Third-party apps providing mail, contacts, and calendar services will need app-specific passwords for iCloud access beginning June 15
Tim Hardwick / MacRumors :
Context & Ripple Effects
This requirement lands mid-arc in a decade-long tightening of how credentials reach Apple's services. It predates the identity tools that came after it — the Sign In with Apple launch in 2019, the account-deletion mandate for apps with third-party logins, and the eventual Passwords app built on iCloud Keychain. What changes now is narrower but structural in kind: iCloud stops accepting plain Apple ID logins from outside apps.
For users of third-party mail, contacts, and calendar clients, the practical effect is per-app credential generation instead of a shared password; for those developers, supporting app-specific passwords becomes table stakes for staying functional against iCloud accounts.
First-order effects
- Developers of third-party mail, contacts, and calendar apps must add app-specific password support by June 15 or their iCloud-connected features break for every user who updates their login flow.
- Users must generate and manage a separate credential per app, trading convenience for a credential that can be revoked independently of the master Apple ID.
Second-order effects
- Native Mail, Calendar, and Contacts gain a friction advantage over third-party rivals, since only the latter need the extra credential step — a quiet tilt of the client market toward Apple's own apps.
- Google's Advanced Protection work securing its services inside Apple's native apps shows competitors meeting Apple's credential bar rather than fighting it, normalizing hardware-backed and scoped authentication across both ecosystems.
Third-order effects
- If the pattern holds, credential policy becomes an enforcement layer: each subsequent step — Sign In with Apple, mandatory account deletion, a first-party Passwords app — extends Apple's control from how apps authenticate to what they must offer users to keep access at all.
- Third-party clients increasingly compete on Apple's terms inside the access layer, shifting the durable question from 'can we connect?' to 'what does Apple require next to stay connected?'
The trend: Apple is converting credential management into a platform-control surface, moving from shared passwords to scoped, revocable, ultimately first-party-managed identity.