Auth 2.0 Error 400 on Mail account

I try to add my account but I got this message


Authorisation Error
Error 400: invalid_request

You can't sign in to this app because it doesn't comply with Google's OAuth 2.0 policy for keeping apps secure.

You can let the app developer know that this app doesn't comply with one or more Google validation rules.
Learn more
Request Details
The content in this section has been provided by the app developer. This content has not been reviewed or verified by Google.
If you’re the app developer, make sure that these request details comply with Google policies.
redirect_uri: urn:ietf:wg:oauth:2.0:oob



What's wrong with Apple and Google? Google asks to contact the developer, yes Apple...


It's so frustrating...

Posted on Feb 22, 2023 2:58 AM

Reply
Question marked as Best reply

Posted on Mar 9, 2023 9:12 PM

I FOUND THE SOLUTION.


People have mentioned it here, but with incomplete steps. So here is how to get it done:


1.) KNOW why this is happening in the first place: it's coz Google says your old mac and old mac OS have insufficient security. With that said, you can only update an old mac for about 7-10 years. Then you're SOL. Keep that in mind. Lucky for us old mac users (I'm running a 2011 MBPro with ElCapitan) -- we are still able to add new GMAIL accounts with a workaround.


2.) As mentioned here, open your GMAIL account preferences by signing into GMAIL by web browser and clicking on your avatar in the upper-right and selecting "Manage your Google Account". Then click on the "Security" tab on the left.


3.) Under "Signing in to Google" ENABLE 2-step verification. This alone will NOT fix it, but it WILL allow you use what Google calls "Less Secure Apps Access". If you notice in your account settings, Google automatically sets this to OFF -- essentially blocking access to any apps that Google dubs 'insufficient security'. Enabling 2-step verification will bring up a third line under "Signing in to Google" that says "App Passwords".


4.) Click on "App Passwords" and this will walk you through generating a password that you can use to manually add a GMAIL account with your old mac.


5.) Select and copy the generated password, go into Apple Mail preferences and select "other" when adding the new email account. Type in your gmail email address, and use the password you copied earlier, in the password field.


If this helps, PLEASE hit the kudos button to bring it to the top!

Similar questions

217 replies

Mar 27, 2023 6:23 AM in response to The Animaster

Ive got the same problem. Weirdly its on my hubby's newer 2014 mac air, but so far [touching wood] not on my old 2011 macbook pro. He literally just lost connectivity for no apparent reason with the authentication error outlined in opening post.

Ive just tried using The Animasters work round, but to no avail, it still won't validate. To be sure I'd got it all correct, I repeated the process twice, reverting to original settings inbetween, but no joy. I was so hopeful this might do the job.

Frankly, its time Apple started recognizing that the longevity of their products means many people will have legacy issues and do more to help solve them. Instead its all about the money - "oh, something doesn't work any more, no problem, spend a small fortune and buy a new one!" It is deeply frustrating, not all Apple users are made of money.

Anyway, between Google and Apple, they seem determined to dictate what we must do, rather than what end users might want. Next new computers may not be Macs, and new email addresses on a different platform/server too.


Fed up in London.

Mar 27, 2023 7:50 AM in response to YvonnePhoto

Hi YvonnePhoto


I'm not affiliated with Apple nor with Google, but this authentication issue is a common issue in the IT industry and not at all specific to Apple hard- and software.


Please follow the instructions from jrginnyc - this is the proper approach to implement a work around. It is that Google has increased security measures and no longer allows the use of the standard Gmail password for all software no being up-to-date security wise. For instance my HP printer imposed the same issue as it is using my Gmail account to deliver me the scans per Email.


All Google is asking is, that you specify a separate - so called app password - that you only use for a dedicated purpose, in this scenario Apple Mail on our desktop or laptop. Then you configure an "Other account" (not Google) but provision your gmail address along with the application password and you are good to go. I just had to do it on my wife's PowerBook which still runs High Sierra.


Alternatively you can also consider using Mozilla Thunderbird on your Mac. You only have the issue on your Mac as Apple tries to simplify the setup process for Gmail and this is a built-in feature of macOS which is no longer supported with updates from Apple. If you still run Windows XP or Windows 7 wyou would experience similar issues.


Hope that helped providing some background to the topic. The process described above will be working 100%. Let me know if you struggle and need further support. You definitely can continue using Apple Mail on your legacy Apple hardware for Gmail.

Mar 29, 2023 1:01 AM in response to The Animaster

The workaround works, the thoughest part is finding the app password generator in Google's kitchen-sink account.


Your Mac and thus email client (Mail) is probably too old to comply with Google's security policy so you are unable to add gmail account to Mail with default procedure (using Google authorisation site where the error message appears). You need log in to your google account, enable 2-step verification if you haven't done that yet, and generate an app password (for Mail). Then in Mail you choose "Other account" (not Google) and use the generated password there instead your standard Google password.

Apr 9, 2023 6:24 AM in response to vascomark

The solution by "the Animaster" works. I have High Sierra on a 2020 Macbook. Pro. You need to follow Animaster's directions carefully. In step 4, copy the new password, but then ignore Google's on-screen instructions, and follow what it says in steps 4 and 5. However, if you do not remove the old instance in your Mac mail account list, it will say there is already an account with the same name, and it won't let you create a new one. Delete the old one. It does not get rid of all your emails. Choose "other", using the same email name as you had before, and the new password that you get in step 4. Then it works, and the old emails are still there (including those that came in while it wasn't working).

Apr 12, 2023 12:16 PM in response to vasilis113

This solution actually worked, THANK YOU!


As of 4.12.23, there are a few more steps to get to the app passwords now. AND you must go into your Gmail settings and go to "permissions" to make sure you have IMAP authorized/give permission. If you miss that second step it won't authorize. This solution remedies the need to give google your phone number (yay!).


Stick with it, guys because I am not super techy and if I can do it, I am confident that you all can do it, too! Good luck!!

Apr 22, 2023 9:27 AM in response to kap10piper

I've been at this several hours now, and have tried the various methods in this string of messages. Per the above I deleted my Gmail account in Apple Mail, and now when I try to add that account back in to Apple Mail (I've tried both the Other Mail and Google options) it tells me the account already exists even though I can't see it.


Is there a way to force my Gmail account back in to Apple Mail?


I'm running High Sierra 10.13.6. TIA

Apr 28, 2023 4:50 AM in response to jaynemiranda

This works! Once you've enabled 2 factor, then click on App passwords, dont click on 'google' check box when adding the account, click on other and in the password section, dont type your gmail password, enter the 'generated app password' and it adds it as normal.

I had this because I signed in on a windows laptop with my google account and it all went to crap on my mac.

This fixes it.

Thanks for the help!

Apr 28, 2023 6:19 AM in response to The Animaster

Do you need to delete the old account first? I had the gmail account connected and working, but something happened with google console and my account was locked out. Finally got it cleared and can use gmail through their web interface but can't connect through mail. When I tried to do so using the instructions it gave me an account already exists message. So my assumption is that I need to delete the account from mail and then re-add it. Sound correct? TIA

May 23, 2023 8:08 AM in response to tnbriggs

Can confirm that this also worked (5/7/23) on the 2009 Macbook 6,1 running High Sierra. Could only get it to work for one user, however. The option for the two factor authorization was not there for the second user on the same machine and trying to use the OAuth code number of the first user for the second user in MacMail did not work.

May 25, 2023 6:31 AM in response to ays177

I had this exact issue on High Sierra.

What worked for me was step two here:

https://technclub.com/guides/fix-oauth-2-0-error-400-apple-mail-mac/


Sign in to google on a browser (I used Safari as suggested by the above link).

Go to 'Manage Your Google Account'. Then 'Security' from the sidebar.

Under 'How you Sign In To Google' go to '2-Step Verification'.

Down the bottom of this page is 'App Passwords' where you can generate a one-time password. Do this and copy it.

Back to Mac Mail and instead of selecting Google under 'Accounts', select 'Other Mail Account'.

Then enter your gmail email address and the one-time password.


This worked for me so I hope it does for you too.


Cheers.


Auth 2.0 Error 400 on Mail account

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.