Port 9090 — Prometheus
TCP registered
What runs on port 9090
The Prometheus metrics server and web UI.
Security considerations
Prometheus has no authentication of its own. Put it behind a reverse proxy that does.
Checking whether something is listening
# Linux / macOS — what is bound to the port
sudo lsof -i :9090
sudo ss -lntp | grep :9090
# Windows
netstat -ano | findstr :9090
Get-NetTCPConnection -LocalPort 9090
# is it reachable from outside?
nc -zv example.com 9090
curl -v telnet://example.com:9090
Freeing the port
# find the process, then stop it
sudo lsof -ti :9090 | xargs kill # Linux / macOS
netstat -ano | findstr :9090 # note the PID, then:
taskkill /PID <pid> /F # Windows
Should this port be open to the internet?
Usually not. Expose it only if a specific external client needs it, and restrict by source address where you can.
Quick reference
| Port | 9090 |
| Protocol | TCP |
| Service | Prometheus |
| Range | Registered (1024–49151) — any user process may bind |
Frequently asked questions
What is port 9090 used for?
The Prometheus metrics server and web UI.
Is it safe to open port 9090?
Prometheus has no authentication of its own. Put it behind a reverse proxy that does.
How do I check if port 9090 is open?
Locally, sudo lsof -i :9090 on macOS or Linux, or netstat -ano | findstr :9090 on Windows. From outside, nc -zv host 9090 tells you whether anything answers.
Why do I get "address already in use" on port 9090?
Another process is bound to it — often a previous run of your own program that did not exit cleanly. Find it with lsof -ti :9090 and stop it, or configure your application to use a different port.
Can I change the port this service uses?
Almost always yes, in the service's configuration. Moving off a default port reduces automated scan noise, but it is obfuscation rather than security — a real attacker scans all 65,535.