What is passd on Mac, and why is it using the network?
Last updated: 2026-07-31
passd is the Apple Pay and Wallet daemon supplied with macOS and launched on demand. Its network activity can support card setup, payment authorization, cross-device payments, and Wallet updates; Apple provides no master switch to disable it.
What it is
passd is Apple’s background daemon for Apple Pay and Wallet on macOS. It handles payment cards, payment authorization, and related requests made through Wallet services. The verified Apple identifier is com.apple.passd, and its executable is located under /System/Library/PrivateFrameworks/PassKitCore.framework/passd.
You do not open or control passd directly. launchd starts it on demand when the system needs one of the services it provides. This also means that seeing it appear in a process list does not imply that it runs continuously or that somebody opened an application manually.
The distinction between “important” and “essential” matters here. passd is important when you use Apple Pay or related Wallet functions. It is not required merely to keep the basic macOS operating system running.
Why it talks to the network
Several legitimate events can cause network activity associated with passd. Adding or re-adding an Apple Pay card may require eligibility checks and an exchange of device-token data with Apple, the card issuer, or the payment network. Paying with Apple Pay on a website or in an app can also require network communication to support payment authorization.
A Mac without payment cards stored locally can still participate in Apple Pay through an iPhone or Apple Watch. In that workflow, Apple’s servers help establish an encrypted payment-continuity channel between the devices. Wallet-related background sessions, push events, and cloud-state updates can create additional activity.
The local LaunchAgent explicitly declares services for APS, cloud storage, payments, payment continuity, and background NSURLSession events. That confirms the available service entry points, but it does not settle every connection detail. Apple has not publicly documented whether passd itself opens each connection involved in every workflow. Exact attribution to individual domains therefore remains unverified, and a domain should not be assigned to passd solely because it appeared near a payment or Wallet event.
How much traffic is normal
Apple has not published a normal per-process traffic baseline for passd, nor has it supplied a reliable numerical range. There is consequently no defensible number of megabytes that can be presented as a universal daily or monthly allowance.
Based on the verified triggers, ordinary activity should mainly consist of intermittent, relatively small control, eligibility, authorization, and status-update requests. Traffic may rise briefly while a card is being added, a payment is authorized, or a background update arrives. This kind of activity would normally be much smaller than software downloads, video delivery, or cloud-drive synchronization.
There is no reliable official basis for treating sustained high-volume transfer as normal passd behavior. If the process appears to move large amounts of data continuously, investigate the actual time window, executable path, and triggering events instead of relying on a generic optimization guide.
Can you turn it off
Apple does not provide a master switch that disables passd or all Apple Pay and Wallet background services. There is therefore no System Settings path for turning the daemon off.
Force-quitting or uninstalling passd is not an Apple-supported approach. Because it is managed by launchd, it may be started again when macOS requests one of its services. Interfering with it can also cause payment-card management, Apple Pay authorization, payments continued through an iPhone or Apple Watch, and related background updates to fail.
If you no longer want payment cards stored on the Mac, you can remove them individually:
Apple menu > System Settings > Wallet & Apple Pay > select a card > Remove Card
Removing cards is not the same as disabling passd. Safari’s “Allow websites to check for Apple Pay and Apple Card” option only limits whether websites can check availability. Likewise, Privacy & Security > Location Services > Wallet controls a specific permission. Neither setting is a process switch.
What people get wrong
1. “passd manages my passwords.” It does not. Apple’s own manual page identifies passd as the Apple Pay and Wallet daemon. The word “pass” here refers to Wallet and PassKit, not to login passwords.
2. “It is useless background software that can be disabled permanently.” passd is an on-demand Apple system component. Disabling or removing it can disrupt Apple Pay and Wallet workflows, and Apple offers no supported master switch for doing so.
3. “Any network connection from passd means malware or tracking.” Card setup, payment authorization, cross-device payment continuity, and background updates are all legitimate reasons for network activity. However, the process name by itself does not authenticate a file. A supposed passd executable outside the verified system location, or traffic that remains unusually heavy, still warrants investigation.
4. “passd synchronizes every pass, ticket, boarding pass, and payment card from all my Apple devices.” Public information does not establish that broad responsibility. Apple has not fully documented how duties are divided between macOS passd and other Wallet services. Payment cards also use a device-specific Device Account Number, so they should not be described as ordinary identical records copied across every device.
5. “Wallet synchronization makes passd transfer large amounts of data all the time.” There is no reliable official evidence for that claim. The verified model is event-driven and centered on control messages and updates. Persistent high-volume traffic should not be explained away as normal Wallet synchronization without further evidence.
6. “Turning off Safari’s Apple Pay detection option shuts down passd.” That Safari option only prevents websites from checking whether Apple Pay is available. It neither disables the daemon nor turns off every Apple Pay and Wallet background service.
Seeing what it actually used
The next step is to measure passd over the same period in which you noticed the activity, rather than guessing from a single process-list snapshot. Bytetally’s per-process statistics can show how much traffic passd used and when it occurred. Compare those times with card setup, payment, cross-device payment, and Wallet update events; investigate a sustained unexplained pattern separately.
Related processes
Common questions
Why is passd running on my Mac?
macOS launches passd on demand to handle Apple Pay, payment-card, and related Wallet service requests.
Is passd malware?
The Apple-supplied passd is a legitimate system component, but a matching process name alone does not prove that an unfamiliar file is authentic. An unexpected path or sustained abnormal traffic should be investigated.
Can I disable passd on macOS?
Apple does not provide a master switch for passd. Force-quitting or removing it is unsupported, may break Apple Pay and Wallet workflows, and may only cause launchd to start it again.
How much data should passd use?
Apple publishes no per-process baseline or numerical range. Expected activity is mainly intermittent, small control, eligibility, authorization, and status-update requests rather than sustained bulk transfers.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account