Guide

WordPress Application Passwords: give a tool access without your password

An Application Password lets a service work with your WordPress site without ever knowing your real password, and you can take it back with one click.

By GO BEST SEOPublished

What an Application Password is

Since version 5.6, WordPress lets each user create separate passwords for apps and services. A tool uses it to connect to your site over the WordPress REST API.

  • It can’t be used to sign in to the WordPress dashboard.
  • Each one has its own name, so you can see which tool uses which password.
  • You can revoke one without touching your real password or any other tool.
  • It carries the permissions of the user who created it, so the user’s role matters.

Create an Application Password in five steps

1. Sign in as the right user

Sign in to WordPress as the user the tool should act as. The tool can do only what that user’s role allows. GO BEST SEO needs an Editor or Administrator, so approved posts can be published.

2. Open the profile

Go to Users, then Profile. An administrator can also open Users, All Users, and edit another user.

3. Name the new password

Scroll to Application Passwords, type a name that says which tool it is for, for example GO BEST SEO, and press Add New Application Password.

4. Copy it right away

WordPress shows the password once: 24 characters in groups of four. Copy it now, because it can’t be shown again. The spaces don’t matter.

5. Paste it into the tool

Paste the password together with your WordPress user name, the name you sign in with. A good tool tests the connection before it saves anything.

If you don’t see Application Passwords

  • The site isn’t on HTTPS. WordPress offers Application Passwords only on sites served over HTTPS, apart from local development sites.
  • A security plugin switched them off. Some security plugins have a setting that disables Application Passwords. Check its settings, or ask whoever manages the plugin.
  • The host blocks the login header. Some hosts strip the header that carries the password, so the connection fails even with the right password. GO BEST SEO tells you when this happens and shows a ready-made rule to send to your host.
  • Your WordPress is older than 5.6. Update WordPress first.

Application Password questions

Is an Application Password safer than my real password?

It limits the damage if it leaks: it can’t sign in to the dashboard, and you can revoke it alone. But it still has the permissions of its user, so give each tool its own password and keep it private.

What happens when I revoke it?

The tool loses access at once. In WordPress, open your profile and press Revoke next to the password’s name. If you revoke the password GO BEST SEO uses, we can no longer write to your site until you connect again from Settings.

How do I know when a password was last used?

The Application Passwords list in your profile shows when each password was last used and from which IP address. A password nobody has used for a long time is a good one to revoke.

Connect WordPress without sharing your password

GO BEST SEO works with an Application Password you can revoke at any time, and every change it makes can be undone.