InletDownload

MongoDB error 13

not authorized on db to execute command

You signed in, but your user has no role that allows this command on this database. Check which roles the connection has, then grant the role it needs on the right database, or connect as a user that has it.

not authorized on seo_mongo to execute command { insert: "orders", documents: [ { total: 10, _id: ObjectId('6ac8bd8bce2ffe18b7a6e353') } ], ordered: true, lsid: { id: UUID("4e3d4ff6-ac84-4c22-8e52-1833542ac256") }, $db: "seo_mongo" }

Tested on MongoDB 8.0.32 (mongosh 2.12.0) · Updated 9 October 2026

What it means

Signing in worked (a wrong password is Authentication failed), but none of your user’s roles grants this action on this database. The server returns code 13, Unauthorized, and names both:

  • not authorized on seo_mongo: the database the command ran against.
  • to execute command { insert: "orders", … }: the command. Its first field is the action (insert, find, createIndexes, listCollections, serverStatus) and the collection.

The same code comes with Command find requires authentication when the connection didn’t sign in at all, on a server that requires it.

Common causes

  1. The role doesn’t include the action. A user with read can’t insert, update, delete or create indexes; those need readWrite.
  2. The role is on another database. Roles are granted per database: readWrite on myapp allows nothing on myapp_test or on admin.
  3. A server-wide command. serverStatus, currentOp and replica set status run against admin and need roles such as clusterMonitor. Monitoring tools and some clients run them as soon as they connect.
  4. No credentials at all. The connection string has no user, or the variable that should hold it is empty, so every command “requires authentication”.
  5. Signed in as another user than you think, for example because an environment variable overrides the URL in your configuration.

How to fix it

See who you are and what you may do

db.runCommand({ connectionStatus: 1 }).authInfo
{
  authenticatedUsers: [ { user: 'seo_mongo_app', db: 'seo_mongo' } ],
  authenticatedUserRoles: [ { role: 'read', db: 'seo_mongo' } ]
}

Compare the roles with the database and action in the error. You can also read your own user with db.getUser("<user>") in its authentication database, without extra privileges.

Grant the role, as an administrator

Connect as a user that administers users, switch to the user’s authentication database, and grant the role on the database the command needs:

db.getSiblingDB("<auth database>").grantRolesToUser("<user>", [
  { role: "readWrite", db: "<database>" }
])

The built-in roles you’ll usually want:

RoleAllows
readReading collections in one database
readWriteread, plus writing, creating indexes and creating or dropping collections
dbAdminSchema tasks, indexes and statistics in one database (not reading data)
dbOwnerreadWrite, dbAdmin and userAdmin together, for one database
clusterMonitorRead-only monitoring commands such as serverStatus (granted on admin)

Grant the narrowest role that works. revokeRolesFromUser takes away what you no longer need.

Use the database you have rights on

If the user should only touch myapp, check the database name in your code and connection string. show dbs lists only the databases your roles cover, which is a quick way to see them.

On Atlas

Atlas manages users and roles in its UI (Database Access), CLI or API; grantRolesToUser from a shell is rolled back. Edit the user there and give it a role on the right database. See connecting to MongoDB Atlas.

Reproduce it

MongoDB 8.0.32 in Docker, mongosh 2.12.0. A user seo_mongo_app with only the read role on seo_mongo, trying to insert:

db.orders.insertOne({ total: 10 })
MongoServerError: not authorized on seo_mongo to execute command { insert: "orders", documents: [ { total: 10, _id: ObjectId('6ac8bd8bce2ffe18b7a6e353') } ], ordered: true, lsid: { id: UUID("4e3d4ff6-ac84-4c22-8e52-1833542ac256") }, $db: "seo_mongo" }

The error’s code was 13 and codeName Unauthorized. With the same user (trimmed):

not authorized on seo_mongo to execute command { createIndexes: "users", … }
not authorized on inlet to execute command { listCollections: 1, … }
not authorized on admin to execute command { serverStatus: 1, … }

Reading seo_mongo worked, and show dbs listed only seo_mongo. Without any credentials:

MongoServerError: Command find requires authentication

After grantRolesToUser with readWrite on seo_mongo, the insert and createIndex both worked. Writing to another database, seo_mongo_other, was still refused.

In Inlet

Inlet connects as the user in your connection and shows the server’s message when a command is refused, with the database and command in it. A user with only the read role can still open collections as tables and read documents in the inspector; anything that writes needs readWrite on that database.

Related

Sources