App passwords for iCloud, Yahoo and Fastmail: a practical setup guide
Know when a provider-issued app password is needed, how to keep it separate from your main password, and what revocation actually changes.
Some email accounts connect through a provider's browser sign-in screen. Others ask you to create a separate app password before a desktop client can read and send mail.
An app password is a credential issued by your email provider for a particular application or connection. It is not a password you invent inside Inbox Invaders, and it is not a temporary code sent to support. Understanding that distinction makes setup easier and helps you remove access cleanly when you stop using a client.
Use the method your provider supports
Inbox Invaders uses OAuth sign-in for Gmail and Outlook. Its iCloud, Yahoo and Fastmail connections use app passwords.
Follow the account option shown by the app and the provider's current instructions. Do not substitute your main account password where an app password is required, and do not try to work around an organisation's restrictions by weakening account security.
Before changing anything, confirm that you can open the provider's own account page. Access to that page gives you a trusted place to create, review and revoke credentials.
For iCloud, start in your Apple Account
Apple documents app-specific passwords for applications that need access to iCloud information. Generating them requires two-factor authentication on the Apple Account. Use the provider's security settings to create a credential labelled for this app, then enter it in the app's password field.
The most useful reference is Apple's app-specific password guide, rather than an old screenshot from a third-party tutorial.
Apple also explains that changing or resetting the main Apple Account password revokes its app-specific passwords. If a previously working connection stops after an account-security change, you may need a newly issued credential.
For Yahoo, check eligibility and security settings
Yahoo provides its own app-password controls for third-party mail clients that do not use Yahoo's sign-in page. Its current instructions explain where to generate and delete these credentials and note that generation eligibility can vary.
Follow Yahoo's official app-password guide. Avoid repeated guesses at the main account password if Yahoo will not issue an app password.
Yahoo's revocation behaviour differs from Apple's: its guide says app passwords remain active after a main-password change until deleted. Treat removal of a specific app's access as its own account-security task.
For Fastmail, check the plan and access level
Fastmail requires a separate app password for an external client, and access to third-party clients depends on your account plan. Check Fastmail's device setup guidance before spending time changing server settings.
Create a credential intended for mail access, with the permissions needed to send and receive email. Fastmail's mail-client troubleshooting guide explains that a password's access level can affect whether mail works.
Use a distinct label so you can recognise the connection later. A list containing several entries called “Mail” makes revocation harder than it needs to be.
Treat the credential like a key
An app password is sensitive even though it is separate from your main password. Someone who obtains it may gain the access it permits. Do not paste it into a support email, public issue, chat message or screenshot.
In signed Inbox Invaders builds, credentials are stored in macOS Keychain. Keep your Mac and user account secure, and do not assume that a credential is harmless because you entered it only once.
When copying from the provider, avoid accidentally including explanatory text. Inbox Invaders trims surrounding paste whitespace, but the value still needs to be the actual credential issued for the correct account.
Troubleshoot one question at a time
First confirm the email address. A credential generated under one account will not authorise another account with a similar name.
Then check whether the app password is still active and has the required access. Consider recent account-password changes, revoked credentials or plan changes. If needed, create a new app-specific credential and use the app's Reconnect control.
If receiving works but sending fails, the problem may be specific to sending rather than the password itself. Check the visible error and provider status before repeatedly regenerating credentials. Never turn off certificate checks to make a connection succeed.
Revocation and local deletion are separate
Revoking an app password at the provider removes future access using that credential. It does not erase messages already downloaded to your Mac.
Removing an account in Inbox Invaders deletes that account's local cache, drafts, Outbox items, managed attachments and saved credentials after confirmation. It does not close the email account or delete its server mailbox.
Before removal, save any local material you need and resolve pending sends. If you want to end access and remove local data, perform both steps: revoke at the provider and remove the account in the app. Exported files and backups need separate attention.
Keep a small access inventory
Periodically review the app credentials listed in your provider's security settings. Remove entries for devices or clients you no longer use, after confirming which active connection each entry belongs to.
A recognisable label, a unique credential and a clear removal routine make app passwords easier to manage. The important habit is to keep your provider's account controls and your Mac's local data controls distinct.