What it means
AUTH <password>, the one-argument form, signs in as the default user. On a server where that
user has no password (nopass, the default when you haven’t set requirepass), there’s nothing to
check the password against, so Redis says your configuration looks wrong rather than accepting it:
(error) ERR AUTH <password> called without any password configured for the default user. Are you sure your configuration is correct?
You’re still connected and can run commands: the server needed no password in the first place.
But a client that treats any error from AUTH as a failed sign-in stops there.
Older servers word it differently. Redis 5 and earlier, which have no ACL users, say:
ERR Client sent AUTH, but no password is set
Valkey 8.1.10 uses Redis 6’s wording. The two-argument form behaves differently: AUTH default <password> on the same server replies OK, because a nopass user accepts any password, and
AUTH <someone-else> <password> gets WRONGPASS
if that user doesn’t exist.
Common causes
- One configuration for several servers. Production has a password, the local or CI server
(such as a Docker container started with no options) doesn’t, and the same
REDIS_PASSWORDorredis://:<password>@…URL is used for both. - A password set only until the next restart.
CONFIG SET requirepasschanges the running server; withoutCONFIG REWRITE(or the same line inredis.conf), a restart brings it back without a password while clients still send one. - A password in a configuration file the server doesn’t read, for example a
redis.confthat the container or service wasn’t started with.
How to fix it
Decide whether the server should have a password
Check the server:
redis-cli CONFIG GET requirepass
redis-cli ACL LIST
An empty requirepass and user default on nopass … in ACL LIST mean anyone who can reach the
port can run commands. Redis’s protected mode, on by default, then accepts connections from the
same machine only, but the official Docker images turn it off (see
Connection refused). No password is fine for a server only your
machine can reach; anything on a network should have a password or ACL users.
If it shouldn’t, stop sending one
Remove the password from the client’s settings or the URL for this server: redis://localhost:6379
rather than redis://:<password>@localhost:6379. Keep separate settings per environment so the
production password isn’t sent to a local server.
If it should, set it on the server
redis-cli CONFIG SET requirepass "<password>"
redis-cli CONFIG REWRITE # keep it after a restart
Or put requirepass <password> in redis.conf, or start the server with
redis-server --requirepass <password>. With ACL users, give the default user a password
(ACL SETUSER default on ><password>) or turn it off and create named users. Clients that don’t
send a password then get NOAUTH Authentication required
(NOAUTH), so update them at the same time.
Or sign in with a user name
If your client sends AUTH default <password> (a user name and a password), a server without a
password accepts it, so the same settings work against both kinds of server. Clients that take a
user name send this form when you give them one: in a URL, redis://default:<password>@host:6379.
Reproduce it
A temporary Redis 8.10.2 container started with no options:
docker run --rm -d --name seo-err-nopass redis:8 redis-server
AUTH secret
(error) ERR AUTH <password> called without any password configured for the default user. Are you sure your configuration is correct?
AUTH default secret
OK
AUTH app secret
(error) WRONGPASS invalid username-password pair or user is disabled.
ACL WHOAMI
"default"
HELLO 3 AUTH default secret succeeded as well ("server" => "redis", "version" => "8.10.2").
redis-cli with -a sends the one-argument form, prints the error, and carries on:
$ redis-cli -a secret PING
Warning: Using a password with '-a' or '-u' option on the command line interface may not be safe.
AUTH failed: ERR AUTH <password> called without any password configured for the default user. Are you sure your configuration is correct?
PONG
redis-cli -u redis://:secret@127.0.0.1:6379 PING did the same, while --user default --pass secret
and -u redis://default:secret@127.0.0.1:6379 replied PONG with no error. A temporary Valkey
8.1.10 container gave the same three replies to AUTH, word for word.
The Redis 5 wording comes from Redis 5.0’s source (authCommand in server.c); we didn’t run a
Redis 5 server.
In Inlet
The connection window takes a user name and password, or a redis:// URL, and keeps the password
in the Keychain or asks for it every time. Leave both empty for a server without a password. If a
connection fails at sign-in, Inlet shows the server’s message and links to its page here.