Your password
never leaves your provider.
BlueMail uses OAuth 2.0: the modern, secure authorization standard supported by Gmail, Outlook, Office 365, Yahoo and every major provider.
How OAuth works in BlueMail
When you add an account, BlueMail redirects you to your provider's own sign-in page. You enter your credentials directly with them, and only with them. Your provider then issues BlueMail a token that grants access to your email, calendar and contacts.
This means your password never touches BlueMail. Not transmitted, not stored, not seen. And because access is tokenized, you can revoke it at any time from your provider's security settings.
Why OAuth matters
- No password sharing. Your credentials stay between you and your email provider.
- Revocable access. Turn off BlueMail's access from your provider with a single click.
- Two-factor friendly. Works seamlessly with provider 2FA, including hardware keys.
- Scoped permissions. BlueMail only requests the access it needs: nothing more.