# What Is /Library/PrivilegedHelperTools on Mac?

> PrivilegedHelperTools holds programs apps install to do work as root. They outlive the app and should be removed together with their launchd plist.

- Updated: 2026-10-10
- URL: https://fresh.ist/library/system-privileged-helper-tools/

**TL;DR:** /Library/PrivilegedHelperTools holds helper programs that apps install so they can perform tasks needing root, like changing network settings or installing updates. Each helper is started by a matching plist in /Library/LaunchDaemons. Deleting the app leaves both behind, so remove a leftover helper together with its plist, using administrator rights.

## Definition

- Full path: `/Library/PrivilegedHelperTools`
- Scope: system (shared, owned by macOS/root)
- Freshist checks this folder when uninstalling an app. When you uninstall an app, Freshist only considers items directly inside this folder whose name matches the app's bundle ID. They're never pre-selected, and because the folder is owned by macOS (root), selected items are deleted permanently by Freshist's signed helper rather than moved to the Trash.

## Why apps install helpers

A regular Mac app runs with your user's permissions. Some jobs need more than that: managing network interfaces, installing software system-wide, controlling hardware, setting up virtual machines. Rather than running the whole app as root, macOS lets an app install a small, separately signed **privileged helper** that does only those tasks.

For years Apple's mechanism for this was `SMJobBless`. It copies the helper binary into `/Library/PrivilegedHelperTools` and writes a launchd plist with the same label into [/Library/LaunchDaemons](/library/system-launch-daemons/). The app then talks to the helper over XPC. Apple has since introduced `SMAppService`, which keeps the helper inside the app bundle. You'll still find many helpers here, though, because widely used apps continue to install them the older way.

## The leftover problem

`SMJobBless` has no uninstall step. When you drag the app to the Trash:

| Piece | Where | After the app is deleted |
|---|---|---|
| App | `/Applications` | Gone |
| Helper binary | `/Library/PrivilegedHelperTools/<label>` | Still there |
| Launchd plist | `/Library/LaunchDaemons/<label>.plist` | Still there; can keep starting the helper as root |

A helper that runs as root with no app to talk to has no purpose, and it no longer receives updates. Some developers ship an uninstaller or a "remove helper" option for this reason.

## Inspecting it read-only

```
ls -la /Library/PrivilegedHelperTools
ls -la /Library/LaunchDaemons
codesign -dvv /Library/PrivilegedHelperTools/com.example.helper
sudo launchctl print system/com.example.helper
```

The file name of a helper is normally its launchd label, so the matching plist is easy to spot. `codesign -dvv` shows who signed the helper (the Authority and TeamIdentifier lines), which tells you the vendor even when the name is cryptic. `launchctl print` shows whether it's currently loaded and running.

## Removing a leftover helper

1. Look for the vendor's own removal option first, in the app's settings, its uninstaller or its support pages.
2. If the app is already gone, unload the job, then remove both files:

```
sudo launchctl bootout system /Library/LaunchDaemons/com.example.helper.plist
sudo rm /Library/LaunchDaemons/com.example.helper.plist
sudo rm /Library/PrivilegedHelperTools/com.example.helper
```

3. Restart the Mac.

Finder works too: drag both items to the Trash and enter an administrator password. Unload the job first, though, or the helper keeps running until you restart.

Keep helpers for apps you still use. Removing one doesn't break the app permanently, but it will ask for your password again to reinstall it, and features that depend on it stop until it does.

## Freshist and helper names

As the facts box notes, Freshist only offers items here when their name matches the app's bundle ID, and deletes them permanently because the folder belongs to root. Helper labels often differ from the app's ID, such as `com.example.vmnetd` for an app identified as `com.example.app`, so check this folder and LaunchDaemons yourself after removing an app that once asked for your password. The full checklist is in [how to uninstall apps completely](/blog/uninstall-apps-mac-completely/), and [/safety/](/safety/) explains how Freshist handles folders owned by macOS.

## Sources

- [SMJobBless](https://developer.apple.com/documentation/servicemanagement/smjobbless(_:_:_:_:)) (Apple Developer Documentation)
- [SMAppService](https://developer.apple.com/documentation/servicemanagement/smappservice) (Apple Developer Documentation)
- [Creating Launch Daemons and Agents](https://developer.apple.com/library/archive/documentation/MacOSX/Conceptual/BPSystemStartup/Chapters/CreatingLaunchdJobs.html) (Apple Daemons and Services Programming Guide)

## Frequently asked questions

### Why did an app ask for my password once and never again?

That's usually the moment it installed its privileged helper. From then on the helper does the root-level work, and the app talks to it without asking you again.

### Do all apps that need admin rights put a helper here?

No. Apps built on Apple's newer SMAppService API keep their helper inside the app bundle and register it with macOS, so nothing is copied to this folder and deleting the app removes it.

### Is the helper still running after I deleted the app?

Possibly. If its launchd plist is still loaded, launchd can keep starting it. Check with sudo launchctl print system/<label>, and restart after removing the files.

---

Canonical page: https://fresh.ist/library/system-privileged-helper-tools/
Official site: https://fresh.ist/ (fresh.ist only)
Generated: 2026-10-10
