← Blog Mac Productivity

Kill Port 3000 on Mac: Commands and Fixes

By FavTray ·

Written by the team behind FavTray, a Mac developer dashboard for the menu bar. We check every app we cover against its own site, docs or a hands-on test, and each post says which.

To kill port 3000 on a Mac, run lsof -ti tcp:3000 -sTCP:LISTEN | xargs kill in Terminal. It finds the process listening on port 3000 and stops it. If the port is still busy a few seconds later, repeat it with kill -9. If you get “operation not permitted”, put sudo in front of both commands.

TL;DR

  • See who owns the port: lsof -nP -iTCP:3000 -sTCP:LISTEN
  • Stop it: lsof -ti tcp:3000 -sTCP:LISTEN | xargs kill
  • Force it: lsof -ti tcp:3000 -sTCP:LISTEN | xargs kill -9
  • Root-owned server: same commands with sudo
  • Port 5000 or 7000: that’s AirPlay Receiver, switch it off instead of killing it
  • One click instead: FavTray Ports, free for 10 kills a day

This post is the short, port-3000 version. For every port, TIME_WAIT and the full background, see our complete guide to killing a port on Mac.

What is using port 3000 on my Mac?

Port 3000 is the default for Next.js, Create React App, Express examples, Rails (rails server), Remix and Grafana, so the usual owner is a dev server you forgot about in another terminal tab or editor. Ask macOS directly:

lsof -nP -iTCP:3000 -sTCP:LISTEN
COMMAND   PID  USER   FD   TYPE  DEVICE SIZE/OFF NODE NAME
node    48213 akash   23u  IPv6  0x9f3…      0t0  TCP *:3000 (LISTEN)
  • -i TCP:3000 picks the port, -sTCP:LISTEN shows only the process that owns it.
  • -n and -P skip DNS and port-name lookups, so it answers instantly.
  • The PID column is what you pass to kill.

COMMAND says node, ruby or python, not which project. To see the folder it was started from, run lsof -a -p 48213 -d cwd.

What are the exact commands to kill port 3000?

# 1. Ask it to stop (SIGTERM): the server can close connections cleanly
lsof -ti tcp:3000 -sTCP:LISTEN | xargs kill

# 2. Still there after a few seconds? Force it (SIGKILL)
lsof -ti tcp:3000 -sTCP:LISTEN | xargs kill -9

# 3. Or by PID, if you already have it
kill 48213
kill -9 48213

-t makes lsof print PIDs only, which is what xargs kill needs.

Why not the popular lsof -ti :3000 | xargs kill -9? It works, but :3000 matches every process with a connection on that port, including your browser if a tab has localhost:3000 open. Force-killing that can take a browser helper process down with the server. Keep -sTCP:LISTEN.

Prefer a package script? npx kill-port 3000 does the same job from npm.

Why do I get EADDRINUSE on port 3000?

EADDRINUSE means another process already holds the port. Each framework says it differently:

StackWhat you seeWhat it means
Node.js / ExpressError: listen EADDRINUSE: address already in use :::3000Another server still has 3000
Next.js (next dev)Port 3000 is in use, trying 3001 instead.Next.js moved on its own; your old server is still running on 3000
Create React AppSomething is already running on port 3000.It offers to use another port
RailsAddress already in use - bind(2) for "127.0.0.1" port 3000Another server has the port
RailsA server is already running. Check tmp/pids/server.pidA stale PID file from a crash; if nothing is on 3000, delete tmp/pids/server.pid

If a port clash is routine for one project, start it elsewhere instead: PORT=3001 npm run dev, next dev -p 3001, or rails server -p 3001.

Why does kill say “operation not permitted”?

The process isn’t yours. It usually runs as root because it was started with sudo, or it belongs to another account on the Mac. Two things follow:

  1. Plain lsof can’t see it, so the port can look free while your server still fails to start. Use sudo lsof -nP -iTCP:3000 -sTCP:LISTEN.
  2. You need sudo to stop it: sudo kill 48213.

Don’t make sudo a habit for dev servers. A server started with sudo leaves root-owned files in node_modules/.cache or tmp/ that cause their own permission errors later.

What if Docker or AirPlay holds the port?

Docker. If a container publishes port 3000, lsof shows a Docker Desktop process (its name starts with com.docker), not your app. Killing that process takes all of Docker down. Stop the container instead:

docker ps --filter "publish=3000"
docker stop <container-id>

AirPlay Receiver on 5000 and 7000. Not port 3000, but it’s the other “port in use” surprise on a Mac. Since macOS Monterey, Control Center listens on 5000 and 7000 so the Mac can receive AirPlay. It shows up as ControlCe in lsof, and if you kill it, it comes straight back. Switch it off in System Settings › General › AirDrop & Handoff › AirPlay Receiver, or run Flask and other port-5000 apps on 5001.

Nothing listed, even with sudo? The port is probably in TIME_WAIT from a server that just exited. It clears on its own in about 30 seconds; the full guide explains why.

Is there a one-click way to kill a port on Mac?

Yes. FavTray’s Ports tool keeps a live list of every listening port on your Mac, with the app behind it and the project name for Node and Python servers, so you can tell which node is which. Click kill and it tries a normal stop first, then offers a force kill if the process ignores it. It lists only listening sockets, so your browser never shows up there. The developer cockpit in the menu bar also flags a dev server that stopped answering, and restarts or stops Docker containers.

Free vs Pro: the free plan includes 10 port kills a day, reset at local midnight. The one-time Lifetime licence makes it unlimited and adds threshold alerts. If you hit the free limit, the button copies the kill command for Terminal instead.

If you kill a port once a month, the commands above are all you need. If it’s several times a day across five projects, a list you can click saves the lsof round trip. For other menu bar tools developers keep open, see the best Mac developer tools for the menu bar.

Frequently Asked Questions

How do I kill port 3000 on a Mac?

Run lsof -ti tcp:3000 -sTCP:LISTEN | xargs kill in Terminal. It finds the process listening on port 3000 and sends it a normal stop signal. If it is still there a few seconds later, run the same command with kill -9. The -sTCP:LISTEN part makes sure you only kill the server, not a browser that has the page open.

What does EADDRINUSE mean?

EADDRINUSE is the error Node.js (and other runtimes) raise when the port you asked for is already bound by another process. The full message looks like Error: listen EADDRINUSE: address already in use :::3000. Find the owner with lsof -nP -iTCP:3000 -sTCP:LISTEN, stop it, or start your server on another port.

Why does kill say operation not permitted?

The process belongs to another user or to root, usually because it was started with sudo. Use sudo lsof -nP -iTCP:3000 -sTCP:LISTEN to see it, then sudo kill followed by the PID. Without sudo, lsof also hides other users' processes, so the port can look free when it isn't.

Is lsof -ti :3000 | xargs kill safe?

Mostly, but it matches every process with a connection on port 3000, including a browser tab that has your dev server open. With kill -9 that can force-quit part of your browser. Adding -sTCP:LISTEN (lsof -ti tcp:3000 -sTCP:LISTEN) limits it to the server that owns the port.

Can I free port 3000 without Terminal?

Yes. FavTray's Ports tool lists every listening port on your Mac with the app and project behind it and kills it with one click. The free plan includes 10 kills a day; the one-time Lifetime licence removes the limit.

Something new: My Dock Buddies