Guides/Manage your account/Account security/Application Passwords

Application Passwords

With Two-Step Authentication active on your WordPress.com account, you can generate a custom password for specific third-party applications you wish to authorize. This guide will show you how to generate a new password for third-party apps accessing your account.

About Application Passwords

There may be some apps that connect to your WordPress.com account that don’t yet fully support two-step authentication. The most common are Jabber apps used to subscribe to WordPress.com blogs.

You can generate unique passwords for these apps (e.g., you can have a different password on your phone and tablet). You can then disable individual passwords and lock applications out of your account to prevent others from accessing your sites.

Add a New Application Password

With Two-Step Authentication active, you can generate a custom password for each third-party application you authorize to use your WordPress.com account. You can revoke access for an individual application if you ever need to.

You can use the following steps to create an application password:

  1. Click on your profile at https://wordpress.com/me.
  2. On the side, select the Security menu option.
  3. Select “Two-Step Authentication,” which must be enabled.
  4. Scroll down to the “Application passwords” section.
  5. Click the “Add new application password” button.
  6. Give the application a name—you’re the only one who will see this name, so call it whatever you’d like—and click the “Generate Password” button.
Application password prompt
  1. WordPress.com will create a unique 16-character password that you can copy and paste the next time you log in to your account on that device. The application will remember this password so you don’t need to.

Site Specific Application Passwords

This section of the guide applies to sites with the WordPress.com Business and Commerce plan, and the legacy Pro plan. If you have a Business plan, make sure to activate it. For sites on the Free, Personal, and Premium plans, upgrade your plan to access this feature.

If your site has a plugin-enabled plan and you have activated the site’s hosting features, you will use the following steps to create a new application password for a specific site on your account:

  1. In your site’s dashboard, navigate to Users → Profile.
  2. Scroll down to the “Application Passwords” section:
The Application Passwords section with a field to enter the New Application Password Name.
  1. Type a descriptive name for the new application you’ll be connecting. Use something that you’ll remember.
  2. Click the “Add New Application Password” button to generate a new password. Take note of the password; it will not be displayed on the screen in the future:
the Application Password screen displaying the automatically generated password.
Application password provided

Revoke an Application

The “Application passwords” section of your Two-Step Authentication page will maintain a list of all the applications for which you’ve generated passwords. You can revoke access for a specific application for any reason, including if any of your devices are lost or stolen.

  1. Click on your profile at https://wordpress.com/me.
  2. On the side, select the Security menu option.
  3. Select “Two-Step Authentication,” which must be enabled.
  4. Scroll down to the “Application passwords” section.
  5. Click the X next to the application you want to revoke access for.
  6. The application will no longer have access to your account.
An arrow pointing to the X next to an active password.
Click the X to revoke an application’s access.

You can revoke access for an individual application if you ever need to. Follow these steps to revoke an Application:

Revoke Site Specific Applications

This section of the guide applies to sites with the WordPress.com Business and Commerce plan, and the legacy Pro plan. If you have a Business plan, make sure to activate it. For sites on the Free, Personal, and Premium plans, upgrade your plan to access this feature.

  1. In your site’s dashboard, navigate to Users → Profile.
  2. Scroll down to the “Application Passwords” section.
  3. Click the “Revoke” button next to the application you want to remove access for or click “Revoke all application passwords” to remove access to all applications:
A list of applications with buttons to Revoke access.

Was this guide helpful for you?

Not quite what you're looking for? Get Help!

Copied to clipboard!