Magisk
by topjohnwu · GPL-3.0 · open source
The best-known way to root Android: patch your phone’s boot image with the Magisk app, flash it, and get root access, modules and Zygisk without touching the system partition.
Needs:Unlocked bootloader · fastboot · Android 6.0+
2113 Apps is independent, not affiliated with or endorsed by topjohnwu. Official sources: source code on GitHub.
- Version
- 30.7
- Size
- 11.6 MB
- Requires
- Android 6.0+
- Updated
- 2026-02-23
Introduction
Magisk is a suite of open-source tools for customising Android, and the best-known way to root a phone. It works by patching the boot image rather than modifying the system partition, which is why it’s often called “systemless” root. The APK here is the Magisk app: you use it to install Magisk, then to manage root access and modules afterwards.
What it includes
From the project’s README:
- MagiskSU, which grants root access to the apps you allow.
- Magisk modules, which modify read-only partitions without actually changing them.
- MagiskBoot, a tool for unpacking and repacking boot images.
- Zygisk, which runs code inside every app’s process. Frameworks such as LSPosed use it; see how to install LSPosed.
Installing it for the first time
Rooting always starts with an unlocked bootloader, which usually wipes the phone. The official installation guide then goes like this:
- Install the Magisk app and open it. The home screen shows whether your device has a ramdisk in its boot partition; that decides which image you patch.
- Get the boot.img (or init_boot.img if your device has one) from your phone’s exact firmware. Devices without a boot ramdisk use the recovery image instead.
- In the app, tap Install → Select and Patch a File and choose the image.
- Copy the patched image to your computer and flash it in fastboot mode, for example
fastboot flash boot magisk_patched_….img. - Reboot, open Magisk, and let it finish setting up its environment.
Samsung devices have their own procedure, described in the guide. The guide is also firm about one rule: never flash a patched image made by someone else or on another device, even the same model. Always patch the image on the phone you are rooting.
Already rooted with Magisk? The developer recommends updating from inside the app with Direct Install, not by repeating these steps.
About this file
The developer states that GitHub is the only official source of Magisk downloads and information. The file here is that GitHub release, unmodified: its hash matches the one GitHub publishes for the release, and it is signed with the developer John Wu’s own certificate (the fingerprint is under More Information). Treat any “Magisk” that doesn’t match this signer, or that comes as a pre-patched image, as suspect.
Not sure Magisk is the right choice? Our comparison of KernelSU, APatch and Magisk explains how they differ.
What’s inside the APK
Trackers
No code matching the Exodus Privacy tracker signatures.
Native code
Runs on 64-bit and older 32-bit ARM phones.
Android versions
Built for Android 16 (target API 36).
Permissions
3 of them need your approval first.
CPU types in this build: arm64-v8a (64-bit ARM, almost every phone since 2017); armeabi-v7a (32-bit ARM, older and budget phones); x86 (32-bit Intel, emulators); x86_64 (64-bit Intel, emulators and Chromebooks).
Asks you first (3)
Android shows a prompt before the app can use these.
- Show notifications (Android 13+) · POST_NOTIFICATIONS
- Read shared storage (Android 12 and older) · READ_EXTERNAL_STORAGE
- Write shared storage (Android 10 and older) · WRITE_EXTERNAL_STORAGE
You switch these on in Settings (1)
Special app access. Nothing is granted until you turn it on yourself.
- Install unknown apps · REQUEST_INSTALL_PACKAGES
Granted at install (7)
Low-risk permissions Android grants automatically, plus any we have not classified.
- ACCESS_NETWORK_STATE
- FOREGROUND_SERVICE
- HIDE_OVERLAY_WINDOWS
- INTERNET
- QUERY_ALL_PACKAGES
- RUN_USER_INITIATED_JOBS
- UPDATE_PACKAGES_WITHOUT_USER_ACTION
More Information
- Package name
- com.topjohnwu.magisk
- Version
- 30.7 (build 30700)
- File size
- 11.6 MB (11,613,864 bytes)
- Requires
- Android 6.0 or later
- Category
- Root & Mods
- License
- GPL-3.0
- Developer
- topjohnwu
- Source code
- github.com/topjohnwu/Magisk
- Released
- Feb 23, 2026
- Signer SHA-256
- b4cb83b4dad99f997dbe872f013aa16c14eec41d167021f371f7e1330f273ee6
- File SHA-256
- e0d32d2123532860f97123d927b1bb86c4e08e6fd8a48bfc6b5bee0afae9ebd5
- Checked
- , against the v30.7 release on GitHub · how we check · verify it yourself
Common questions
Is this APK the official Magisk release?
Yes. It is the file from the project’s v30.7 release on GitHub, byte for byte, and it matches the SHA-256 checksum GitHub publishes for it. It is signed with the certificate we recorded when we first checked Magisk (SHA-256 b4cb83b4dad99f997dbe872f013aa16c14eec41d167021f371f7e1330f273ee6); a release signed with a different key would not be published here.
What Android version does Magisk need?
Android 6.0 or later (API level 23). Version 30.7 is built for Android 16 (target API 36). Runs on 64-bit and older 32-bit ARM phones.
Can Magisk access the internet?
Yes. The APK requests Android’s internet permission. In total it declares 11 permissions, and 3 of them need your approval first.
Does Magisk contain trackers?
No known trackers: our scan of version 30.7 found no code matching the Exodus Privacy tracker signatures. The scan covers known tracker libraries; it doesn’t show what data the app itself sends.
Is Magisk open source?
Yes. Magisk is released under the GPL-3.0 licence, and its source code is published at https://github.com/topjohnwu/Magisk.
Older versions of Magisk
| Version | Released | Requires | Download |
|---|---|---|---|
| v30.7 · current | Feb 23, 2026 | Android 6.0+ | Magisk 30.7 APK · 11.6 MB |
| v30.6 | Dec 1, 2025 | Android 6.0+ | Magisk 30.6 APK · 12.9 MB |
| v29.0 | May 14, 2025 | Android 6.0+ | Magisk 29.0 APK · 11.8 MB |
| v28.1 | Dec 7, 2024 | Android 6.0+ | Magisk 28.1 APK · 11.7 MB |
| v28.0 | Oct 10, 2024 | Android 6.0+ | Magisk 28.0 APK · 11.2 MB |
We host the current version and the 4 before it. Each older file is signed with the same key as the current one, so newer versions install over it as normal updates. 30.6 also matches the checksum GitHub publishes. GitHub has no published checksum for 29.0, 28.1, 28.0, so those were checked by signature and file size. The permissions and trackers listed above describe the current version. Full changelog.