MongoDB error 13
not authorized on db to execute command
You signed in, but your user has no role that allows this command on this database. Check which roles the connection has, then grant the role it needs on the right database, or connect as a user that has it.
not authorized on seo_mongo to execute command { insert: "orders", documents: [ { total: 10, _id: ObjectId('6ac8bd8bce2ffe18b7a6e353') } ], ordered: true, lsid: { id: UUID("4e3d4ff6-ac84-4c22-8e52-1833542ac256") }, $db: "seo_mongo" }Tested on MongoDB 8.0.32 (mongosh 2.12.0) · Updated 9 October 2026
What it means
Signing in worked (a wrong password is Authentication failed),
but none of your user’s roles grants this action on this database. The server returns code 13,
Unauthorized, and names both:
not authorized on seo_mongo: the database the command ran against.to execute command { insert: "orders", … }: the command. Its first field is the action (insert,find,createIndexes,listCollections,serverStatus) and the collection.
The same code comes with Command find requires authentication when the connection didn’t sign
in at all, on a server that requires it.
Common causes
- The role doesn’t include the action. A user with
readcan’t insert, update, delete or create indexes; those needreadWrite. - The role is on another database. Roles are granted per database:
readWriteonmyappallows nothing onmyapp_testor onadmin. - A server-wide command.
serverStatus,currentOpand replica set status run againstadminand need roles such asclusterMonitor. Monitoring tools and some clients run them as soon as they connect. - No credentials at all. The connection string has no user, or the variable that should hold it is empty, so every command “requires authentication”.
- Signed in as another user than you think, for example because an environment variable overrides the URL in your configuration.
How to fix it
See who you are and what you may do
db.runCommand({ connectionStatus: 1 }).authInfo
{
authenticatedUsers: [ { user: 'seo_mongo_app', db: 'seo_mongo' } ],
authenticatedUserRoles: [ { role: 'read', db: 'seo_mongo' } ]
}
Compare the roles with the database and action in the error. You can also read your own user with
db.getUser("<user>") in its authentication database, without extra privileges.
Grant the role, as an administrator
Connect as a user that administers users, switch to the user’s authentication database, and grant the role on the database the command needs:
db.getSiblingDB("<auth database>").grantRolesToUser("<user>", [
{ role: "readWrite", db: "<database>" }
])
The built-in roles you’ll usually want:
| Role | Allows |
|---|---|
read | Reading collections in one database |
readWrite | read, plus writing, creating indexes and creating or dropping collections |
dbAdmin | Schema tasks, indexes and statistics in one database (not reading data) |
dbOwner | readWrite, dbAdmin and userAdmin together, for one database |
clusterMonitor | Read-only monitoring commands such as serverStatus (granted on admin) |
Grant the narrowest role that works. revokeRolesFromUser takes away what you no longer need.
Use the database you have rights on
If the user should only touch myapp, check the database name in your code and connection string.
show dbs lists only the databases your roles cover, which is a quick way to see them.
On Atlas
Atlas manages users and roles in its UI (Database Access), CLI or API; grantRolesToUser from a
shell is rolled back. Edit the user there and give it a role on the right database. See
connecting to MongoDB Atlas.
Reproduce it
MongoDB 8.0.32 in Docker, mongosh 2.12.0. A user seo_mongo_app with only the read role on
seo_mongo, trying to insert:
db.orders.insertOne({ total: 10 })
MongoServerError: not authorized on seo_mongo to execute command { insert: "orders", documents: [ { total: 10, _id: ObjectId('6ac8bd8bce2ffe18b7a6e353') } ], ordered: true, lsid: { id: UUID("4e3d4ff6-ac84-4c22-8e52-1833542ac256") }, $db: "seo_mongo" }
The error’s code was 13 and codeName Unauthorized. With the same user (trimmed):
not authorized on seo_mongo to execute command { createIndexes: "users", … }
not authorized on inlet to execute command { listCollections: 1, … }
not authorized on admin to execute command { serverStatus: 1, … }
Reading seo_mongo worked, and show dbs listed only seo_mongo. Without any credentials:
MongoServerError: Command find requires authentication
After grantRolesToUser with readWrite on seo_mongo, the insert and createIndex both worked.
Writing to another database, seo_mongo_other, was still refused.
In Inlet
Inlet connects as the user in your connection and shows the server’s message when a command is
refused, with the database and command in it. A user with only the read role can still open
collections as tables and read documents in the inspector; anything that writes needs readWrite
on that database.