# How do we remove firm os?

> From the install's own page, with another Allow. It deletes firm os's parts, with all their data, keeps the account's own setup, and can't be undone.

Open the install's own page with `/remove` after its address, and press Allow on the Cloudflare page again. The installer then deletes firm os's parts, with all the data in them, and keeps the account's own setup. This can't be undone.

## How

1. Open the install's own page and choose **Remove firm os**, or add `/remove` to its address, which opens it.
2. The page says how many things it will delete and names what the account keeps, and lifts what it would delete a little off its plate. Press **Remove with Cloudflare**.
3. On the Cloudflare page, tick the account firm os is in and press Allow. An Allow that doesn't cover that account changes nothing.
4. The page shows each part going. When it is done, the installer revokes the key.

It takes a new Allow because the installer kept no key after the install.

## What is deleted, in order

1. **The nine Workers**, the router first: it is what people open, and it calls the others. Deleting a Worker deletes the data its Durable Objects hold.
2. **The three key-value stores, then the R2 bucket**, with everything in them. The bucket is emptied before it is deleted, a few hundred files at a time.
3. **The sign-in app** that guards the firm's address.

Only what is on the install's own list is deleted. Before making anything, the install checked that every name it would use was free, so nothing the account already had is on that list.

## What is kept

The account's own setup stays, because other things may use it, even where the install made it:

- the workers.dev name
- the Zero Trust team
- sign-in with email codes
- the AI Gateway `default`

The account's plan doesn't change: Workers Paid continues until the firm cancels it in the Cloudflare dashboard ([cost](https://firmos.railblocks.com/docs/cost)). A Mac app someone installed stays on their Mac.

## When something stops

- An install that stopped part-way can be removed the same way: Remove deletes what it made so far.
- If a removal stops, the page says why. Until an hour after the Allow, **Try again** carries on with the key the installer still holds; after that, **Remove again** takes a new Allow. Either runs it once more, passing over what is already gone.
- A removal can't start while an install or removal is still running.

Updated 2026-10-02.
