PostgreSQL error
fe_sendauth: no password supplied
The server asked for a password and your client had none to give: nothing in the connection string, no PGPASSWORD, no matching line in ~/.pgpass, and no way to ask you. Supply the password in one of those places.
connection to server at "localhost" (::1), port 54318 failed: fe_sendauth: no password supplied
Tested on PostgreSQL 18.6, psql 18.6 · Updated 9 October 2026
What it means
The server matched a pg_hba.conf rule that requires a password (scram-sha-256, md5 or
password) and asked your client for one. The client had nothing to send, so it gave up. fe is
“front end”: libpq, the client library behind psql and most PostgreSQL drivers, raises this error
itself. The server never saw a wrong password, and there’s no SQLSTATE.
libpq looks for a password in this order: the connection string or URL, then the PGPASSWORD
environment variable, then the password file (~/.pgpass). If all three come up empty, psql asks
you at the terminal, unless it can’t (no terminal) or was told not to (-w).
Common causes
- No password configured. The app’s settings or
DATABASE_URLhas a user and host but no password, or an environment variable that should hold it is unset or empty in this shell, container or CI job. - Nobody there to type it. Cron jobs, scripts, CI and
psql -w(--no-password) can’t prompt, so a missing password fails at once. ~/.pgpassdoesn’t match. Its host field is compared with the host you gave as text: a line for127.0.0.1doesn’t match-h localhost. The port, database and user must match too (or be*).~/.pgpassis ignored because other users can read it. libpq prints a warning and carries on as if the file weren’t there.- It worked a different way before. Inside a Docker container,
psqlconnects over the local socket, which the official image trusts without a password. From your Mac the same server is reached over TCP, where it asks for one.
How to fix it
Put the password in the connection
psql "postgresql://<user>:<password>@<host>:5432/<database>"
Percent-encode @, :, /, ?, # and % in a URL password; see
special characters in passwords. In a shell,
this puts the password in your history. PGPASSWORD=<password> psql … has the same drawback and is
visible to other processes on some systems; the password file is better for anything you keep.
Use a password file
~/.pgpass holds one line per server, in the form host:port:database:user:password, and *
matches anything:
localhost:5432:*:<user>:<password>
db.example.com:5432:app:<user>:<password>
It must be readable only by you:
chmod 600 ~/.pgpass
Write the host the same way you pass it. If you connect with -h localhost, the line needs
localhost, not 127.0.0.1. PGPASSFILE (or the passfile connection parameter) points libpq at a
different file.
Let psql ask
Run psql without -w in a terminal and it prompts: Password for user <user>:. -W makes it ask
before connecting, even if it might not need to.
Check what the server asks for
If you expected no password (a local trust or peer rule), check which pg_hba.conf line you match:
a TCP connection to localhost doesn’t match a local (socket) line. Connecting with -h changes
which rule applies.
Reproduce it
PostgreSQL 18.6 in Docker, with host all all all scram-sha-256 for connections from outside the
container, no PGPASSWORD and no ~/.pgpass. -w stops psql from prompting:
psql -w -h localhost -p 54318 -U inlet -d inlet -c 'select 1'
psql: error: connection to server at "localhost" (::1), port 54318 failed: fe_sendauth: no password supplied
An empty PGPASSWORD= gives the same error. So does a password file whose only line is for
127.0.0.1 when you connect to localhost; the same file works with -h 127.0.0.1:
$ cat pgpass
127.0.0.1:54318:inlet:inlet:<password>
$ PGPASSFILE=pgpass psql -w -h localhost -p 54318 -U inlet -d inlet -Atc 'select 1'
psql: error: connection to server at "localhost" (::1), port 54318 failed: fe_sendauth: no password supplied
$ PGPASSFILE=pgpass psql -w -h 127.0.0.1 -p 54318 -U inlet -d inlet -Atc 'select 1'
1
With a password file other users can read, libpq warns and ignores it:
WARNING: password file "/private/tmp/…/pgpass" has group or world access; permissions should be u=rw (0600) or less
psql: error: connection to server at "localhost" (::1), port 54318 failed: fe_sendauth: no password supplied
Through an md5 rule the error is the same.
In Inlet
If the password is missing, the connection window asks for it there; tick Save in Keychain and
Inlet keeps it once the server accepts it. Inlet can also import your connections from ~/.pgpass.