How to Query MongoDB From an iPhone Without a Backend
You get a message on a Saturday: an order is stuck, a user can’t log in, a counter looks wrong. The answer is one query away, and the only computer you have is your phone. If you have ever tried to query MongoDB from an iPhone in that moment, you know it is surprisingly awkward. This article explains why, what changed in 2025, and which options actually work today.
Why a phone can’t just “use the driver”
On a server, talking to MongoDB is trivial: install the driver, pass a connection string, call
find(). That simplicity hides three things the driver needs from its environment:
- Raw TCP sockets. MongoDB doesn’t speak HTTP. Clients use the MongoDB wire protocol over a plain TCP connection, usually on port 27017 and wrapped in TLS.
- A TLS implementation the driver can drive directly, including certificate validation and SNI for Atlas hosts.
- DNS beyond simple lookups. A
mongodb+srv://connection string is not a host name: the driver resolves an SRV record to find the actual servers of the replica set and a TXT record for options such asreplicaSetandauthSource.
The Node.js driver gets all of this from Node’s net, tls and dns modules. Those modules don’t
exist in a browser, and they don’t exist in the JavaScript engines used by mobile frameworks: React
Native’s Hermes, for instance, has fetch and WebSockets but no raw sockets and no SRV lookups.
That is why “just npm install mongodb” fails in a mobile app, and why there has never been a
first-party MongoDB driver for React Native.
Native iOS code can open sockets, but the official options there have dried up too. MongoDB stopped development of its Swift driver in 2023, and the Realm-based Atlas Device SDKs were aimed at syncing an on-device database rather than querying an arbitrary cluster.
What changed in 2025
For years the escape hatch was HTTP. The Atlas Data API exposed CRUD and aggregation over
HTTPS with an API key, so anything that could call fetch could read and write documents: mobile
apps, edge functions, IoT devices, spreadsheets, shell scripts.
MongoDB deprecated the Data API and Custom HTTPS Endpoints in September 2024 and removed them on September 30, 2025. Atlas Device Sync and the Atlas Device SDKs reached end of life on the same date (the on-device database lives on as an open-source project, without sync). If an app or a workflow relied on any of these to reach Atlas from a phone, it stopped working.
We cover replacements for application traffic in The MongoDB Atlas Data API Is Gone: What to Use Instead. The rest of this article is about the other use case: you, a developer or operator, needing to look at your own data from your phone.
First, a security distinction that matters
There are two very different questions hiding behind “MongoDB from a mobile app”:
- Should a consumer app I ship connect straight to my database? No. Anything inside an app bundle can be extracted, including connection strings. Apps used by customers should talk to an API you control, which holds the credentials and enforces what each user may do.
- Can I, the owner of the database, use a client app on my phone the way I use Compass or mongosh on my laptop? Yes. Here the credentials are yours, typed into your device, and the client is a tool, not a product shipping your secrets.
Everything below is about the second case.
Your options today
1. The Atlas web UI in mobile Safari
If your cluster is on Atlas, the Data Explorer in the Atlas web interface works from a phone’s browser in a pinch. It needs your Atlas login (and usually 2FA), it is designed for a desktop screen, and it only covers Atlas, not self-hosted deployments. Fine for a quick look, tiring for anything more.
2. SSH plus mongosh
If you have a server that can reach the database, an SSH client on the phone plus mongosh gives
you the full shell. It is powerful and works with any deployment, but typing JSON filters with
nested braces and dollar signs on a phone keyboard, then reading wide documents in an 80-column
terminal, is nobody’s idea of fun. It also requires a jump host with access to the database.
3. A small personal API
Some teams keep a tiny internal service around: a few authenticated endpoints that run predefined queries. It is the safest option for very sensitive data, because the phone never holds database credentials. The cost is maintenance, and the queries you didn’t anticipate are exactly the ones you’ll need at 11 p.m.
4. A native client that embeds a real driver
The last option is a native app that solves the three problems above on the device itself: opens TCP connections, runs TLS, resolves SRV records, and speaks the wire protocol. That is what Bussola does. It embeds the official MongoDB Rust driver, compiled for iOS, so you get the same connection handling, server selection and authentication as a server-side application, without anything in between.
How a direct connection works on iOS
When you paste a mongodb+srv:// string, a few things happen before the first document appears:
- SRV and TXT resolution. The host is resolved through the iOS system resolver, the same one every app uses, so it respects your network’s DNS (including VPN configurations). If the system resolver can’t answer, public DNS is used as a fallback.
- TLS and authentication. The driver opens TLS connections to the replica set members and authenticates with SCRAM using the username and password in the string.
- Typed results. Documents come back as BSON and are shown with their exact types. This
matters more than it sounds: a JavaScript number can’t represent every 64-bit integer, so tools
that go through plain JSON can silently round large
Int64values or flattenDecimal128into floating point.
Mobile networks add their own problems: switching from Wi-Fi to cellular kills existing sockets, and a weak signal can leave a request hanging forever. A mobile client needs to notice network changes, reconnect, and put a timeout on every operation. Bussola does all three.
The one thing you must configure: network access
Even with the right app, your database has to accept connections from your phone. On Atlas that means the IP Access List of the project. Mobile IP addresses change constantly, so you have three reasonable choices:
- Add your current IP as a temporary entry that expires on its own, when you need it.
- Route your phone through a VPN with a fixed exit IP and allow only that address.
- For non-production clusters only, accept wider ranges.
Opening a production cluster to 0.0.0.0/0 because “the password is strong” is the mistake to
avoid. We go deeper on this, plus read-only users and query limits, in
How to Safely Query a Production MongoDB From Your Phone.
Quick checklist
- Use a dedicated database user for your phone, ideally with the
readrole on the databases you need. - Allow your phone’s network in the IP Access List, temporarily or through a fixed-IP VPN.
- Pick a client that connects directly and stores the connection string in the Keychain.
- Keep production connections read-only unless you are deliberately fixing something.
- Prefer indexed filters and limits; a phone is the worst place to discover a collection scan.
Wrapping up
Querying MongoDB from an iPhone without a backend is harder than it should be: the protocol needs sockets that mobile JavaScript doesn’t have, and the HTTP shortcut is gone. For apps you ship to customers, put an API in front of the database. For you, the owner, a native client that embeds the real driver is now the most direct way to answer that Saturday question without opening a laptop.
Bussola is a free MongoDB client for iPhone: query, edit and aggregate over a direct connection, with no backend.
Coming soon to the App Store