# Nyxian: An On-Device iOS IDE and Userspace Microkernel for Stock iPhones

> Nyxian is an AGPL-3.0 iOS app that provides a full native IDE and a userspace microkernel for building and running iOS apps directly on an unjailbroken iPhone, offline, across iOS 18.4 through iOS 27 Beta 4.

**emexlab/Nyxian** — IDE to develop native code iOS apps and utilities on stock iOS it self just via a certificate and a custom micro kernel for those apps.

- Repository: https://github.com/emexlab/Nyxian
- Website: https://emexlabs.org/Nyxian/
- Stars: 1,218 · Forks: 114
- Language: C
- License: AGPL-3.0
- Published: 2026-08-26 · Updated: 2026-08-26 · Language: en
- Canonical page: https://hysenlabs.com/projects/emexlab-nyxian

## The Problem: iOS Development Without a Mac or a Cloud

iOS development normally requires a Mac with Xcode, or a cloud service that compiles remotely. Nyxian attacks that constraint directly. It is an iOS app that bundles an IDE and a runtime environment, letting you compile and run native iOS apps entirely on the iPhone itself. The README claims it works offline, even in airplane mode, after the SDK and resources are downloaded once. This targets developers who travel, work in isolated networks, or simply want to iterate on code without carrying a laptop. The project's scope is ambitious: it supports Swift, C, Objective-C, C++ and Objective-C++, and it ships with the entire iOS 26.5 SDK. That is a significant claim, and if it holds, it removes the hardware dependency that has been central to iOS development since the platform began.

## How Nyxian Works: A Userspace Microkernel Named ksurface

The core of Nyxian is not the editor but the runtime. The README describes a userspace microkernel called ksurface that runs inside the iOS process. It provides radix trees, an object API, process objects, and a privilege model. The key trick is that Nyxian signs executables with a custom entitlement blob, and it patches several system calls to make guest processes behave as if they were running on a real kernel. For example, it fixes posix_spawn, vfork, sysctl, and even task_for_pid. The microkernel intercepts Mach IPC and handles task port handoff by using a clever sequence: it moves a receive right after setting a send right as an exception port, then executes __builtin_trap, which causes the host to deliver a control task port. This is a low-level hack that bypasses the usual port guards. The documentation is candid about the one major gap: it cannot intercept an arm64 supervisor call. The project argues that on iOS this is not a security issue because processes have almost no privileges anyway, but it does affect initialization speed. The team proposes a separate extension process pool to mitigate that latency, where extensions wait on mach msg traps until they receive a request.

## Getting Started: Installation and Signing

The README points to an Installation Guide at emexlabs.org/Nyxian/docs/installation/ for the actual steps. The key requirement is a certificate. Nyxian does not require a jailbreak, but it does need a valid signing identity, presumably from an Apple developer account or a free provisioning profile. The project also provides a tool called nxtool that can sign apps like CocoaTop on your desktop, which suggests a workflow where you prepare executables on a Mac and then transfer them to the iPhone. The README mentions that signing executables is a completed feature, and that the guest file system uses sandbox file extensions for permissions. For a typical user, the first step is to download Nyxian from the project's homepage, install it on a compatible device, and follow the guide to obtain a certificate. The release notes show a version 0.11.3.1 called 'Scriptura' Beta, so expect beta-level stability.

## What Works Now: Compilation and Typechecking Status

The Todo list in the README gives a clear picture of what is implemented. Compilation is complete for C, Objective-C, C++, Objective-C++, and Swift. Linking objects to MachO is also done. Typechecking is complete for C and Objective-C, and partially done for C++ and Objective-C++ (limited without indexing). Swift typechecking is not yet implemented. Indexing is not done at all. This means you can compile and run Swift code, but you will not get the same inline error checking that you would in Xcode. For C-like languages, the experience is closer to a traditional editor with compiler feedback. The README also notes that NSBundle can be made to think it is loaded as a binary, and that apps and binaries can use the DYLD version they were built for. These are low-level integration details that matter for running real iOS apps, not just command-line tools.

## A Genuine Limitation: The arm64 Supervisor Call Gap

The most honest limitation is stated plainly: Nyxian cannot intercept an arm64 supervisor call. This means that if a guest process executes a supervisor call directly, it bypasses the microkernel's shims and goes to the iOS kernel. The project argues that this is not a security problem because the iOS kernel grants nothing useful to an unprivileged process. That is a reasonable argument, but it has a practical consequence: any code that relies on a syscall that is not patched will behave differently or fail. The README also lists incomplete features, such as tty support that only works when NXWindowSessionTerminal creates it, and an unresolved question about the NSExtension spawn limit. These are not theoretical concerns; they are explicit gaps in the current beta. If your app uses exotic syscalls or depends on full tty behavior, Nyxian may not support it yet.

## Alternatives: Xcode and On-Device Interpreters

The obvious alternative is Xcode, which runs on a Mac and provides a full IDE with indexing, debugging, and a simulator. Xcode is the standard tool, but it requires a Mac and cannot run on the iPhone itself. Another alternative is to use on-device interpreters like Pythonista or Swift Playgrounds, which allow scripting and simple app development but do not compile native iOS binaries with a full SDK. Nyxian's approach is different: it is not an interpreter, it is a compiler plus a microkernel that emulates enough of the kernel to run native Mach-O binaries. That is a fundamental architectural difference. Xcode gives you a mature toolchain with a heavy hardware dependency; interpreters give you portability but limited native capability. Nyxian tries to combine native compilation with on-device execution, trading maturity for mobility.

## Maintenance and License Implications

The project is actively maintained, with the latest release dated 2026-08-26, just a day before the repository snapshot. The version numbering (0.11.3.1) indicates a fast iteration pace. The license is AGPL-3.0, which is a strong copyleft license. If you use Nyxian as a tool to develop your own apps, the AGPL applies to the Nyxian software itself, not necessarily to the apps you write with it, but you should verify that interpretation with a legal professional. The README does not mention any upgrade path or migration cost, but the beta status suggests that updates may change APIs and behavior. The project's homepage and Discord server are the primary support channels. Given the low-level nature of the microkernel, expect that upgrading Nyxian could break existing projects if the internal APIs change.

## Who Should Adopt Nyxian and What to Verify First

Nyxian is for developers who need to write and test iOS code entirely on an iPhone, perhaps for field work, security research, or just convenience. It is not for teams that require a stable, feature-complete IDE or that must ship proprietary code without copyleft obligations. Before adopting it, verify that your device runs iOS 18.4 through iOS 27 Beta 4, as stated in the README. Test your specific code against the microkernel's limitations, especially any use of supervisor calls or tty. Check the installation guide for the certificate requirements, and if you plan to distribute apps, look into nxtool for signing. The project is still in beta, so expect bugs and incomplete features, but the roadmap is clear and the core compilation path is complete. If you accept those trade-offs, Nyxian offers a unique way to develop native iOS apps without a Mac.

## Conclusion

Nyxian suits developers who need to write and test iOS code entirely on an iPhone, especially in offline or constrained environments, and who accept the AGPL-3.0 license and the project's experimental status. It is not for teams that require a stable, fully indexed IDE or that must ship proprietary code without copyleft obligations. Before adopting it, verify that your target iOS version (18.4 through 27 Beta 4) is supported, review the installation guide for signing requirements, and test the microkernel's limitations with your specific syscall usage, as the project notes it cannot intercept arm64 supervisor calls and some fixes are incomplete.

## FAQ

### What is Nyxian?

An iOS application that provides a full native development toolchain on the device, plus a userspace microkernel, so you can compile and run your own iOS apps on stock hardware without jailbreaking. It supports Swift, C, Objective-C, C++ and Objective-C++, and the project is licensed AGPL-3.0 and written mostly in C.

### Does Nyxian really work offline?

After one download. The page says it needs no cloud and can be used with airplane mode enabled, and qualifies that as after it has downloaded the SDK and resources from the project's own server. It also states it compiles using one SDK version while claiming support for a later host version.

### Which languages does Nyxian typecheck fully?

C, Objective-C and Swift. The C++ and Objective-C++ rows of the type-checking table are ticked but annotated as limited without indexing, and indexing is the one unchecked box in the editor section. All five languages do compile, and linking objects into the Mach-O format is ticked.

### Which system calls does the Nyxian microkernel patch?

For the guest processes it spawns: the process spawning and fork calls, the system-information call, terminal support, the process-library call, the two task-inspection calls, and the credential calls that set user and group id. It also patches memory copy between the host and guest processes, and hosts a Mach inter-process communication syscall server.

### What is the main limitation of Nyxian?

The project states that it cannot intercept one supervisor call on the target architecture. Its argument is that processes on the operating system hold very few privileges, so a process bypassing the project's shims and asking the platform kernel directly would gain nothing useful, and it substitutes an extension poll on message traps that shrinks guest initialization time to effectively nothing.

### Are the Nyxian releases stable?

All three recent releases are zero-eleven betas carrying the same release codename, and two of them were published six hours apart on the same day. There is no stable tag to pin and no release policy section on the page; the project publishes a per-item progress checklist instead, with unchecked items for indexing, thread-local storage in the extension loader and the extension host's spawn limit.

## Sources

- [Official documentation](https://emexlabs.org/Nyxian/)
- [Official README](https://github.com/emexlab/Nyxian#readme)
- [Project repository](https://github.com/emexlab/Nyxian)
- [Release notes](https://github.com/emexlab/Nyxian/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/emexlab-nyxian
