Updating & Uninstalling

Preview

Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in

Updating & Uninstalling

Updating the CLI

How you update depends on how you installed. locally update knows which it was and, for a package-manager install, points you at the package manager's own upgrade command instead of replacing the binary underneath it.

Installed with Update with
Homebrew (macOS, Linux)brew upgrade locally
Scoop (Windows)scoop update locally
Direct downloadlocally update

locally update --check reports whether a newer version exists without installing it, and -y skips the confirmation. The updater downloads the release for your platform from get.locally.build, verifies its checksum, and replaces the binary in place. Stop a running locally build first: the new version takes effect on the next launch.

$ locally update --check

After an update

  • Run locally validate. A new version can require extra *.locally domains on the TLS certificate; validate says so and locally setup regenerates it.
  • Update the plugins. Resource Provider plugins are versioned separately from the CLI, and locally build tells you when an installed plugin is behind:
$ locally plugin update

Plugins are downloaded into the config directory (plugins/), so updating them needs no elevated rights. locally plugin list-installed shows what you have and at which version.

Versions

Releases are versioned vYYYY.MM, with a bug-fix number added when one is needed - for example v2026.09, then v2026.09.01. locally version prints the version and platform of the binary you have, and the Dashboard's Settings → Changelog page lists what changed in each release.

Uninstalling

Locally touches four things on a machine: the binary, a config directory, an entry in your DNS resolver configuration, and (if you chose to trust it) a root certificate in your trust stores. Remove them in this order so each step can still use the CLI.

1. Sign out and deregister

This tells your Locally Account the installation is gone (freeing the seat on a Team plan) and removes the installation certificate. Locally will not run again on this machine until locally setup is re-run.

$ locally logout

2. Undo the machine configuration

Each locally configure subcommand can remove exactly what it added and nothing else - the .locally resolver rule, and the registry configuration inside a Podman machine. --status first shows what is there; --dry-run prints what would change.

$ locally configure dns --remove $ locally configure podman --remove

3. Remove the root certificate from your trust stores

Trusting the CA was a step you ran yourself, and so is removing it. The root's subject is Locally CLI - Local Certificate Authority (or mkcert's root, if you chose to reuse one); remove it from every store you added it to:

Store Command
macOS system keychainsudo security delete-certificate -Z "$(openssl x509 -in ~/.config/locally/local-ca.pem -noout -fingerprint -sha1 | cut -d= -f2 | tr -d :)" /Library/Keychains/System.keychain
Windows (Administrator)certutil -delstore "ROOT" "Locally CLI - Local Certificate Authority"
Debian / Ubuntusudo rm /usr/local/share/ca-certificates/locally-ca.crt && sudo update-ca-certificates --fresh
Fedora / RHELsudo rm /etc/pki/ca-trust/source/anchors/locally-ca.crt && sudo update-ca-trust
Linux browsers (NSS)certutil -d sql:$HOME/.pki/nssdb -D -n "Locally Local CA"

4. Delete the config directory

This removes the CA and its key, the installed plugins, synced team content, pending analytics and crash reports, and the Azure CLI working directory Locally used. Nothing you provisioned lives here - that was in memory and is already gone.

$ rm -rf ~/.config/locally

On Windows the directory is %LocalAppData%\locally (hidden by default in Explorer):

$ Remove-Item -Recurse -Force "$env:LocalAppData\locally"

5. Remove the binary

Installed with Remove with
Homebrewbrew uninstall locally
Scoopscoop uninstall locally
Direct downloadDelete the locally binary from wherever you placed it on your PATH

Leftovers to check

  • Containers Locally started are removed when it stops; a launch that crashed can leave one behind, along with the DNS forwarder container on Docker Desktop. Check docker ps -a / podman ps -a for anything you didn't start yourself.
  • MCP client registrations added with locally mcp install point at the binary; locally mcp uninstall <client> removes them while the binary is still present.
  • Terraform state files and .terraform.lock.hcl in your projects are yours and untouched.
Preview

Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in

A local cloud for you and your agents.

Your Azure infrastructure, running on your machine. Deploy in seconds, break things freely, and ship to Azure when you're ready.