InletDownload

PostgreSQL error

fe_sendauth: no password supplied

The server asked for a password and your client had none to give: nothing in the connection string, no PGPASSWORD, no matching line in ~/.pgpass, and no way to ask you. Supply the password in one of those places.

connection to server at "localhost" (::1), port 54318 failed: fe_sendauth: no password supplied

Tested on PostgreSQL 18.6, psql 18.6 · Updated 9 October 2026

What it means

The server matched a pg_hba.conf rule that requires a password (scram-sha-256, md5 or password) and asked your client for one. The client had nothing to send, so it gave up. fe is “front end”: libpq, the client library behind psql and most PostgreSQL drivers, raises this error itself. The server never saw a wrong password, and there’s no SQLSTATE.

libpq looks for a password in this order: the connection string or URL, then the PGPASSWORD environment variable, then the password file (~/.pgpass). If all three come up empty, psql asks you at the terminal, unless it can’t (no terminal) or was told not to (-w).

Common causes

  1. No password configured. The app’s settings or DATABASE_URL has a user and host but no password, or an environment variable that should hold it is unset or empty in this shell, container or CI job.
  2. Nobody there to type it. Cron jobs, scripts, CI and psql -w (--no-password) can’t prompt, so a missing password fails at once.
  3. ~/.pgpass doesn’t match. Its host field is compared with the host you gave as text: a line for 127.0.0.1 doesn’t match -h localhost. The port, database and user must match too (or be *).
  4. ~/.pgpass is ignored because other users can read it. libpq prints a warning and carries on as if the file weren’t there.
  5. It worked a different way before. Inside a Docker container, psql connects over the local socket, which the official image trusts without a password. From your Mac the same server is reached over TCP, where it asks for one.

How to fix it

Put the password in the connection

psql "postgresql://<user>:<password>@<host>:5432/<database>"

Percent-encode @, :, /, ?, # and % in a URL password; see special characters in passwords. In a shell, this puts the password in your history. PGPASSWORD=<password> psql … has the same drawback and is visible to other processes on some systems; the password file is better for anything you keep.

Use a password file

~/.pgpass holds one line per server, in the form host:port:database:user:password, and * matches anything:

localhost:5432:*:<user>:<password>
db.example.com:5432:app:<user>:<password>

It must be readable only by you:

chmod 600 ~/.pgpass

Write the host the same way you pass it. If you connect with -h localhost, the line needs localhost, not 127.0.0.1. PGPASSFILE (or the passfile connection parameter) points libpq at a different file.

Let psql ask

Run psql without -w in a terminal and it prompts: Password for user <user>:. -W makes it ask before connecting, even if it might not need to.

Check what the server asks for

If you expected no password (a local trust or peer rule), check which pg_hba.conf line you match: a TCP connection to localhost doesn’t match a local (socket) line. Connecting with -h changes which rule applies.

Reproduce it

PostgreSQL 18.6 in Docker, with host all all all scram-sha-256 for connections from outside the container, no PGPASSWORD and no ~/.pgpass. -w stops psql from prompting:

psql -w -h localhost -p 54318 -U inlet -d inlet -c 'select 1'
psql: error: connection to server at "localhost" (::1), port 54318 failed: fe_sendauth: no password supplied

An empty PGPASSWORD= gives the same error. So does a password file whose only line is for 127.0.0.1 when you connect to localhost; the same file works with -h 127.0.0.1:

$ cat pgpass
127.0.0.1:54318:inlet:inlet:<password>
$ PGPASSFILE=pgpass psql -w -h localhost -p 54318 -U inlet -d inlet -Atc 'select 1'
psql: error: connection to server at "localhost" (::1), port 54318 failed: fe_sendauth: no password supplied
$ PGPASSFILE=pgpass psql -w -h 127.0.0.1 -p 54318 -U inlet -d inlet -Atc 'select 1'
1

With a password file other users can read, libpq warns and ignores it:

WARNING: password file "/private/tmp/…/pgpass" has group or world access; permissions should be u=rw (0600) or less
psql: error: connection to server at "localhost" (::1), port 54318 failed: fe_sendauth: no password supplied

Through an md5 rule the error is the same.

In Inlet

If the password is missing, the connection window asks for it there; tick Save in Keychain and Inlet keeps it once the server accepts it. Inlet can also import your connections from ~/.pgpass.

Related

Sources