← Nevermore

App passwords

The one thing to do before Nevermore can read your mailbox.

Nevermore signs in to your mailbox over IMAP with an app-specific password rather than OAuth: a separate password that works for one app, that you can revoke on its own, and that involves no consent screen and no third party. The cost is that you have to go and create one first, and every provider files it somewhere different under a different name. Here is where.

Why not "Sign in with Google"?

OAuth would mean registering a cloud project, shipping a client secret inside a downloadable app, and asking you to grant a scope on a consent screen — and it would only ever work for the providers we had registered with. An app-specific password is narrower, revocable on its own, and works the same way with anything that speaks IMAP. The FAQ goes into it further.

Where the password goes

Into the macOS Keychain, stored so it can't ride a backup or Migration Assistant transfer to another machine. It is never written to disk in the clear and never logged, and revoking it at your provider cuts Nevermore off without changing anything else about your account.