# iOS-Location-Spoofer-Web: a self-hosted map panel that drives iPhone GPS through Shadowrocket

> This project pairs a Cloudflare Pages control panel with a Shadowrocket module that intercepts and minimally rewrites Apple location service responses, letting a single user set the coordinates their own iPhone reports. It is CC BY-NC-SA licensed, so commercial use is excluded, and the README states that iOS 27 beta 6 and later block every MITM approach through TLS certificate pinning.

**akudamatata/iOS-Location-Spoofer-Web** — iOS GPS location spoofer web panel - map-based location picker powered by Shadowrocket MITM

- Repository: https://github.com/akudamatata/iOS-Location-Spoofer-Web
- Stars: 364 · Forks: 358
- Language: JavaScript
- License: NOASSERTION
- Published: 2026-09-18 · Updated: 2026-09-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/akudamatata-ios-location-spoofer-web

## What it is, and the app it depends on

iOS-Location-Spoofer-Web is two pieces. One is a web control panel, a full screen map where you pick a point and lock it. The other is a Shadowrocket module that the panel generates, which intercepts the phone's location service traffic and rewrites the response. The panel alone does nothing to your phone.

That dependency is the first thing to weigh. Shadowrocket is a commercial iOS proxy client, not part of this project, and the README requires version 2.2.x or newer with HTTPS decryption enabled and its CA certificate trusted on the device. You are trusting a locally generated certificate authority on your phone, which is the standard cost of any MITM tooling.

The architecture is explicitly personal: a minimal Serverless design for a single user, one instance per person, zero maintenance cost. There is no multi-tenant model and no account system beyond a token.

## How the rewrite works, in the terms the README uses

The interesting engineering is in the interception strategy, which the README calls WLOC minimal rewrite with a sliding window scan as a fallback. Rather than replacing whole responses, it changes as little as possible and scans for the payload when the minimal path does not find it. That approach is chosen for stability across iOS updates, where fixed offsets and full rewrites break.

The rewrite engine is location-spoofer.js, described as a pure JavaScript native implementation with zero BigInt, which is what lets it claim support back to iOS 12.0. The backend and the rule module are self-hosted rather than pulled from an external rule subscription, so nothing in the chain depends on a third party continuing to host rules for you.

The compatibility matrix is unusually candid. iOS and iPadOS from 12.0 through 26.x are listed as fully supported, as are iOS 27 beta 1 through beta 5, which the README says follow the minimal rewrite strategy and packaging scan fallback. From iOS 27 beta 6 onward the status changes to system-limited, because Apple enabled strong TLS certificate pinning in the system location component, and the README states that all MITM approaches are currently limited by it.

## Deploying the panel to Cloudflare Pages

Deployment is designed around Cloudflare Pages and happens in the dashboard rather than on a server. Create a KV namespace named SPOOFER_DATA first, fork the repository, then create a Pages application. The README stresses one trap: select the Pages tab rather than the default Workers tab before connecting to Git.

Build settings are trivial because there is nothing to compile. The framework preset is None, the build output directory is public, and the build command is:

```bash
exit 0
```

Two environment variables are documented. TOKEN is your private access password and is required, used both for panel login and API authentication. AMAP_KEY is an AMap web service key for higher quality place name search in China, optional but recommended.

After the first deploy, bind the KV namespace under Settings, Functions, KV namespace bindings, with the variable name set to SPOOFER_DATA exactly, then retry the deployment so the binding takes effect. The result is a dedicated address like https://your-project.pages.dev that you open on the phone.

## Connecting the phone and the daily routine

On the phone you open the panel, log in with your token, and copy the module link from settings. In Shadowrocket you add that link under Configuration, Modules, and make sure the resulting iOS Location Spoofer module is switched on.

Then HTTPS decryption has to be enabled on the configuration: turn on HTTPS Decryption, turn on MitM over HTTP/2, generate a new CA certificate and install it, and finally go to Settings, General, About, Certificate Trust Settings on the iPhone and fully trust the Shadowrocket certificate. With the VPN switched on in Config mode, the module is active.

Daily use is four steps: open the panel, drag the crosshair or paste coordinates such as 39.9087, 116.3975 into the search box, tap lock so the blue pin appears, then refresh location by turning Location Services off, waiting ten seconds and turning it back on. Changing location repeats the last steps without restarting Shadowrocket. Favorites are saved by tapping the star next to the crosshair, and the panel can be added to the home screen from Safari for a full screen PWA.

## What the panel sends outward, and what it keeps

The README lists the external services the browser front end contacts, which is more disclosure than most projects of this kind provide. Map tiles come from AMap and AMap satellite for China, and CartoDB and Esri World Imagery elsewhere. Place search uses the AMap web service API when AMAP_KEY is configured, falling back to OpenStreetMap Nominatim for international search. Elevation comes from the Open-Meteo Elevation API, which is how the panel can fill in realistic altitude for a picked point automatically. Static assets load Leaflet from unpkg.com and the Inter font from Google Fonts.

On storage, the project states that your self-hosted configuration, token authentication, current coordinates and favorites live only in the Cloudflare KV of your own deployment, and that private location records are not uploaded to any third party.

Two things follow from that which the README does not spell out. Tile and geocoding providers still see requests coming from your deployment, so a picked coordinate is visible to whichever tile service is active. And the token that guards the panel is the only thing standing between the internet and your saved locations, so it needs to be a real secret rather than a convenience string.

## Limits, licence and responsible use

Three limits are structural. The iOS 27 beta 6 certificate pinning change stops the mechanism at the system level, not just this project. The dependency on a closed source paid client means the project cannot fix problems inside Shadowrocket. And the personal single-instance design rules out shared or team deployments.

Licensing is the part most likely to surprise people. The repository is CC BY-NC-SA 4.0, which requires attribution, forbids commercial use, and requires derivative work to be shared under the same or a compatible licence. GitHub's licence field reports NOASSERTION, which usually means its detector did not recognise the Creative Commons text, so read the LICENSE file yourself. The README also carries an anti-scam notice: it is free, and anyone who sold it to you on a marketplace has defrauded you.

On use, the README states the project is for map development testing, geolocation API debugging and technical learning and research, and asks that it not be used for illegal purposes. That is the right frame for a tool that changes what your device reports about where it is. Testing your own app's geofences is legitimate. Presenting a false location to an employer, a dating or delivery service, or anyone relying on it is a different matter, and may breach terms of service or law.

## Xcode's simulated location is the sanctioned alternative

For developers with a Mac, the obvious comparison is Xcode, which can simulate a location on a connected device and in the iOS Simulator, including routes defined in GPX files. That path is supported by Apple, requires no proxy, no CA certificate and no interception of your traffic, and it is what most teams use for testing location features.

It also has real constraints that explain why projects like this one exist. It needs a Mac running Xcode, it is aimed at apps you are building and debugging, and it is less convenient for quickly checking how a third-party app behaves at a given coordinate on a physical phone you happen to be holding.

This project inverts those trade-offs: no Mac, works against any app on the device, driven from a phone browser, at the cost of installing a trusted CA, routing traffic through a proxy, and depending on a mechanism the README already says is being closed off by certificate pinning. If you have a Mac and the goal is testing your own app, use Xcode. If the goal is ad hoc checks on a physical device and you accept the trade, this is the more convenient route while it still works.

## Conclusion

Take this project if you develop location-aware apps, want to test geofences and map behaviour on a real iPhone without a Mac, and are willing to run a personal Cloudflare Pages deployment and trust a proxy CA on your own device. Do not take it if you need it on iOS 27 beta 6 or later, where the README says certificate pinning limits all MITM approaches, or if you want anything commercial, since the licence is non-commercial and share-alike. Understand what you are installing: HTTPS decryption on your own phone means the proxy can read traffic you route through it, so keep it to a device you own and a profile you can remove. The stated purpose is map development testing, geolocation API debugging and technical research, and using it to misrepresent your whereabouts to an employer, a service or another person can breach terms of service or law.

## FAQ

### How do you spoof iPhone location in iOS with this project?

You deploy the web panel to Cloudflare Pages, add the generated module link in Shadowrocket, enable HTTPS decryption and trust its CA certificate on the device, then pick a point in the panel and lock it. The README's compatibility matrix lists iOS 12.0 through 26.x and iOS 27 beta 1 to 5 as supported.

### Can someone spoof their location on an iPhone?

Yes. This project documents one approach, a Shadowrocket MITM module that applies a minimal rewrite to location service responses. The README notes that from iOS 27 beta 6 onward certificate pinning in the system location component limits all MITM approaches.

### How do you spoof location in a web browser?

This panel runs in a browser but does not change browser geolocation. It is a control surface you open in Safari, optionally added to the home screen as a PWA, and the location change is applied on the iPhone through the Shadowrocket module.

## Sources

- [akudamatata/iOS-Location-Spoofer-Web on GitHub](https://github.com/akudamatata/iOS-Location-Spoofer-Web)
- [Issues](https://github.com/akudamatata/iOS-Location-Spoofer-Web/issues)
- [README](https://github.com/akudamatata/iOS-Location-Spoofer-Web/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/akudamatata-ios-location-spoofer-web
