troubleshooting

Google App Passwords Deprecated? What Changed and What Still Works

Key takeaways

  • did google get rid of app passwords? No. Google removed less secure app access - signing in with just your plain password - for personal accounts in 2022 and for Google Workspace accounts by mid-2025.
  • why did my email client stop working with my regular gmail password? Your client was almost certainly using plain password sign-in, known as less secure app access, which Google shut off for personal accounts on May 30, 2022, and for Google Workspace accounts by May…
  • what is the difference between an app password and less secure apps? Less secure app access let a third-party app sign in with your actual account password and nothing else - no second factor at all.

Short answer: Google did not remove app passwords. It removed less secure app access - plain username-and-password sign-in with no app-specific code - for personal accounts in 2022 and for Google Workspace accounts through 2025. App passwords are the thing that replaced that access, they still work today provided you have 2-Step Verification turned on, and for most third-party mail tools that is exactly what you still need to generate.

  • If your mail client or sending tool suddenly stopped working with your normal Gmail password: that is the less-secure-apps cutoff, not app passwords being removed. Turn on 2-Step Verification and generate an app password instead.
  • If you already have an app password and it stopped working: check whether your Google Workspace admin disabled app password generation for your organization - that is an admin choice, not a global Google policy change.
  • If your tool only supports full Google sign-in and not app passwords: that depends on what that specific tool has built, not on anything Google changed this year.
  • If you are trying to connect a Gmail mailbox to WarmySender specifically: jump to the section on what that actually requires.

What Actually Changed (It Is Not What Most People Think)

A great deal of confusion around this topic comes from two genuinely different Google features sharing enough surface similarity that people use the names interchangeably. They are not the same thing, they were not deprecated on the same schedule, and only one of them is actually gone.

Less secure app access was a setting that let a third-party app sign in to your Google account using nothing but your regular account password - no extra code, no app-specific credential, just the same password you use to sign in to Gmail yourself. Google turned this off because a single leaked password was enough to compromise the account through any app using it, with no second factor involved anywhere in the process.

App passwords are a different mechanism: a 16-character code, generated by Google, tied to your account only after you turn on 2-Step Verification, used in place of your real password specifically by apps and devices that cannot do a modern sign-in flow. This is not a workaround Google is quietly trying to kill - it is the officially supported answer to the question of what to use once an app can no longer use less secure sign-in.

So when someone says Google deprecated app passwords, what usually actually happened is one of three things: their less-secure-apps access was cut off and they have not yet generated the app password that replaces it, their Google Workspace administrator disabled app passwords specifically for their organization, or they are reading Google's own language discouraging app passwords in favor of full sign-in and concluding the door is already closed when it is not.

App Passwords and "Less Secure Apps" Are Two Different Things

Less secure app accessApp passwords
What it isSigning in with your actual account password, no extra codeA separate 16-character code generated specifically for one app or device
Requires 2-Step VerificationNo - this is what made it riskyYes, always. You cannot generate one without it turned on first
Current status for personal accountsGone since May 30, 2022Still available today
Current status for Google WorkspaceGone - fully disabled across all Workspace accounts by mid-2025Still available by default, unless an admin has restricted it
What Google says about itNo longer offered at allNot recommended and unnecessary in most cases - discouraged, not disabled
What replaces it if unavailableAn app password, or full Google sign-in if the app supports itFull Google sign-in, if the specific app or tool has built support for it

The practical difference that matters to you: if a tool needs to sign in to Gmail using a plain username and password with nothing else, that stopped working years ago and nothing brings it back. If a tool needs an app password, that almost certainly still works right now, and the fix for it having stopped is almost always that 2-Step Verification was never turned on, or the app password was never actually generated and entered in the right field.

The Actual Timeline

  • May 30, 2022 - Google removed the "Allow less secure apps" toggle from personal Google accounts. Any tool relying on plain password sign-in for a personal Gmail account stopped working from this date.
  • 2023 to 2024 - Google announced the same change for Google Workspace accounts, with an original target date that slipped and was pushed back once.
  • March 14, 2025 - Google's enforced deadline for Google Workspace: third-party apps needed to use full Google sign-in rather than a plain password to access Gmail, Calendar, and Contacts.
  • May 1, 2025 - The underlying less-secure-apps access was fully disabled across all Google Workspace accounts, closing out the transition that started with personal accounts three years earlier.

Nowhere in that timeline did Google announce removing app passwords themselves. What repeatedly changed was plain-password access, in two separate waves, personal accounts first and Workspace accounts later. If your tool broke specifically on one of these dates, that is almost certainly what happened to it.

Personal Gmail vs Google Workspace: Different Rules

Whether an app password is available to you at all depends on which kind of account you have.

On a personal Gmail account, app passwords remain a self-service feature: turn on 2-Step Verification, generate one, done. Nobody above you can turn this off, because there is no administrator on a personal account.

On a Google Workspace account, app passwords are available by default, but an administrator can restrict or turn them off entirely for the organization, the same way they can restrict less secure apps at the org level. If you are on a company Google account and cannot find the option to generate an app password at all, this is the single most likely explanation, and it means the fix is a conversation with your admin, not a setting on your own account.

Are App Passwords Actually Gone? What Still Works Today

As of today, no. Google's own current account help documentation describes app passwords as available for personal accounts with 2-Step Verification enabled, explicitly for the case of less secure apps or devices that would otherwise be blocked entirely. The mechanism, the requirement, and the purpose are unchanged from how they have worked for years - what changed around them is that the alternative, plain password sign-in, went away, making app passwords the only password-based option left rather than one of two.

Google's language does actively steer people away from app passwords, calling them not recommended and unnecessary in most cases, and pushing full Google sign-in as the preferred route wherever an app supports it. That is a real trend worth taking seriously - Google has spent several years narrowing password-based access down to fewer and fewer paths, and app passwords are clearly not where the company wants sign-in to end up long-term. But discouraged and disabled are different states, and right now, app passwords are the former, not the latter.

Why Google Is Doing This at All

It is worth understanding the reasoning, because it explains why this trend is very unlikely to reverse. A plain password is a single, static secret that works from anywhere, forever, until it is deliberately changed. If it leaks - through a phishing page, a reused password exposed in an unrelated breach, or malware on a shared device - anything that can present that password can sign in as you, with no second check at any point in the process.

An app password narrows that risk considerably even though it looks similar to a password on the surface. It only exists behind an account that already has 2-Step Verification turned on, it is scoped to a single app rather than usable everywhere the real password would be, and it can be individually revoked without touching your main password or any other app password you have generated. Full Google sign-in narrows the risk further still, since no password-equivalent secret sits inside the third-party tool at all - the tool never sees anything it could leak. Google's stated direction moves accounts toward that end of the spectrum over time, which is why the language around app passwords keeps getting more discouraging even while the feature itself keeps working exactly as before.

Who Is Actually Affected

  • Anyone using an older mail client or device that was configured years ago with a plain Gmail password directly typed into an IMAP or SMTP setting - printers, scanners, some CRMs, and older desktop mail apps are common examples. These stopped working on the relevant cutoff date and need an app password entered in place of the real password, with nothing else changed in the setup.
  • Anyone on a personal account without 2-Step Verification turned on. App passwords cannot be generated at all until 2-Step Verification is active first - this is the most common reason someone concludes app passwords do not exist anymore when really they were never eligible for one yet.
  • Google Workspace users whose admin has restricted app passwords. The option is simply missing from account settings, and no amount of retrying fixes it from the user side.
  • Anyone using a cold-email or warmup tool that connects over IMAP and SMTP rather than through a native Google sign-in integration. These tools were built around the credential-based model from the start, and for them, an app password is not a workaround - it is the intended way to connect a Gmail mailbox.

How to Generate a Working App Password Today

  1. Turn on 2-Step Verification first if it is not already active. Go to your Google Account, then Security, then 2-Step Verification, and follow the setup. This is a hard requirement - the app password option does not appear at all until this is done.
  2. Go to your Google Account, then Security, then App passwords. If this option is not visible after 2-Step Verification is confirmed on, you are very likely on a Google Workspace account where an admin has restricted it - see the section below.
  3. Create a new app password. Give it a name that identifies what it is for, so you can find and revoke it later without guessing.
  4. Copy the 16-character code Google generates. It is shown once. If you lose it before entering it somewhere, you cannot retrieve it again - you delete it and generate a new one instead.
  5. Enter it in place of your real password in whatever tool's IMAP or SMTP password field you are setting up. The username stays your full Gmail address; only the password field changes.
  6. Leave the rest of the connection settings alone. Host, port, and encryption settings for Gmail's IMAP and SMTP servers have not changed as part of any of this.

One detail that surprises people: an app password is automatically revoked if you later change your main account password. If a working connection suddenly stops authenticating and you recently changed your Google password for an unrelated reason, that is almost always why - generate a fresh app password and update it wherever the old one was entered.

A second detail that trips people up just as often: an app password is not the same as your account recovery codes, and it will not appear anywhere near your regular sign-in screen. If a tool is asking for a password and rejecting your normal one, and you are confident 2-Step Verification is on, go back to the App passwords screen specifically rather than trying variations of your real password - no variation of it will ever work again for a tool that requires this credential.

When Your Workspace Admin Is the One Blocking It

If you are on a company Google account and the app password option is missing entirely, this is almost always a deliberate organizational security setting, not a bug and not a Google-wide change. Administrators can restrict app password generation the same way they control less secure app access, usually to force every connection through full Google sign-in for better visibility and easier revocation across the organization.

If you need an app password for a legitimate business tool and your organization has this restricted, the conversation is with your Workspace administrator, not with Google support and not with any setting on your own account. Ask them specifically whether app passwords can be enabled for your account, or whether the tool you are trying to connect has a supported alternative your organization already allows.

The Real Alternatives, Honestly Compared

OptionWhat it takesWhere it worksTrade-off
App password2-Step Verification turned on, then generate a 16-character codeAny tool that has an IMAP, SMTP or POP password fieldSimplest and most widely compatible option; Google discourages it long-term but it works today
Full Google sign-inNothing on your end beyond signing in through a popup when the tool asksOnly tools that have specifically built support for Google's sign-in flowMore secure since no password-like credential sits inside the tool, but only available where the tool supports it
Admin-granted exception (Workspace only)Your administrator enabling app passwords or a specific integration for your accountGoogle Workspace accounts where an admin has otherwise restricted thisRequires cooperation from whoever administers your organization's Google account
Switching to a different mailbox or sending setupA genuinely different mail provider or sending arrangementAlways works, since it sidesteps the question entirelyThe most disruptive option, worth it only if the first three are all genuinely unavailable to you

For almost everyone reading this because a cold-email, warmup, or CRM tool needs to authenticate against Gmail over IMAP or SMTP, the first option is the answer. It is not a downgrade or a workaround - it is the current, fully supported way to do exactly that.

What This Means for Connecting a Gmail Mailbox to a Sending Tool

WarmySender connects Gmail mailboxes over IMAP and SMTP, the same way most cold-email and warmup platforms do. That means the credential it needs in the password field is an app password, not your regular Google sign-in password - WarmySender does not offer a Google sign-in option for connecting a Gmail mailbox.

In practice, that means the setup is exactly the process described above: turn on 2-Step Verification if it is not already on, generate an app password from your Google Account security settings, and enter that 16-character code as the password when you connect the mailbox. If you are on a Google Workspace account and the app password option is missing, that is between you and your admin, not something a sending tool on either end can work around.

Keeping an App Password Safe

  • Generate a separate app password for each tool rather than reusing one everywhere. If you ever need to cut off access for a single tool, you revoke that one code without touching anything else.
  • Name each one clearly when you create it, so your app passwords list is still meaningful six months later.
  • Revoke anything you no longer use. An app password for a tool you stopped using months ago is a standing piece of access nobody is watching.
  • Remember it is tied to 2-Step Verification, not a replacement for it. Turning off 2-Step Verification revokes every app password associated with the account at once.
  • Treat a leaked app password like a leaked password, because functionally that is what it is for the one app it was created for - revoke it immediately and generate a new one if you ever suspect it was exposed.

If Nothing Works: When to Involve Your Admin or Switch Providers

Work through this order before assuming you are stuck:

  1. Confirm 2-Step Verification is genuinely on, not just available - this is the single most common reason the app password option does not appear.
  2. Confirm you are looking in the right place: Google Account, then Security, then App passwords, on the account itself rather than inside the tool you are trying to connect.
  3. If it is a Workspace account and the option is missing after 2-Step Verification is confirmed on, ask your administrator directly whether app passwords are restricted for your organization.
  4. If your admin confirms they are restricted and cannot be enabled for a legitimate reason, ask what alternative your organization does support for the specific kind of tool you are trying to connect.
  5. Only after all of that is genuinely exhausted does moving the mailbox to a different setup become the right next step, rather than the first thing to try.

Is This Just a Google Thing?

No - the same shift has happened at Microsoft, on a broadly similar timeline, which is useful context if you manage mailboxes across both. Microsoft 365 also moved away from plain-password sign-in for mail clients in favor of modern authentication, and Microsoft's own version of an app password - generated the same way, behind two-step verification - fills the same gap for tools that cannot use full Microsoft sign-in.

If you handle a mix of Gmail and Outlook or Microsoft 365 mailboxes for cold outreach or warmup, expect to need the same two-step-verification-plus-generated-code pattern on both sides, even though the exact menu paths and terminology differ between the two. Neither provider has left a plain-password path open for third-party mail clients any more, and neither is likely to reopen one - the direction of travel across the industry has been the same for several years now, driven by the same credential-leak math regardless of which company's account is involved.

Where WarmySender Fits

To be direct about the limits here: WarmySender cannot turn on 2-Step Verification for you, cannot generate a Google app password on your behalf, and cannot override a Workspace admin's decision to restrict them. Those are account-level and organization-level settings that live entirely inside Google, and no connected tool can reach past them.

What WarmySender does once a mailbox is actually connected is run the rest of your outreach around it: cold email campaigns with per-mailbox daily sending caps and paced delivery, peer-to-peer email warmup that builds a real sending history before a mailbox carries a real campaign, LinkedIn outreach and multichannel sequences that combine email and LinkedIn, and mailbox health monitoring that watches for problems after the connection is working. Getting a Gmail mailbox connected with a working app password is the first step - everything after that is where the platform earns its place.

See how WarmySender works.

Frequently asked questions

did google get rid of app passwords?
No. Google removed less secure app access - signing in with just your plain password - for personal accounts in 2022 and for Google Workspace accounts by mid-2025. App passwords are a separate, still-active feature that replaced that access: a 16-character code tied to 2-Step Verification, generated specifically for apps that cannot do a modern sign-in. Google discourages using them in favor of full sign-in, but discouraged is not the same as disabled.
why did my email client stop working with my regular gmail password?
Your client was almost certainly using plain password sign-in, known as less secure app access, which Google shut off for personal accounts on May 30, 2022, and for Google Workspace accounts by May 2025. The real password itself has not been usable for third-party mail clients since those dates. The fix is turning on 2-Step Verification and generating an app password, then entering that 16-character code in place of your real password.
what is the difference between an app password and less secure apps?
Less secure app access let a third-party app sign in with your actual account password and nothing else - no second factor at all. Google removed that entirely. An app password is a separate, single-purpose 16-character code that only exists once 2-Step Verification is turned on, generated specifically for one app or device. It is the officially supported replacement, not a lesser version of the same risk, and it remains available today.
can I still create a gmail app password in 2026?
Yes, for a personal Google account with 2-Step Verification turned on. Go to your Google Account, then Security, then App passwords, and generate one - the option has not been removed. If you do not see it, either 2-Step Verification is not actually active yet, or you are on a Google Workspace account where an administrator has restricted app passwords for the organization, which is a separate setting from anything Google controls globally.
why does my work google account not show the app password option?
On Google Workspace, administrators can restrict app password generation for the whole organization, the same way they control less secure app access. If 2-Step Verification is confirmed on and the option still is not there, this is almost always the reason. It is a deliberate choice made inside your organization's own Google settings, not something Google removed universally, and the fix is asking your administrator to enable it or suggest an approved alternative.
is an app password safe to use?
Reasonably, yes, when used correctly. It only exists after 2-Step Verification is enabled, it is scoped to whichever app or device you generate it for, and it can be revoked individually without touching your main password or other app passwords. Generate a separate one for each tool rather than reusing a single code everywhere, name each one so you can identify it later, and revoke anything tied to a tool you have stopped using.
what do I use instead of an app password if my tool doesn't support one?
Check whether the tool supports full Google sign-in, often labeled Sign in with Google, which needs nothing from you beyond approving the sign-in popup. If the tool supports neither an app password field nor Google sign-in, the realistic options are asking a Workspace admin about an approved alternative, or connecting a different mailbox that the tool does support. There is no third hidden option Google has not documented somewhere.
does google workspace still allow app passwords?
By default, yes, provided 2-Step Verification is turned on for the account, the same requirement as a personal account. The difference is that a Workspace administrator can restrict or disable app password generation across the organization, which personal accounts have no equivalent control for. If they are unavailable on a work account, that is an organizational setting your admin controls, not a change Google has made to app passwords generally.
AK
Technical Content Lead · WarmySender
Writes about email deliverability, sender reputation, cold outreach, and LinkedIn prospecting — turning the mechanics of the inbox into plain-English playbooks.