# How to Query MongoDB From an iPhone Without a Backend

> Why you can't just run the MongoDB driver in a mobile app, what changed when the Atlas Data API was retired, and the options that still work.

Source: https://bussolaformongo.app/blog/query-mongodb-from-iphone-without-backend/ · 2026-10-06

You get a message on a Saturday: an order is stuck, a user can't log in, a counter looks wrong. The
answer is one query away, and the only computer you have is your phone. If you have ever tried to
**query MongoDB from an iPhone** in that moment, you know it is surprisingly awkward. This article
explains why, what changed in 2025, and which options actually work today.

## Why a phone can't just "use the driver"

On a server, talking to MongoDB is trivial: install the driver, pass a connection string, call
`find()`. That simplicity hides three things the driver needs from its environment:

1. **Raw TCP sockets.** MongoDB doesn't speak HTTP. Clients use the MongoDB wire protocol over a
   plain TCP connection, usually on port 27017 and wrapped in TLS.
2. **A TLS implementation** the driver can drive directly, including certificate validation and
   SNI for Atlas hosts.
3. **DNS beyond simple lookups.** A `mongodb+srv://` connection string is not a host name: the
   driver resolves an SRV record to find the actual servers of the replica set and a TXT record for
   options such as `replicaSet` and `authSource`.

The Node.js driver gets all of this from Node's `net`, `tls` and `dns` modules. Those modules don't
exist in a browser, and they don't exist in the JavaScript engines used by mobile frameworks: React
Native's Hermes, for instance, has `fetch` and WebSockets but no raw sockets and no SRV lookups.
That is why "just npm install mongodb" fails in a mobile app, and why there has never been a
first-party MongoDB driver for React Native.

Native iOS code can open sockets, but the official options there have dried up too. MongoDB
stopped development of its Swift driver in 2023, and the Realm-based Atlas Device SDKs were aimed at
syncing an on-device database rather than querying an arbitrary cluster.

## What changed in 2025

For years the escape hatch was HTTP. The **Atlas Data API** exposed CRUD and aggregation over
HTTPS with an API key, so anything that could call `fetch` could read and write documents: mobile
apps, edge functions, IoT devices, spreadsheets, shell scripts.

MongoDB deprecated the Data API and Custom HTTPS Endpoints in September 2024 and removed them on
**September 30, 2025**. Atlas Device Sync and the Atlas Device SDKs reached end of life on the same
date (the on-device database lives on as an open-source project, without sync). If an app or a
workflow relied on any of these to reach Atlas from a phone, it stopped working.

We cover replacements for application traffic in
[The MongoDB Atlas Data API Is Gone: What to Use Instead](/blog/mongodb-data-api-alternatives/).
The rest of this article is about the other use case: **you, a developer or operator, needing to
look at your own data from your phone.**

## First, a security distinction that matters

There are two very different questions hiding behind "MongoDB from a mobile app":

- **Should a consumer app I ship connect straight to my database?** No. Anything inside an app
  bundle can be extracted, including connection strings. Apps used by customers should talk to an
  API you control, which holds the credentials and enforces what each user may do.
- **Can I, the owner of the database, use a client app on my phone the way I use Compass or
  mongosh on my laptop?** Yes. Here the credentials are yours, typed into your device, and the
  client is a tool, not a product shipping your secrets.

Everything below is about the second case.

## Your options today

### 1. The Atlas web UI in mobile Safari

If your cluster is on Atlas, the Data Explorer in the Atlas web interface works from a phone's
browser in a pinch. It needs your Atlas login (and usually 2FA), it is designed for a desktop
screen, and it only covers Atlas, not self-hosted deployments. Fine for a quick look, tiring for
anything more.

### 2. SSH plus mongosh

If you have a server that can reach the database, an SSH client on the phone plus `mongosh` gives
you the full shell. It is powerful and works with any deployment, but typing JSON filters with
nested braces and dollar signs on a phone keyboard, then reading wide documents in an 80-column
terminal, is nobody's idea of fun. It also requires a jump host with access to the database.

### 3. A small personal API

Some teams keep a tiny internal service around: a few authenticated endpoints that run predefined
queries. It is the safest option for very sensitive data, because the phone never holds database
credentials. The cost is maintenance, and the queries you didn't anticipate are exactly the ones
you'll need at 11 p.m.

### 4. A native client that embeds a real driver

The last option is a native app that solves the three problems above on the device itself: opens
TCP connections, runs TLS, resolves SRV records, and speaks the wire protocol. That is what
[Bussola](/) does. It embeds the official MongoDB **Rust** driver, compiled for iOS, so you get the
same connection handling, server selection and authentication as a server-side application, without
anything in between.

## How a direct connection works on iOS

When you paste a `mongodb+srv://` string, a few things happen before the first document appears:

- **SRV and TXT resolution.** The host is resolved through the iOS system resolver, the same one
  every app uses, so it respects your network's DNS (including VPN configurations). If the system
  resolver can't answer, public DNS is used as a fallback.
- **TLS and authentication.** The driver opens TLS connections to the replica set members and
  authenticates with SCRAM using the username and password in the string.
- **Typed results.** Documents come back as BSON and are shown with their exact types. This
  matters more than it sounds: a JavaScript number can't represent every 64-bit integer, so tools
  that go through plain JSON can silently round large `Int64` values or flatten `Decimal128` into
  floating point.

Mobile networks add their own problems: switching from Wi-Fi to cellular kills existing sockets, and
a weak signal can leave a request hanging forever. A mobile client needs to notice network changes,
reconnect, and put a timeout on every operation. Bussola does all three.

## The one thing you must configure: network access

Even with the right app, your database has to accept connections from your phone. On Atlas that
means the **IP Access List** of the project. Mobile IP addresses change constantly, so you have
three reasonable choices:

1. Add your current IP as a **temporary entry** that expires on its own, when you need it.
2. Route your phone through a **VPN with a fixed exit IP** and allow only that address.
3. For non-production clusters only, accept wider ranges.

Opening a production cluster to `0.0.0.0/0` because "the password is strong" is the mistake to
avoid. We go deeper on this, plus read-only users and query limits, in
[How to Safely Query a Production MongoDB From Your Phone](/blog/query-production-mongodb-from-phone-safely/).

## Quick checklist

- Use a **dedicated database user** for your phone, ideally with the `read` role on the databases
  you need.
- Allow your phone's network in the **IP Access List**, temporarily or through a fixed-IP VPN.
- Pick a client that **connects directly** and stores the connection string in the **Keychain**.
- Keep **production connections read-only** unless you are deliberately fixing something.
- Prefer **indexed filters and limits**; a phone is the worst place to discover a collection scan.

## Wrapping up

Querying MongoDB from an iPhone without a backend is harder than it should be: the protocol needs
sockets that mobile JavaScript doesn't have, and the HTTP shortcut is gone. For apps you ship to
customers, put an API in front of the database. For you, the owner, a native client that embeds the
real driver is now the most direct way to answer that Saturday question without opening a laptop.
