native. For slow-flow investigations, combine help react-devtools for the narrow React profile window with help debugging for log markers, network/audio evidence, traces, and perf samples. Start with one bounded survey: the profile stop summary, the slow and rerenders tables with a --limit, and timeline only when commit timing matters. Then drill into a specific @c ref with profile report instead of raising the profile slow limit again and again.
React Native warning and error overlays come from the app. Treat them as findings or blockers: capture them, check react-devtools errors when connected, run agent-device react-native dismiss-overlay when the overlay is unrelated, then re-snapshot and report the overlay.
For permission prompts and other alerts already on screen, see Wait and alerts.
React Native JS memory through CDP
Use cdp when a React Native or Expo app exposes a Metro CDP target and you need JavaScript heap usage, heap snapshots, allocation hotspots, retained-object diffs, retaining paths, or a small runtime eval to confirm JS state.
cdpruns a pinned CDP helper through npm. The first run may download the package; later runs reuse the npm cache.- Every argument after
cdpis passed to the CDP helper. Putagent-deviceglobal flags beforecdpwhen you need the outer CLI to consume them. - In remote bridge sessions, run
connectfirst and omit--urlfortarget listortarget select;agent-devicederives the Metro CDP URL from the prepared remote runtime. - Start with
memory usage sample --gcfor a quick JS heap growth signal. Use snapshot diff andleak-tripletfor proof that objects stayed retained after cleanup. cdphas no single leak-report command. Build one frommemory usage diff,memory snapshot diff,memory snapshot leak-triplet, andmemory snapshot retainers.- Keep raw heap snapshots and allocation exports as artifacts. Summarize heap deltas, top retained classes/shapes, leak-triplet rows that stayed high after cleanup, and shortest useful retaining paths.
- React Native/Hermes supports only part of browser CDP. If a method is unsupported, keep the selected target and fall back to heap usage samples plus heap snapshots.
- Prefer
perf cpu,trace,network,logs, andreact-devtoolsovercdp profile cpu,trace,network, andconsole. - Use
perf memory sampleandperf memory snapshotfor native/process memory. Usecdponly for JavaScript heap evidence.
Capture a clean repro window
This flow gives you logs, recent network activity, and a quick metrics sample from the active app session, starting from an empty log.
open prints Session state: <path>. That directory holds the run's request diagnostics, Apple runner output, and app logs; see Find a session's logs and artifacts.
When a command fails, use --json to inspect error.details.stderr when it is present. Diagnostic stderr is secret-redacted and retains up to 8,192 characters; longer output keeps its beginning and end with a truncation marker between them. Other diagnostic strings remain limited to 400 characters. Compact retry summaries may retain less output.
When a command fails against a remote daemon, the Diagnostics Log: path is always on your machine:
agent-device downloads the failing request's record over the same base URL and token into
<state-dir>/remote-diagnostics/<session>/requests/<request-id>.ndjson, so a CI job can keep it as a build
artifact. If the download fails, the line reads unavailable with the remote daemon, the
request id, and the reason — never a path on the daemon host.
On iOS simulators, logs scope by bundle id and the resolved app executable. For launch-time stdout/stderr, capture the direct app launch console instead of starting raw simctl streams:
--launch-console is only for direct iOS simulator app launches, not URL opens.
Crash symbolication
Pick the tool for what you need:
Use debug symbols when you already have an Apple crash artifact and local dSYMs and need the failing code path, not a full log dump:
The command supports Apple .ips, .crash, and log-style crash artifacts that contain Binary Images or IPS usedImages. It matches UUIDs from the crash artifact against dwarfdump --uuid output from .dSYM bundles, runs atos, writes a symbolicated artifact, and prints only the output path plus a compact crash report: app/thread, exception or termination, top symbolicated frames, and the first actionable frame finding. The full symbolicated artifact stays on disk, so agent context stays small.
debug covers symbolication only. Use logs for app logs, network for HTTP evidence, perf for performance samples, record/trace for media and traces, and react-devtools for React Native internals. debug symbols does not handle Android Java/R8 mapping.txt or native ndk-stack/addr2line symbolication; capture Android crash evidence with logs and symbolicate it with other tools.
Core commands
Logs
- Logging is off by default; turn it on only for focused debugging windows.
- Prefer
logs clear --restartfor clean repro loops.
Search app logs with grep
Run logs path to get the log file, then grep that path so only matching lines enter agent context:
- Replace the example path with the one
logs pathprints. - Prefer targeted patterns (such as
Error,Exception, or your own log tags) over reading the whole file. logs mark "before submit"writes a line prefixed with[agent-device][mark][...], so grep foragent-device.*markto find your timing markers.
Network inspection
network dumpparses recent HTTP(s) entries from the session app log for app/device sessions and from managedagent-browserrequest history for web sessions.- For app/device sessions, results depend on what the app writes to the platform log.
- For the alias and per-platform limits, see Media and logs.
Audio probes
audio probe start [durationSeconds] [bucketMs]samples live audio while the session keeps running and reports compactrmsDbfsandpeakDbfsbuckets. The first timing positional is seconds; the second is milliseconds.- On web, the probe samples HTML media elements through Web Audio. URL-backed media may be routed through the probe
AudioContextwhile observed. - On macOS hosts, the probe samples host system audio through ScreenCaptureKit for macOS sessions, iOS simulators, and Android emulators. It requires Screen Recording permission and is system-audio evidence, not app-instrumented audio. Physical iOS and Android devices are not supported.
- Use
statusto poll partial buckets during a 10-20 second observation window, andstopto end the probe early.
Performance snapshots
- Name a
frames,memory,cpu, ortracearea. Bareperf,perf sample,perf metrics, andmetricsfail with an error that names the replacement. perf framesreturns a focused frame/jank-health payload.perf memory samplereturns a compact memory-only payload. Prefer it over rawdumpsys/leaksoutput for a first pass: arrays stay bounded and the top consumers are listed compactly.- Example sample shape:
{"metrics":{"memory":{"available":true,"totalPssKb":562958,"totalRssKb":570304,"topConsumers":[{"name":"Dalvik Heap","pssKb":213456}]}}}. perf memory snapshotescalates to file artifacts. Android supports Java HPROF capture for active app processes when the build/device allows heap dumping. iOS simulator and macOS app sessions support memgraph capture. On physical iOS devices, memgraph capture reports unavailable with a hint.- Heap and memgraph artifacts are returned as paths plus compact metadata. Example default output:
Memory artifact (android-hprof): /tmp/app.hprof (42MB). They are not printed or embedded in JSON by default. Native allocation tracing (heapprofd) is not supported. perf cpu profile ... --kind xctracecollects an Apple native.trace;reportaggregates every run, returns at most ten weighted top functions in JSON, and prints five.perf trace ... --kind xctracekeeps trace data as an artifact.- On iOS simulators and macOS, process sampling and captures target the resolved app executable. Other running copies with the same executable name are excluded, including copies installed on another simulator.
- Android native profiling uses
perf cpu profile ... --kind simpleperf; its report likewise returns at most ten top functions and prints five. Android native trace capture usesperf trace ... --kind perfetto. These commands require an active Android app session and return artifact paths/summaries instead of dumping profile or trace contents. - Use the compact result as evidence. For example, a successful Perfetto stop may return
state: "stopped",outPath: "/tmp/app.perfetto-trace",sizeBytes: 5392410, andmethod: "adb-shell-perfetto"while the 5.3 MB raw trace remains on disk as the artifact. - Memory and Android frame-health availability depend on platform and whether the active session is bound to an app/package. HarmonyOS reports process RSS through HDC; CPU profiling, frame sampling, and memory-snapshot artifacts remain unavailable on the public HDC surface.
openreturns app startup duration asstartup.- On Android and supported Apple targets, use
metrics.fps.droppedFramePercentfor the health check andmetrics.fps.worstWindowsto line up jank clusters with logs, network activity, or recent actions.
Where to go deeper
- Full command reference: Commands
- Node.js observability APIs: Node.js API
- Session behavior and lifecycle: Sessions
