App passwords connect a Cedros-hosted mailbox to a mail app such as Apple Mail, Outlook, or Thunderbird. Create one for each independently configured device or connection so you can replace or revoke it without disrupting the others.
An app password is separate from your Cedros sign-in password. Use the full mailbox address and its app password for both incoming and outgoing mail. These credentials do not apply to a mailbox hosted by Google Workspace; use Google's account setup for that mailbox. See Choosing Cedros email or Google Workspace if you are unsure which service hosts your mail.
Choose the right action
| What you need to do | Action to use |
|---|---|
| Connect a new device or mail app | Create app password; existing passwords stay valid |
| Replace one working connection's password | Create a new password, update and test that connection, then revoke its old password |
| Stop a lost, retired, or untrusted connection from signing in | Revoke its individual password |
| Invalidate every existing app password for the mailbox | Replace all…; this revokes the old passwords and issues one new password |
If a password may have been exposed, revoke it promptly rather than leaving it usable while you prepare a routine replacement. If you cannot identify which password was exposed, coordinate with the mailbox administrator before replacing all of them.
These actions affect the selected mailbox's mail-app credentials. They do not delete its messages, close the mailbox, or change your Cedros sign-in password.
Anyone with a working mailbox app password can use it to access that mailbox through a compatible mail app. The device label helps you identify the credential; it does not lock the password to that physical device. Avoid sharing one password between unrelated connections.
Open the mailbox's app passwords
- In Cedros, open Email → Inbox → Settings. Under Your mail → Your addresses, find the mailbox.
- Open its actions and select App passwords…. You can also select Connect mail app, then Open app passwords.
- Check the address in App passwords for [address] before making changes. Administrators can also open the same controls through Team → Mail addresses → App passwords….
If you are asked to contact the administrator, ask them to manage the credential for this address. Being able to read a personal or shared inbox does not automatically include permission to issue or revoke its app passwords. A receiving alias has no separate credential; open the mailbox that receives its mail. See Creating personal and shared email addresses.
Existing entries show their label, status, a short identifier, and an expiration time or no expiry. The short identifier distinguishes entries; it is not the password and cannot be used to sign in. The list does not reveal previously issued passwords.
Check the expiration time as well as the status. A password whose expiration has passed cannot authenticate, even if its row still displays active.
Create and save a new password
- In What is this password for?, enter a short, specific label such as “Outlook on work laptop” or “Mail on office iPad.” When replacing a connection, include a date or other distinction so you can recognize the old entry later.
- Leave Expires (optional) empty for no scheduled expiration, or choose a future date and time. Plan to update the connection before that time if it must keep working.
- Select Create app password. Wait for Your app password is ready. Save it before closing.
- Use Copy password to save the One-time app password securely. If an administrator is handing it over, use your organization's approved secure method and identify the mailbox and device it belongs to.
- After saving the password, select I’ve saved this password. Use the accompanying server settings to configure the mail app.
One-time means Cedros shows the password once. It is not a one-use verification code: the mail app can keep using it until it expires or is revoked. I’ve saved this password acknowledges that you saved it; the button does not store another recoverable copy for you.
If you try to leave before acknowledging it, Cedros offers Back to password or Close anyway. Closing does not revoke the password. If you close without saving it, create another password and revoke the unused entry. Cedros cannot display the old password again.
You may be able to issue a password while the mailbox is provisioning, but the mailbox must be Active before the mail app can connect. Finish provisioning before treating a rejected connection as a password problem.
Use Connect mail app to retrieve the current hostname and ports. Copy settings copies connection details, not the app password. Follow the relevant setup guide for Apple Mail on Mac, iPhone or iPad, Outlook, or another mail app.
Replace one connection's password
For a planned change where the old password is still trusted:
- Open the correct mailbox's app passwords and select Create app password with a distinct label. Save the new password. Leave the old entry active during this planned handover.
- Update the mail app's incoming password and its separate outgoing SMTP password. Keep the full mailbox address as the username in both sections.
- Reconnect the app so it uses the new credential. Send a fresh message to an outside account you control, confirm delivery there, and reply back to the Cedros mailbox.
- Confirm that the reply appears in the mail app and Email → Inbox in Cedros. Check that the app is sending from the intended mailbox address.
- Close and reopen App passwords… to return to the list. Find the old entry by its label and identifier, then select its Revoke action. Leave the new entry active.
If the app uses a cloud connection shared by several devices, check the clients that use that connection before revoking the old credential. A label naming one device does not guarantee that only that device uses the password.
Do not use Replace all… for this routine change. It would invalidate the credentials used by other mail apps for the same mailbox.
Revoke a lost, retired, or exposed password
- Open App passwords… for the affected mailbox. Check the address at the top and identify the entry by its label and short identifier.
- Confirm which connection uses it. If several devices share that password, all of them will need a different credential.
- Select Revoke on that entry. This action applies to the selected credential; check the target before selecting it.
- Confirm the success message and check that the refreshed list shows revoked. If the list cannot refresh, use Retry app passwords to retrieve its current state.
A revoked password cannot be restored. Create a new one if the connection should be allowed again. Other app passwords for this mailbox remain usable unless they have expired or been revoked separately.
Revocation prevents new authentication with that password. It is not a remote wipe or a guarantee that every already-open mail connection closes immediately. Messages already downloaded or copied to another service remain there. If a lost or compromised device needs immediate containment, tell the administrator as well as revoking its credential.
Do not use a mail app continuing to display cached messages as evidence that revocation failed. Check the credential's state in Cedros and whether a fresh connection can authenticate.
Replace every app password for a mailbox
Use this when you intend to invalidate all existing app passwords for the selected address. It disrupts every connection using those credentials, including apps that still work normally. Arrange access to the affected devices and coordinate with other people using a shared mailbox.
- Open App passwords… and confirm the mailbox address.
- Enter a label for the new password and, if needed, a future expiration time.
- Select Replace all…. Read the warning that every existing app password for this address will stop working. Choose Cancel replacement if you meant to change only one connection.
- To proceed, select Yes, revoke all and issue one. This issues one new password while revoking the previous active entries; it does not generate a separate replacement for each device.
- Save the new One-time app password securely and select I’ve saved this password. Use it for its intended connection. Create separately labeled passwords for the other connections you want to restore.
- Update both incoming and outgoing credentials on each restored connection, then repeat the send-and-reply test. Reopen the list and confirm that old entries are revoked and the intended new entries are present.
If you lose the new password before saving it, the previous passwords are still revoked. Create another password, save it, and revoke the unused replacement entry. Repeating Replace all… would also revoke any new credentials you have issued since the first replacement.
Check that the change worked
For creation or replacement, verify a fresh connection and actual delivery:
- The mail app uses the full mailbox address and the new app password for both incoming and outgoing mail.
- The connection uses the hostname shown in Cedros: IMAP 993 with SSL/TLS, and SMTP 587 with STARTTLS or 465 with SSL/TLS.
- A newly sent message reaches an outside account, and its reply reaches the Cedros mailbox and the mail app.
- The app-password list contains the expected entries, and obsolete credentials show revoked.
A saved account, an existing inbox view, or a message in Sent is not enough to establish that the new password and both mail directions work. If receiving succeeds but sending fails, check the separate SMTP credential and follow Why can I receive email but not send it?.
For revocation, use the refreshed credential state as your first check. Do not send a revoked password in a support request to prove that it was disabled.
Resolve common problems
The password is no longer visible. Cedros cannot reveal it again after the issuance dialog closes. Create and save a new password, update the relevant connection, and revoke the old or unused entry.
The label or expiration is rejected. Use a shorter nonempty label and a valid future date/time, or leave expiration empty. A past expiration time is not accepted. To replace a credential with the wrong label or expiration, issue a new one and retire the incorrect entry.
The credential says active, but the app cannot sign in. Check its expiration time, the mailbox's Active status, the full username, and the server settings. Make sure you copied the actual password rather than the short identifier. A correct password does not bypass an inactive mailbox or an incorrect connection setup.
The list failed to load or refresh. Select Retry app passwords before making another change. If a newly issued password is still displayed, save it first. A refresh failure does not necessarily mean creation or revocation failed. Check the list before retrying a consequential action, especially Replace all….
The app still asks for the old password. Update the app's saved credential and its separate SMTP settings, then reconnect. Check for another account, device, or shared cloud connection still using the old credential.
A revoke or replacement request returned an error. Read the error, reload the credential list, and check the actual state before repeating the action. If you cannot establish which entries are active, ask the administrator for help rather than repeatedly replacing all passwords.
For support, include the mailbox address, credential label or short identifier, action attempted, approximate time, exact error, and whether a success message appeared. Never include the password or private message contents. See Getting help and reporting a problem.