Email glossary · Practical guide

App password: a provider-issued credential with a specific lifecycle

An app password is a provider-issued credential for an eligible application connection. Availability and revocation rules depend on the provider and account policy.

Reviewed · Examples are illustrative

Who this helps: Readers checking a term before making an outreach or mailbox decision.

Meaning and common confusion

For Google accounts, app passwords have eligibility requirements and can be revoked after a main account password change. Their absence is not a reason to disable account protections. Prefer the supported authorization path and have an administrator review policy when necessary.

Source: Google: sign in with app passwords

Worked example

This is a synthetic illustration, not a customer result or a live configuration to copy.

Previously working app credential
Main account password changes
Connection begins failing
Investigation: check credential revocation and the supported reconnection path
Do not expose either credential in an error screenshot.

Checks to make

  1. Confirm the account supports the intended method.
  2. Use a distinct approved credential rather than sharing the main password.
  3. Verify both sending and receiving after replacement.

Next step and limits

Use the missing or revoked app-password guides for a specific failure. Do not assume every provider offers this mechanism or that it bypasses protocol restrictions. Store it as a secret and remove obsolete credentials through the provider's process.

Source: Google: sign in with app passwords

Source references

Worked examples are illustrative. Editorial procedures are suggested methods, not measured performance claims or promises of additional product features.

Related guides

Explore the Zintara workflow