Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in
How you update depends on how you installed. locally update knows which it was and, for a package-manager install, points you at the package manager's own upgrade command instead of replacing the binary underneath it.
| Installed with | Update with |
|---|---|
| Homebrew (macOS, Linux) | brew upgrade locally |
| Scoop (Windows) | scoop update locally |
| Direct download | locally update |
locally update --check reports whether a newer version exists without installing it, and -y skips the confirmation. The updater downloads the release for your platform from get.locally.build, verifies its checksum, and replaces the binary in place. Stop a running locally build first: the new version takes effect on the next launch.
$
locally update --check
locally validate. A new version can require extra *.locally domains on the TLS certificate; validate says so and locally setup regenerates it.locally build tells you when an installed plugin is behind:
$
locally plugin update
Plugins are downloaded into the config directory (plugins/), so updating them needs no elevated rights. locally plugin list-installed shows what you have and at which version.
Releases are versioned vYYYY.MM, with a bug-fix number added when one is needed - for example v2026.09, then v2026.09.01. locally version prints the version and platform of the binary you have, and the Dashboard's Settings → Changelog page lists what changed in each release.
Locally touches four things on a machine: the binary, a config directory, an entry in your DNS resolver configuration, and (if you chose to trust it) a root certificate in your trust stores. Remove them in this order so each step can still use the CLI.
This tells your Locally Account the installation is gone (freeing the seat on a Team plan) and removes the installation certificate. Locally will not run again on this machine until locally setup is re-run.
$
locally logout
Each locally configure subcommand can remove exactly what it added and nothing else - the .locally resolver rule, and the registry configuration inside a Podman machine. --status first shows what is there; --dry-run prints what would change.
$
locally configure dns --remove
$
locally configure podman --remove
Trusting the CA was a step you ran yourself, and so is removing it. The root's subject is Locally CLI - Local Certificate Authority (or mkcert's root, if you chose to reuse one); remove it from every store you added it to:
| Store | Command |
|---|---|
| macOS system keychain | sudo security delete-certificate -Z "$(openssl x509 -in ~/.config/locally/local-ca.pem -noout -fingerprint -sha1 | cut -d= -f2 | tr -d :)" /Library/Keychains/System.keychain |
| Windows (Administrator) | certutil -delstore "ROOT" "Locally CLI - Local Certificate Authority" |
| Debian / Ubuntu | sudo rm /usr/local/share/ca-certificates/locally-ca.crt && sudo update-ca-certificates --fresh |
| Fedora / RHEL | sudo rm /etc/pki/ca-trust/source/anchors/locally-ca.crt && sudo update-ca-trust |
| Linux browsers (NSS) | certutil -d sql:$HOME/.pki/nssdb -D -n "Locally Local CA" |
This removes the CA and its key, the installed plugins, synced team content, pending analytics and crash reports, and the Azure CLI working directory Locally used. Nothing you provisioned lives here - that was in memory and is already gone.
$
rm -rf ~/.config/locally
On Windows the directory is %LocalAppData%\locally (hidden by default in Explorer):
$
Remove-Item -Recurse -Force "$env:LocalAppData\locally"
| Installed with | Remove with |
|---|---|
| Homebrew | brew uninstall locally |
| Scoop | scoop uninstall locally |
| Direct download | Delete the locally binary from wherever you placed it on your PATH |
docker ps -a / podman ps -a for anything you didn't start yourself.locally mcp install point at the binary; locally mcp uninstall <client> removes them while the binary is still present..terraform.lock.hcl in your projects are yours and untouched.Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in
Your Azure infrastructure, running on your machine. Deploy in seconds, break things freely, and ship to Azure when you're ready.