Guide
Gmail says app passwords are not available for your account.
Google reports 2-Step Verification as on and still refuses. The cause is almost always which second factor you set up rather than whether you set one up, and Google now steers new accounts straight into the version that does not qualify.
- Reading About 5 minutes
- Fix About 2 minutes
- Needs A phone or an authenticator app
The short version
Add a phone number or an authenticator app to your Google Account as a second step, then go back to app passwords. A security key or a passkey on its own does not unlock the option, even though Google reports 2-Step Verification as on.
The symptom
The message you are seeing
You have gone to create an app password, and Google has said:
The setting that you are looking for is not available for your account.
Or the App passwords entry simply is not on the security page at all, so there is nothing to click and no error to read. Both are the same situation and both have the same usual cause.
Nothing is broken and your account is fine. What Google is saying is that the app passwords page is not available for the account you are signed in as, in its current configuration, which is a much narrower statement than the wording suggests.
The cause
Why it happens
Google's requirement is short and it is the first thing to check:
To create an app password, you need 2-Step Verification on your Google Account.
Google Account Help: sign in with app passwords
The trap is that you almost certainly have 2-Step Verification. It says so on the page. What is not obvious is that not every second step counts for this purpose, and Google acknowledges one version of that on the same page:
If you've set up 2-Step Verification but can't find the option to add an app password, it might be because: Your Google Account has 2-Step Verification set up only for security keys.
Google Account Help: sign in with app passwords
What we found, which Google does not document
Testing this against a live account while building the connector, we hit the same dead end on an account whose only second step was a passkey. 2-Step Verification reported as on, and app passwords were still unavailable.
Google's page names security keys and does not mention passkeys, so treat that as our observation rather than as Google's published position. The underlying rule appears to be the same in both cases: a phishing-resistant factor on its own does not unlock a feature whose entire purpose is to bypass the second step.
Why this now catches so many people
Google steers new accounts towards passkeys, and rightly: they are better for signing in. The side effect is that the default route through account security now ends in exactly this dead end, and the page that stops you does not say which of your second steps is the problem.
Walkthrough
The fix, in four steps
About two minutes. You are adding a second factor rather than replacing one, so nothing you already rely on stops working.
-
Open 2-Step Verification in your Google Account
Google Account, then Security, then 2-Step Verification. Expect it to tell you it is already on. That is the point: it is on, and it is on in a form that does not qualify.
-
Add a phone or an authenticator app
Add a phone number for verification codes, or set up an authenticator app. Either qualifies. This is the whole fix and everything else is confirming it worked.
Keep your passkey
You are adding a method, not swapping one. Your passkey or security key stays, Google keeps using the strongest method for ordinary sign-ins, and your account does not get weaker.
-
Go back to App passwords
Return to the app passwords page. The option is there now. It usually appears straight away and occasionally takes a few minutes, so if it is not there immediately, reload once before assuming something else is wrong.
-
Create it and paste it before you close the page
Create an app password, and copy the sixteen characters straight into wherever you are connecting the mailbox.
Google shows it once
There is no way to see it again afterwards. If you lose it, delete that one and create another; there is no limit and no cost to doing so.
Once the app password exists, connecting the mailbox is a paste and a sign-in, on the free tier with no card.
Other causes
Three other reasons it can be missing
If adding a phone did not do it, one of these three is the reason.
It is a work or school account
On a Google Workspace account an administrator can turn app passwords off for everybody, and many do. You will not be able to change that yourself and no amount of second factors will help. Ask whoever administers the domain; it is one setting at their end.
The account is on the Advanced Protection Programme
Advanced Protection deliberately removes app passwords, because bypassing the second step is exactly what it exists to prevent. That is the programme working as designed and it is not something to work around: if an account needs Advanced Protection, it should not have an app password on it.
You are signed in as the wrong account
More common than it sounds if you hold several Google accounts in one browser. The security page follows whichever account is currently active, and the wording of the message gives no clue that you are looking at a different one. Check the avatar before anything else.
Provider change
While you are here: do not hunt for the IMAP setting
Nearly every guide about connecting Gmail to something still tells you to turn IMAP on in Gmail settings first. Google removed that option in January 2025. IMAP is always on now, and there is no toggle to find.
It is worth saying because the search you have just done will return those guides, and a person who cannot find the app password setting AND cannot find the IMAP setting reasonably concludes their account is broken. Neither is missing. One is not unlocked and the other no longer exists.
Paste the app password in and ask for your five most recent messages. If they are the ones you expect, it is connected.
Limits
When none of this will work
-
Your administrator
A Workspace account whose administrator has disabled app passwords. That is their setting and only they can change it.
-
Advanced Protection
An account on the Advanced Protection Programme. App passwords are removed on purpose and should stay removed.
-
A Microsoft 365 mailbox
A Microsoft 365 mailbox. App passwords are a Google concept; Microsoft disabled password access to IMAP in 2022 entirely. Use the Microsoft path.
-
Your Google password
Anything to do with your Google password itself. Nothing here changes or recovers it, and no legitimate service ever asks for it.
Why can I not create an app password?
Almost always because of WHICH second factor you have, not whether you have one. Google requires 2-Step Verification to create an app password, and an account whose only second step is a security key or a passkey does not unlock the option even though the page reports 2-Step Verification as on. Adding a phone or an authenticator app fixes it in about two minutes.
What does "the setting that you are looking for is not available for your account" mean?
It is Google telling you the app passwords page is not available for the account you are signed in as. It is not a fault and nothing is broken. The usual cause is the second-factor one above; the other three causes are a work or school account whose administrator has turned it off, an account enrolled in the Advanced Protection Programme, and being signed in to the wrong account.
Do passkeys count as 2-Step Verification?
Not on their own, in our testing. An account with a passkey set up and nothing else showed 2-Step Verification as on and still would not offer app passwords. Google's own help page documents the equivalent case for security keys and does not mention passkeys, so treat this one as our observation rather than as Google's published position.
Is turning on a phone code less secure than my passkey?
For signing in, a passkey is stronger and you should keep it. Adding a phone or an authenticator app does not remove it: you end up with both, and Google will keep using the strongest method available for ordinary sign-ins. What the extra method unlocks is the app passwords page.
Why does Google make app passwords conditional at all?
An app password bypasses your second step by design, which is the whole point of it and also its weakness. Requiring a qualifying second factor first means the account is at least protected everywhere else. It is a defensible position even when it is an inconvenient one.
Can I avoid app passwords entirely?
On Gmail, no: an app password is how a mail client connects. On Microsoft 365 the question does not arise, because password access to IMAP was disabled in 2022 and connecting is one Microsoft sign-in instead.
Attribution
Sources
- Google Account Help: sign in with app passwords Both quotations above, including Google's own acknowledgement of the security-key case. Read 2026-08-26.
- Google Account Help: turn on 2-Step Verification How to add a phone or an authenticator app as a second step, which is the fix.
- Google Advanced Protection Programme Why app passwords are removed on enrolled accounts.
- Connect Gmail The full set-up once the app password exists, including the January 2025 IMAP change.
Keep going
Read next
Once it exists, this takes two minutes.
Paste the app password into the control panel and ask your assistant for your five most recent messages. Free tier, 5 calls a day, no card.