The ritual
You run npm run dev and the terminal says no.
Error: listen EADDRINUSE: address already in use :::3000
Something has port 3000. You don't know what. It might be a server you started yesterday and forgot. It might be a process belonging to a terminal tab you closed, which did not take its process with it. It might be a container.
Finding out is four commands. Look up what holds the port. Get the process ID. Work out what that process actually is, which node alone will not tell you. Work out which directory it was started from, because you have six node processes and only one of them is the one you want. Then kill it, usually while quietly hoping you picked right.
I did this often enough that the ritual stopped registering as work. It was just friction I had absorbed. That's the part that eventually bothered me — not that it was hard, but that I had stopped noticing how often I did it.
So I built the answer instead. Sokket is a free macOS app that lists everything holding a port on your machine, names it in terms you recognise, and lets you act on it without leaving the window.
A port should say what it is
The whole app rests on one idea: a row should tell you what it is.
Open Sokket and you get a table of every port on the machine. The rows don't say node 30014. They say:
storefront · next dev · ~/code/storefront · 14% CPU · 412 MB
That name comes from the directory the process was started in. Sokket reads whatever file describes the project there — package.json for JavaScript, Cargo.toml for Rust — and falls back to the git repository name when there isn't one. So the table shows what you call the project, not what the kernel calls the process.
Click a row and the detail pane fills in the rest: the full command line, the working directory, CPU, memory, threads and open connections, the process tree showing what spawned what, and whether the port is reachable only from your own machine or from anyone on the network.
The buttons you came for sit alongside that: Kill, Forward, Watch Live, Record.
Containers are just rows
Docker, OrbStack, Colima and Podman ports appear in the same table as everything else, showing the container name, the image, and the compose service — not the anonymous proxy process that technically owns the port, which is the thing every other tool shows you and which tells you nothing.
You can stop the container or free just the port.
Answering "which service got which port after docker compose up" was the second ritual, and it needed the same fix as the first.
Killing things carefully
An app that kills processes on your behalf has to be careful, because the failure mode is somebody's afternoon.
Sokket asks a process to stop politely, waits, and only then forces it. Before forcing, it re-checks that the process is still the one you selected. Process IDs get recycled, and the window between "you clicked kill" and "the signal lands" is long enough for a number to be reassigned. Without that check, a tool like this eventually kills something innocent and you never find out why.
Kill tree lists every child it is about to stop before it stops anything. And you can kill by typing a port or a process ID, without finding the row at all — useful when you already know the number and don't need the table to tell you anything.
Watching, and remembering
Some problems refuse to appear when you're looking.
Live view opens a port in its own tab, with a chart per metric and a running request log, updating every second. Put the front end in one tab and the API in the next and you can watch both at once.
Recording captures a port over time, up to ten samples a second, while you get on with your work. A global shortcut drops a marker the moment something feels wrong, from whatever app you happen to be in. You can pause. Recordings survive a crash. The app estimates the file size before you start, because a capture that quietly fills your disk is its own kind of bug.
Playback is where a recording becomes useful. Zoom to the moment the memory line turns. Select a range and read its averages. Jump between detected problems — error responses, slow requests, memory drops, the Mac thermally throttling — rather than scrubbing for them. Read the requests that happened in any given second.
Compare puts two recordings on one chart. Record before the fix and after it, and the pull request gets evidence instead of "feels faster."
Exports cover the chart as an image, the metrics as a spreadsheet, the log as text, captured requests in the format browser dev tools already read, or the whole recording. Passwords, tokens and cookies are stripped as the recording is written, not on the way out — so a capture is safe to attach to an issue from the moment it exists, including the ones you forget you made.
Rules I gave myself
A tool that watches your machine is asking for a lot of trust, so a few things were fixed before I started.
Nothing leaves the Mac. Ports, projects, paths and recordings are never uploaded. The app talks to a server only when you ask it to check for updates or send feedback.
No accounts, no licence keys. It's free, and every feature is in every copy.
Nothing runs in the background. No helper, no daemon, no login item. Sokket samples only while its window is open and in front. Close it and it does nothing at all.
It stays small. About 5 MB to download, and a full scan of every port, process and container takes a few milliseconds.
Testing it the way it actually gets used
A developer tool that falls over under load is worse than no tool, because you reach for it precisely when things are already going wrong.
So I built a deliberately hostile setup: six containers under constant load — web servers, a database running benchmarks, a cache, a service flooding logs — with thousands of requests around them, ports opening and closing every few seconds, six live views at once, recordings having their settings changed mid-capture, and whole process trees being killed underneath it.
That found things no quiet test would have. A busy recording took over two minutes to open; it now opens instantly. Events recorded after a pause were placed at the wrong time. Jumping between detected problems got stuck on the first one and refused to advance.
Each of those is fixed, and each has a regression test, which is the only part of that sentence that matters. There are over 500 tests in total.
What it gives back
There's no single feature here worth writing home about. The value is a lot of small moments that stop costing anything.
A port is taken: type the number, read the row, kill it. Ten seconds instead of five minutes. Which service got which port: open Containers. What's exposed on café Wi-Fi: open Exposed and look. "Works on my machine": record while you reproduce it and hand over the capture. "Did the fix help?": compare two recordings and paste the numbers.
Each of those used to be a detour — a search, a half-remembered command, a guess. None of them was expensive on its own. Together they were a tax I'd been paying without itemising it.
That's the whole idea behind the tagline. Your machine shouldn't be something you interrogate. It should just tell you.
Sokket is free, for macOS 14 or later on Apple silicon, at sokket.app.