Gmail App Password Option Missing? Here's Why

The short answer
The app password option in your Google Account is missing for one of four reasons: 2-Step Verification is not enabled, a Workspace admin has blocked access, your account type never supported them, or Google has removed them for your scenario. Enable 2-Step Verification first; if the option still does not appear, the cause is almost certainly admin policy.
Gmail app password option missing? Four causes and exact fixes: 2-Step Verification off, admin policy block, account type, or Google withdrawal.
On this page
If the gmail app password option is missing from your Google Account security page, you are looking for a setting that is either hidden behind a prerequisite you have not met, blocked by a policy you cannot change yourself, or gone from your account type entirely. Google does not grey it out or show a message explaining why — it simply removes the option from view, which is why searching the page or clicking around the Security tab will not help.
App passwords are 16-character codes that let older email clients and apps sign in to Gmail when they cannot use Google's modern OAuth-based flow. Most people encounter them when connecting a third-party mail client via IMAP — Thunderbird, Apple Mail, Outlook with a manual IMAP setup, or a legacy app that accepts only a plain username and password. When the option is missing, the connecting app fails with a generic 'incorrect password' error that gives no indication of the actual problem.
There are four reasons the option disappears. First and most common: 2-Step Verification is not enabled on your account, and Google refuses to show app passwords until it is. Second: you are on a Google Workspace account and an administrator has disabled app passwords at the domain level. Third: your account is enrolled in Google's Advanced Protection Program, which replaces app passwords with security keys by design. Fourth: your account type or current configuration simply does not support them. This post identifies which of the four applies to you and tells you exactly what to do — including the cases where the fix is not in your hands.
Before you start: confirm where the option should appear#
App passwords do not appear in the main Security page, in Gmail settings, or anywhere else in your Google Account other than one specific location. They live inside the 2-Step Verification detail page: myaccount.google.com, then Security in the left panel, then scroll to 'How you sign in to Google,' then click 2-Step Verification, then scroll to the bottom of that sub-page. If you are not navigating to exactly that spot, the option looks missing even when it is available.
Before assuming the option is blocked, confirm two things. First: which Google account are you actually signed in as? Browser profiles, multiple Google accounts in one session, and autofill make it easy to check the wrong address. Open myaccount.google.com and verify the email shown in the top-right corner matches the account you are trying to configure. Second: is this a personal Google Account or a Google Workspace account — one tied to a custom domain for a company, school, nonprofit, or government organisation? The fix differs by account type, and Workspace accounts have an administrator policy layer that personal accounts do not.
A note on mobile browsers: Google's Account security pages render differently on mobile, and some sub-pages — including the App passwords section — are difficult to reach through a mobile browser. If you are troubleshooting on a phone, switch to a desktop browser or enable desktop mode in your mobile browser before continuing.
The option is inside 2-Step Verification, not the main Security list
Steps to enable 2-Step Verification and reach app passwords#
For a personal Google Account, the single most common reason the app password option is missing is that 2-Step Verification is turned off. Google hides the App passwords section entirely until 2SV is active — this is not a bug, it is intentional. There is no way to reach app passwords on a personal account without enabling 2SV first. If you have already confirmed 2SV is on and the option still does not appear, skip this section and go to the platform differences table below.
- 1
1. Open your Google Account on a desktop browser
Navigate to myaccount.google.com. Confirm the email address shown in the top-right corner is the correct account. If you manage multiple Google accounts, click the avatar, sign out of all accounts, and sign back in specifically as the account you need to configure. Session confusion is one of the most common reasons people end up checking the wrong account's settings.
- 2
2. Go to Security and check 2-Step Verification status
Click Security in the left navigation panel. Scroll down to the section labelled 'How you sign in to Google.' This section lists your current sign-in methods: password, 2-Step Verification, passkeys, and so on. Look at the 2-Step Verification entry and note whether it shows as 'On' or 'Off.' If it shows 'Off,' that is the cause.
- 3
3. Enable 2-Step Verification if it is off
Click 2-Step Verification, then click 'Get started.' Google will guide you through adding a second factor. The recommended options are a Google prompt sent to a phone, or an authenticator app such as Google Authenticator or any TOTP app. SMS is also available but is the least secure option. Complete the setup and confirm the status changes to 'On.' Without completing this step, app passwords will not appear regardless of anything else you try.
- 4
4. Return to Security and re-enter the 2-Step Verification detail page
After 2SV is on, go back to the Security tab and click '2-Step Verification' again. This time, scroll all the way to the bottom of the detail page. You should now see 'App passwords' listed as a sub-option. If the option is present, click it and proceed. If it is still absent, an admin policy or account type restriction is the cause — see the table below.
- 5
5. Generate the app password for your mail client
Click 'App passwords.' Google will ask what app and device the password is for. If your specific app is not in the dropdown, choose 'Other (Custom name)' and type a label you will recognise — for example, the name of the mail client. Click 'Create.' Google displays the 16-character code once. Copy it immediately and paste it into your mail client's password field in place of your normal Google Account password.
- 6
6. Revoke the password when you retire the device or app
App passwords are persistent credentials with full Gmail access. Changing your Google Account password does not invalidate them. If a device is lost, an app is uninstalled, or an account is compromised, return to myaccount.google.com, open Security, click 2-Step Verification, find the App passwords list, and delete the relevant entry. Each unused app password left active is an open door that your main password change does not close.
Platform differences: why the option disappears by account type#
Enabling 2-Step Verification resolves the missing option for almost all personal Google Account users. But users on Workspace accounts, education accounts, or Advanced Protection face a different situation. The table below maps each account type to whether app passwords are available and who holds the key to changing it. Read the row that matches your account before doing anything else.

| Account type | App passwords available? | Who controls the fix |
|---|---|---|
| Personal Google Account — 2SV off | No — option is hidden until 2SV is enabled | You — enable 2-Step Verification in Security settings |
| Personal Google Account — 2SV on | Yes — option appears at bottom of 2-Step Verification detail page | You — generate and manage via myaccount.google.com |
| Google Workspace Business or Enterprise — admin allows | Yes — appears once user also has 2SV on | Admin must first enable it in Admin Console under Security then Authentication |
| Google Workspace Business or Enterprise — admin blocks | No — policy overrides individual 2SV status | Admin only; individual users cannot override a domain policy |
| Google Workspace Education or Government | Typically no — most admins restrict by default for compliance reasons | Admin only — students, faculty, and staff cannot self-enable |
| Advanced Protection Program enrolled | No — unavailable by design; hardware security keys replace them | Not configurable; connect via OAuth with a compatible client instead |
| Personal account with passkeys-only enforcement on some configurations | No or restricted — depends on the specific policy applied | Check Security settings; OAuth is the recommended path forward |
What to do when the option still does not appear#
Once you identify which row in the table above describes your account, the correct next step is specific to that case.
If 2-Step Verification was off, enabling it as described in the steps above is the complete fix. The App passwords option appears at the bottom of the 2-Step Verification detail page as soon as 2SV is active. No additional steps are needed.
If you are on a Google Workspace account and your admin has blocked app passwords, you cannot resolve this yourself. The setting is controlled at the domain level in the Admin Console and overrides any individual account configuration. Your Workspace administrator needs to sign in to admin.google.com, navigate to Security then Authentication, and enable the option for users in the domain. Whether they will do so depends on your organisation's security posture. Many admins block app passwords deliberately, because OAuth-based connections are more auditable: an OAuth grant can be scoped and revoked per app from Google's connected apps page, while an app password is harder to track and stays valid until explicitly removed. If your admin declines, the practical alternative is to connect your mail client via OAuth where it supports that method.
If your account is enrolled in the Advanced Protection Program, Google's position is explicit: app passwords are not available for Advanced Protection accounts, and this is not a bug to be worked around. The Programme is designed for users who face targeted phishing risks, and app passwords are a known attack vector — a 16-character credential with full account access can be phished and used from any location, while a hardware security key cannot be remotely compromised in the same way. The path forward is to use an email client that supports OAuth for Gmail. Most major clients — Thunderbird, Apple Mail, Outlook, and others — added Gmail OAuth support between 2019 and 2022.
If none of the above applies and 2SV is confirmed on, try signing out of your Google Account entirely, clearing the browser session, and signing back in before navigating to myaccount.google.com fresh. In a small number of cases, a stale session prevents updated security options from rendering. If the option still does not appear after a clean session, contact Google Account support and specify your account type alongside confirmation that 2-Step Verification is active.
Changing your Google password does not revoke app passwords
A faster way: connect Gmail without an app password#
If the app password option is blocked for you — by admin policy, by account type, or by Advanced Protection — and you need to connect a third-party email client to your Gmail, OAuth is the practical alternative. Instead of generating a password-equivalent credential and storing it in your mail client, OAuth lets the client authorize through Google's own sign-in flow. No app password is created. No 16-character code is stored. Revoking the connection later is a single click on Google's connected apps page.
We build AI Emaily, an AI-native email client and autonomous assistant. AI Emaily connects Gmail exclusively through OAuth — you click to authorize, complete Google's sign-in, and the connection is established without generating an app password. If your Workspace admin has blocked app passwords, or if your account is on Advanced Protection, that block has no effect on the OAuth path. The connection works regardless.
If you are also looking for a smarter inbox rather than just a working IMAP connection, AI Emaily triages incoming mail, drafts replies in the voice you define through your Context brain and per-client profiles, and handles routine actions in Manual, Copilot, or Autopilot mode — each with undo and a full audit log, and no training on your mail. What is included in the 7-day free trial is at aiemaily.com/pricing; the trial starts at aiemaily.com and requires no app password. If the option is blocked for you, OAuth is the path forward regardless of which client you use — AI Emaily is simply the one that also handles the inbox once the connection is in place.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.