App password are for any app /script / service that doesn't (for whatever reason) support that 2FA authorization workflow.
So instead of using your regular password + OTP code (or clicking on notification on your smart phone... whatever type of extra steps that are there for extra secure login) Google allows those "less secure apps" to use just "app password".
Calibre's "send via email" feature is just one of those cases where that type of authorization isn't implemented.
|