What is akd on Mac, and why is it using the network?

Last updated: 2026-07-31

akd is a built-in macOS daemon that supports Apple Account authentication and authorization through AuthKit. Its network activity can be legitimate, while sustained high traffic needs separate investigation because Apple publishes no normal baseline.

What it is

akd is a background daemon included with macOS. It belongs to Apple’s AuthKit framework and provides Apple Account authentication and authorization services to system components. Apple Account is the current name for what was formerly called Apple ID, which explains aliases such as “Apple ID authentication daemon” that still appear in discussions about the process.

The verified system executable is located at /System/Library/PrivateFrameworks/AuthKit.framework/Versions/A/Support/akd. Its local code-signing identifier and launchd configuration both use com.apple.akd. Those details matter when identifying the real system service: a different file cannot be considered legitimate merely because its executable is also named akd.

Apple has not published a complete description of every responsibility assigned to akd. It is therefore reasonable to describe it as an AuthKit service for Apple Account authentication and authorization, but not as the single process that manages or refreshes every credential used by iCloud, the App Store, FaceTime, or other Apple services. Those services may depend on an Apple Account without placing all of their account work inside akd.

Why it talks to the network

Authentication cannot always be completed solely with information stored on the Mac. akd may connect to Apple’s authentication and account-security services when a user signs in to an Apple Account, is asked to verify the account again, or uses Sign in with Apple. Network activity may also occur while handling two-factor authentication and during some passkey, account-security, or account-recovery workflows.

The locally inspected launchd configuration also contains scheduled or event-driven network work. It lists daily health checks associated with Sign in with Apple and passkeys, a service-list update, and a network task following a system upgrade. This means that an akd connection does not necessarily coincide with someone manually entering a password. Periodic activity can arise from the system’s own configured checks and updates.

The exact server domains, protocols, and mapping between individual Apple services and akd have not been made public. It would therefore be misleading to turn a connection from this process into a claim about one particular Apple product or type of data. In particular, there is no reliable evidence that akd transfers iCloud documents, photo libraries, or the audio and video content of FaceTime calls. Its verified role is in the authentication and authorization control path, not in those content-transfer functions.

How much traffic is normal

Apple does not publish a normal traffic baseline for akd. There is no verified number of kilobytes or megabytes that can serve as a universal daily, weekly, or per-login limit. A fixed numerical threshold would imply evidence that is not available.

Its verified role does support a cautious expectation: authentication and account-security operations would generally involve low-volume, intermittent requests, substantially less traffic than cloud-drive synchronization, photo downloads, or an audio or video call. That is an inference from the type of work akd performs, not an Apple-published measurement. Activity can rise briefly during sign-in, re-verification, recovery, or failed retries.

Sustained high-volume traffic should not be labeled normal solely because the process is named akd. The process name establishes neither what caused a particular transfer nor whether repeated activity succeeded. The useful questions are when the traffic happened, whether the Mac was signing in or requesting verification at that time, whether retries continued, and whether the executable matches the known system path and signing identifier.

Can you turn it off

Apple does not provide a supported System Settings switch for disabling akd, so there is no settings path to follow. It is an on-demand system service rather than an optional network feature with its own user-facing toggle.

Force-quitting akd or persistently blocking it with a firewall can cause Apple Account sign-in or re-verification to fail. Sign in with Apple, some passkey operations, and account-security workflows may also fail or repeatedly ask for attention. Because launchd manages the service, macOS may start it again when another component needs it. Blocking it may consequently replace a small authentication request with failures and further retries rather than permanently eliminating its activity.

Signing out of the Apple Account is a different action. The path is System Settings, your name, then Sign Out, and it disables related account services on that Mac. It is not an akd switch, does not remove the daemon, and should not be described as a way to turn the process itself off.

What people get wrong

Seeing what it actually used

When the concern is a specific spike, the next step is to measure akd rather than estimate from its name. Bytetally’s per-process statistics can show how much network traffic was attributed to akd during the period in question. Compare that timing with sign-in, re-verification, recovery, or repeated account prompts before deciding whether the activity needs further investigation.

Related processes

Common questions

Is akd malware or spyware?

The copy at the documented system path with the com.apple.akd signing identifier belongs to macOS. A file elsewhere is not trustworthy merely because it uses the same process name.

Why is akd connecting to the internet?

It may contact Apple during Apple Account authentication, Sign in with Apple, two-factor authentication, and some passkey, account-security, or recovery workflows.

Can I disable akd on my Mac?

Apple provides no supported switch for disabling akd. Terminating or persistently blocking it can disrupt authentication and may only cause launchd to restart it.

Does akd upload my iCloud files or FaceTime calls?

There is no reliable evidence that akd transfers iCloud files, photos, or FaceTime audio and video. Its verified role concerns authentication and authorization.

See exactly how much it used

Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.

Download Free on the Mac App Store

macOS 14 Sonoma or later · 100% on-device · No account