Opens in a new tab
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background
[wpps_ai_summarize]
On This Page
Last updated: 01/09/2026

Disable Application Passwords

Disables WordPress application passwords site-wide: blocks REST/XML-RPC login with app tokens and hides the profile UI. Normal account passwords and logged-in REST access are unaffected. Existing tokens remain stored but cannot authenticate until this module is off. May break mobile apps, headless sites, and automation that rely on application passwords.

Overview

Disable WordPress Application Passwords when your website does not use external applications or integrations that authenticate through them.

Disable Application Passwords uses WordPress’s own application-password availability control to switch the feature off site-wide. The Application Passwords interface disappears from user profiles, new application passwords cannot be created, and existing application-password tokens can no longer authenticate through REST API or XML-RPC while the module is active.

Normal WordPress username/password login and authenticated browser sessions continue working as usual.

Disable Application Passwords is a Free security module in WP PowerSuite.

Solid black square
Solid black square
Who is this for?
  • WordPress sites that do not use Application Passwords for external integrations
  • Agencies hardening client websites by disabling unused authentication methods
  • Business websites that only require normal dashboard authentication
  • Security-conscious administrators reducing unnecessary API authentication options
  • Sites that do not use mobile apps, headless clients, or automation through Application Passwords

Features

Disable Application Passwords Site-Wide
Turn off WordPress Application Password authentication across the entire website with a single module.
Disable Existing Tokens Without Deleting Them
Previously generated application passwords remain stored but cannot authenticate until Application Passwords are enabled again.
Built-In 2FA Conflict Protection
WP PowerSuite prevents configurations where 2-Factor Authentication requires Application Passwords for API access while this module simultaneously disables them.
No Configuration Required
There are no additional settings. Enable the module to disable Application Passwords and disable it when you need the functionality again.

What Are WordPress Application Passwords?

Reduce Unused WordPress Authentication Surfaces

Disable Authentication Without Destroying Existing Tokens

Works Safely With Two-Factor Authentication

Use Cases

  • Business Websites Without API Integrations
    Disable Application Passwords when users manage the site through the normal WordPress dashboard and no external application requires token-based authentication.
  • Agency Security Baselines
    Agencies can disable an unused authentication method on client websites where Application Password integrations are not part of the approved stack.
  • Reduce Unnecessary Authentication Options
    Prevent users from creating Application Passwords when the website has no legitimate use for them.
  • Harden REST/XML-RPC Authentication
    Prevent Application Password credentials from authenticating through REST or XML-RPC while controlling the actual APIs separately through Disable REST API or Disable XML-RPC when required.

Frequently Asked Questions

Related Modules

Tell modern browsers to enforce sensible safety rules—like blocking sneaky scripts and iframe tricks—with strong defaults you can tighten further for HSTS...
Disabled
Turn off public "forgot password" self-service for everyone. Use only when you reset passwords another way (manual admin password, WP-CLI, or admin-sent...
Disabled
Always open your dashboard and login screen over a secure https:// link. Anyone using the old http:// address is sent to the...
Disabled
Allow or block visitors by IP address—ideal for office-only dashboards or shutting out known troublemakers. Rules apply site-wide, including wp-admin and login.
Disabled
Automatically protects visible email addresses and mailto links from basic spam bots by safely encoding them while keeping them clickable for visitors.
Disabled
Bot protection with Cloudflare Turnstile on logins, forms, comments, and WooCommerce—low hassle for real people.
Disabled
Keep a clear record of important dashboard activity—who logged in, what changed, and when—so you can investigate issues or stay audit-ready without...
Disabled
Remove the dashboard screens that let anyone edit theme or plugin code from the browser—one less disaster if an account is compromised.
Disabled
Put your whole site behind one shared password—ideal for staging, client previews, or a soft launch before you go public.
Disabled
Blocks risky default usernames during registration so bots have fewer easy targets.
Disabled