Creating app password doesn't work

Hello everyone,

When I try to generate a new app password via Personal Settings → Security → Create App Password, a pop-up window appears asking for a password to authentificate myself for this action. After entering my password, the dialog box closes without creating any app password. In the former version of nextcloud (33.x.x), no password at all was accepted and opened an error notice.

Is this issue already known?

  • Nextcloud Server version: 34.0.0

  • Web server and version: Webspace (IONOS)

  • Reverse proxy and version _(e.g. nginx 1.27.2): none

  • PHP version (e.g, 8.3): 8.4

  • Is this the first time you’ve seen this error? (Yes / No): Yes

  • When did this problem seem to first start? It’s the first time I tried…

  • Installation method: setup-nextcloud.php on Webspace

  • Are you using Cloudflare, mod_security, or similar? No

Hello,
There have been similar topics in the forum in the past. If I remember correctly, there is no bug.
Have you searched before posting?

Hello,
of course I searched before posting.
The behaviour changed between 33.x.x and 34.0.0, but it is still not possible to create new app passwords to connect other devices. And 34.0.0 is still young, so I don’t expect lots of information in the forum. Asking a colleague, her friend gets the same results at his installation… (34.0.0 but other environement).
In my case, setting up new online accounts in (new) KDE environements are not possible. Trying to connect via normal login page ends in showing a blanc site (only the background of the website is visible) - switching to >login with app password< shows a login dialog.

Please monitor the output in your browser inspector under both the Console and Network tabs while reproducing your problem - as described in the support template.

Also configuration and apps would be helpful, also as requested in the support template.

config.php:

<?php
/*
 * WARNING
 *
 * This file gets modified by automatic processes and all lines that are not
 * active code (ie. comments) are lost during that process.
 *
 * If you want to document things with comments or use constants add your settings
 * in a '<NAME>.config.php' file which will be included and rendered into this file.
 *
 * Example:
 *   <?php
 *   $CONFIG = [];
 *
 * See also: https://docs.nextcloud.com/server/latest/admin_manual/configuration_server/config_sample_php_parameters.html#multiple-merged-configuration-files
 */
$CONFIG = array (
  'instanceid' => 'SECRET',
  'passwordsalt' => 'SECRET',
  'secret' => 'SECRET',
  'trusted_domains' => 
  array (
    0 => 'cloud......de',
  ),
  'datadirectory' => '/homepages/14/SECRET/htdocs/NC/data',
  'skeletondirectory' => '',
  'default_language' => 'de',
  'dbtype' => 'mysql',
  'version' => '34.0.0.12',
  'overwrite.cli.url' => 'https://cloud.......de',
  'dbname' => 'SECRET',
  'dbhost' => 'SECRET',
  'dbtableprefix' => 'oc_',
  'mysql.utf8mb4' => true,
  'dbuser' => 'SECRET',
  'dbpassword' => 'SECRET',
  'installed' => true,
  'config_preset' => 3,
  'mail_from_address' => 'cloud',
  'mail_smtpmode' => 'smtp',
  'mail_sendmailmode' => 'smtp',
  'mail_domain' => '...........de',
  'mail_smtphost' => 'smtp.....de',
  'mail_smtpport' => '587',
  'mail_smtpauth' => true,
  'mail_smtpname' => 'SECRET',
  'mail_smtppassword' => 'SECRET',
  'maintenance' => false,
  'app_install_overwrite' => 
  array (
  ),
  'theme' => '',
  'loglevel' => 0,
);

Nextcloud log during time of problem:

Fehlersuche
user_status-menucss

Only lowercase alphanumeric characters are allowed in appIds; check paths of installed app [1 characters replaced]
29.06.2026, 08:34:18

Information
no app in context

The app config key dav/hide_absence_settings is not defined in the config lexicon
29.06.2026, 08:34:18

Fehlersuche
settings

NotConfirmedExceptionRequired authorization header missing
29.06.2026, 08:34:12

Firefox inspector network tab:

Status
403
VersionHTTP/2
Übertragen798 B (51 B Größe)
Referrer Policyno-referrer
Anfrage-PrioritätHighest
DNS-AuflösungSystem

cache-control
no-cache, no-store, must-revalidate
content-security-policy
default-src ‘none’;base-uri ‘none’;manifest-src ‘self’;frame-ancestors ‘none’
content-type
application/json; charset=utf-8
date
Mon, 29 Jun 2026 06:30:29 GMT
feature-policy
autoplay ‘none’;camera ‘none’;fullscreen ‘none’;geolocation ‘none’;microphone ‘none’;payment ‘none’
referrer-policy
no-referrer
server
Apache
x-content-type-options
nosniff
X-Firefox-Spdy
h2
x-frame-options
SAMEORIGIN
x-nc-auth-notconfirmed
true
x-permitted-cross-domain-policies
none
x-request-id
akIRBWEnvq-wyOHORE_tXwACAGQ
x-robots-tag
noindex, nofollow
x-user-id
marc
x-ws-origin
available
x-ws-ratelimit-limit
1000
x-ws-ratelimit-remaining
998

Accept
application/json, text/plain, /
Accept-Encoding
gzip, deflate, br, zstd
Accept-Language
de,en-US;q=0.7,en;q=0.3
Authorization
Basic bWFyYuoyVcUpaznHgWeUdmlgQnR6SWU=
Cache-Control
no-cache
Connection
keep-alive
Content-Length
30
Content-Type
application/json
Cookie
__Host-nc_sameSiteCookielax=true; __Host-nc_sameSiteCookiestrict=true; nc_sameSiteCookielax=true; nc_sameSiteCookiestrict=true; nc_username=mchc; nc_token=NDchangedVZAGd083rCQRNlNJswph; nc_session_id=6a33r99fmchangedff88e4c2f87105ff247756b; oc_sessionPassphrase=a%2BGkq01jsxYcTO2VPnFHn8THurvyIvlnWns05pjo2V8fiRf0dAhHyeiULZa%2Fr2ocBPKrd7whobothersg%2BmT%2FDCRHqNz3J%2FEo; ocb4w05xqaz1=4b6346666357888b4762a352a700; oc08esdp1dis=50179f55fgh66643369a4b8a7c7e0f; oc02pv043elg=6acafd108825545z672f87105ff888247756b
DNT
1
Host
cloud…de
Origin
https://cloud…de
Pragma
no-cache
Priority
u=0
requesttoken
8ZMTplvFW30aGHF6Auyb1Guuz+NcRK0V0gZOA=;-)p9EhkTguKYE0TZhCsYellow4IG7fRCkRREF5g=
Sec-Fetch-Dest
empty
Sec-Fetch-Mode
cors
Sec-Fetch-Site
same-origin
Sec-GPC
1
TE
trailers
User-Agent
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.0
X-Requested-With
XMLHttpRequest, XMLHttpRequest

Firefox Inspector console output:

[DEBUG] settings: Creating a new app token
Object { app: “settings”, uid: “xxxx”, level: 0 }
index.mjs:38:1
[DEBUG] @nextcloud/password-confirmation: Adding auth info to the request
Object { app: “@nextcloud/password-confirmation”, level: 0, config: {…} }
index.mjs:38:1
XHRPOST
https://cloud…de/index.php/settings/personal/authtokens
[HTTP/2 403  208ms]

[DEBUG] @nextcloud/password-confirmation: Password confirmation failed
Object { app: “@nextcloud/password-confirmation”, level: 0, error: AxiosError }
index.mjs:38:1
[DEBUG] @nextcloud/password-confirmation: Handle modern confirmation error based on header
Object { app: “@nextcloud/password-confirmation”, level: 0, hasConfirmationHeader: false }
index.mjs:38:1
[DEBUG] @nextcloud/password-confirmation: Handle modern confirmation error based on header
Object { app: “@nextcloud/password-confirmation”, level: 0, hasConfirmationHeader: false }
index.mjs:38:1

I hope this is helpful…

Are you sure your web server is set-up per Nextcloud’s requirements?

This suggests the Authorization header isn’t getting through.

I found this hint on google last week, too…
The proposed solution was to check the .htaccess - some entries have to be present there:

<IfModule mod_headers.c>
    <IfModule mod_setenvif.c>
        <IfModule mod_fcgid.c>
            SetEnvIfNoCase ^Authorization$ "(.+)" XAUTHORIZATION=$1
            RequestHeader set XAuthorization %{XAUTHORIZATION}e env=XAUTHORIZATION
        </IfModule>
        <IfModule mod_proxy_fcgi.c>
            SetEnvIfNoCase Authorization "(.+)" HTTP_AUTHORIZATION=$1
        </IfModule>
        <IfModule mod_lsapi.c>
            SetEnvIfNoCase ^Authorization$ "(.+)" XAUTHORIZATION=$1
            RequestHeader set XAuthorization %{XAUTHORIZATION}e env=XAUTHORIZATION
        </IfModule>
    </IfModule>

Yes - this entries are present in my .htaccess file.

The problem with creating app passwords was not present on the first installation last autum. It started after an update to 33.x.x, where all passwords were rejected as “wrong”. The next update to 34.0.0 changed the behavior.
AI found a possible workaround - revoke all tokens from all connected devices an restart with a new browser tab to log in again. I’ll try this tomorrow, when I can log out from my office PC.
Next step is updating to 34.0.1.
I’ll keep you updated

Unfortunately nothing worked…

  • I tried to revoke all tokens, but only received error messages.
  • I logged out from all connected devices
  • I deleted the tokens manualy in the database
  • I updated to 34.0.1

I found the warning, that Strict-Transport-Security`-HTTP-Header is not set and added >>Header always set Strict-Transport-Security “max-age=15552000; includeSubDomains”<< in top of the section in my .htaccess file.
The warning is still there. :roll_eyes:

The update to 34.0.1 changed the layout on the page to set a new app password, but not the behavior…

It seems to be an issue with the HTTTP header - I found a warning on the administration overview page.

Editing the .htaccess file on IONOS webspace didn’t help - after inserting

<IfModule mod_headers.c>
    # 1. Force HTTPS redirect (required for HSTS to work)
    RewriteEngine On
    RewriteCond %{HTTPS} !=on
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

    # 2. Enable HSTS header for 1 year (includes subdomains and preload list)
    Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
</IfModule>

the warning remains…

I thougt I found a workaround in the internet and did a password reset now - in my case it didn’t work. Well, the password is changed, but I still can’t create app passwords.
I wonder, why

NotConfirmedExceptionRequired authorization header missing

only comes up by creating new app passwords… To revoke a token, the confirmation with my password worked fine - the device was marked to be deleted.
So I doubt, that ist really a problem with .htaccess.

I’m having the same issue on 34.0.1. Adding a new device brings up the password dialog, but after entering the password, there is no response (no app token is generated and no error message shown). Also, removing older tokens fails with the error message “Could not delete the app token”, with no further reasons why.

Same here. Entering password, nothing happens. Firefox inspector console output says “403 Forbidden”.

The only working alternative is to create an app password via occ command. This works fine for me.

Can you check the request if it does contain the authorization header ?

Firefox-inspector → console → respose → JSOIN says: "message “Required authorization header missing”

Please also check the request, not response, is the header there?

In the request-tab is only JSON {“name”:“test”,“oneTime”:true}

That is the content, that looks correct, you should be able to see the sent headers, like this:

Yes, is present: