# MeshBay — Android client A client, not a host: no node runs on a phone (`docs/MESHBAY_DESIGN.md` §11.3). The shell is a system WebView showing the interface **from the package** — `meshbay-hub/src/meshbay_hub/static/` copied at build time into `build/generated/`, never committed (§8.3) — with a bridge (`app/src/main/assets/bridge/meshbay-bridge.js`) that offers the page the same `window.meshbay` as the desktop preload, wherever it offers anything at all. Hub calls leave from native code, to the signed-in hub only. The device key, the bundle key and every node identity are held natively under an Android Keystore key; the page is told public keys and handed signatures, asked for by kind — never bytes. `meshbay-hub/tests/vectors/keyring.json` holds that keyring to the desktop's and to the specification. ```bash # needs JDK 17+ and an Android SDK (ANDROID_HOME, or sdk.dir in local.properties) ./gradlew assembleDebug # app/build/outputs/apk/debug/app-debug.apk ./gradlew testDebugUnitTest # JVM unit tests ``` The security contract is also pinned from the Python suite by reading this source: `packages/meshbay-hub/tests/test_android_shell.py`. Not built yet: downloads to disk, casting, phone-specific behaviour (back button, network handover), signed releases.