App passwords

You can control whether third-party apps can access your account using app passwords. For example, a password that you create for your mail client doesn't allow access to Yandex.Disk using the WebDAV protocol. No app password grants access to your account.

When two-factor authentication is enabled, app passwords are required and can't be disabled.

Attention. Official Yandex apps and software require a regular Yandex ID password if two-factor authentication isn't enabled, and a one-time password if 2FA is enabled.

You will need to create a separate password for each third-party application or program that requires you to enter your Yandex password. These include:

  • Email clients (Mozilla Thunderbird, Microsoft Outlook, The Bat!, and more);
  • WebDAV client for Yandex Disk
  • CardDAV client for syncing Yandex Mail contacts with a mobile device
  • CalDAV client for Yandex Calendar
  • mail importers for other mail services (Mail.ru, Gmail, Outlook.com and others)

To create an app password:

  1. Open the Security tab.
  2. In the Access to your data section, select App passwords.
  3. Click Enable app passwords → Create a new password.

    If two-factor authentication is enabled, click Create a new password.

  4. Select the type of application.
  5. Come up with a name for the password. For example, you can use the name of the application that you are creating a password for. The password will be shown with this name in the list.
  6. Click Create. The app password will appear in a pop-up window.
Restriction. You can only see the generated password once. If you entered the password incorrectly and then closed the window, delete the current password and generate a new one.

Resetting application passwords

All application passwords that you created get reset in the following cases:

  • You change a password (with two-factor authentication disabled)
  • You enable or disable two-factor authentication
  • You restored access to your account by yourself or with the help of our support staff
  • You followed the Log out on all devices link on the Account management page.

Every app password you use must be re-generated following any of these events.