How to uninstall OWASP ZAP on Mac
Save the ZAP sessions, scripts and reports you need before removing OWASP ZAP. This guide covers the official Mac app and Homebrew cask, not a separately installed command-line distribution, container or browser proxy setup.
Quit and remove the app
Stop active work and quit ZAP, then move ZAP.app from Applications to the Trash. Keep exported sessions and reports at their chosen locations. If you configured another browser to send traffic through ZAP, undo that configuration separately before trying to browse without ZAP.
Review the local data
In Finder, choose Go › Go to Folder and open each exact path below. Copy anything you need first, then move only the app-owned item you have decided to discard to the Trash. These locations come from the Homebrew removal list or the recorded local check; a missing location needs no cleanup.
| Location | What to keep or remove |
|---|---|
~/Library/Application Support/ZAP |
Support data observed in the test and named by Homebrew; inspect and back up anything useful before removal. |
~/Library/Preferences/org.zaproxy.zap.plist |
Alternate ZAP preferences; removing them resets these settings. |
Check the result
These commands only list the app and the locations discussed above. The app filename comes from the cask; adjust it if your official-download bundle has a different name.
ls -ld "/Applications/ZAP.app"
ls -ld "$HOME/Library/Application Support/ZAP"
ls -ld "$HOME/Library/Preferences/org.zaproxy.zap.plist"
An entry printed by ls still exists at that path. No such file or directory means that exact item is absent; Permission denied or Operation not permitted means the check could not establish its state. A retained data folder is expected if you chose to keep it. This check does not search every disk or cloud account.
If you installed it with Homebrew
Uninstall without running zap:
brew uninstall --cask zap
This removes Homebrew's managed app artifacts without applying its zap list. The live cask contains a Gatekeeper-related disable declaration; this is removal guidance for an existing installation, not a recommendation to bypass that block. A “not installed” error means Homebrew has no matching cask installation; use the Finder route for a manually copied app.
The live cask source names these additional zap targets:
~/Library/Application Support/ZAP~/Library/Preferences/org.zaproxy.zap.plist
Some targets can hold settings or personal data. Keep the paths you still need and back them up before considering brew uninstall --cask --zap zap. That direct command applies the cask's entire zap list regardless of Mole's checkboxes. Mole uses zap only when its complete scope passes its selection and shared-data checks; unchecked, shared, out-of-boundary or unsupported targets suppress zap, while selected remnants use Mole's own removal path.
What Mole lists
Mole lists ~/Library/Application Support/ZAP and ~/Library/Preferences/org.zaproxy.zap.plist for review, not selected by default. The latter is an explicit alternate-identity rule. This is not a claim that all ZAP sessions or every location under the ZAP name is scanned. These defaults describe the app-data option switched off. Opting into Remove data and settings with apps also selects eligible reviewed app data; shared stores and protected data retain their individual review or protection.
What this test covered
The official Mac application and its Application Support folder were removed on 21 September 2026. The test did not create the home-directory ZAP store and did not scan websites. The alternate preferences leaf was added to the scanner after the observed gap. Homebrew instructions were checked against the current cask, but this record does not establish a Homebrew-managed uninstall or removal of every possible leftover.
