Rootless

Automate iOS, iPadOS, and macOS using plain JavaScript. Build custom widgets and interact directly with native APIs.

Download on the App Store
Rootless app interface

Plain JavaScript

Supports ES6. Scripts are stored as plain .js files on your disk.

Native APIs & Documentation

Integrate directly with iOS native APIs. Fully documented, available offline.

Siri Shortcuts

Trigger scripts via Siri. Present tables, websites, and custom HTML natively.

System Integration

Run from the Share Sheet, process inputs, and manage local files via Files.app.

x-callback-url

Communicate seamlessly and trigger workflows with other apps on your device.

Customizable & Ready

Tailor the code editor to your liking. Includes several example scripts to start immediately.

Documentation

Also inside the app, or as rootless.json.

Crypto

Digests and signing

Hashing, HMAC, base64 and random bytes. JavaScriptCore is an ECMAScript engine, not a browser, so it has no atob, btoa or crypto object. Needed for signed APIs (AWS, Cloudflare, anything HMAC) and for Basic auth.

Methods

Crypto.md5(text)String

MD5 digest, hex.

  • text String required
Crypto.sha1(text)String

SHA-1 digest, hex.

  • text String required
Crypto.sha256(text)String

SHA-256 digest, hex.

  • text String required
Crypto.sha384(text)String

SHA-384 digest, hex.

  • text String required
Crypto.sha512(text)String

SHA-512 digest, hex.

  • text String required
Crypto.hmacSHA256(message, key)String

HMAC-SHA256, hex.

  • message String required
  • key String required
Crypto.hmacSHA512(message, key)String

HMAC-SHA512, hex.

  • message String required
  • key String required
Crypto.hmacSHA256Base64(message, key)String

HMAC-SHA256, base64. What most signing schemes want.

  • message String required
  • key String required
Crypto.base64Encode(text)String

UTF-8 text to base64.

  • text String required
Crypto.base64Decode(encoded)String

Base64 back to text, or null if it isn't valid.

  • encoded String required
Crypto.randomUUID()String

A new UUID string.

Crypto.randomBytes(count)String

Cryptographically random bytes as hex, up to 1024.

  • count Number required

Examples

A signed request

var stamp = String(Math.floor(Date.now() / 1000));
var signature = Crypto.hmacSHA256(stamp + path, Keychain.get("apiSecret"));

Http.get(url, { headers: {
  "X-Timestamp": stamp,
  "X-Signature": signature,
}});