InletDownload

Redis error NOAUTH

NOAUTH Authentication required.

The server needs you to sign in, and your connection sent a command before it did. Give your client the password (and user name, for an ACL user), or send AUTH first.

NOAUTH Authentication required.

Tested on Redis 8.10.2 and Valkey 8.1.10 · Updated 9 October 2026

What it means

Every new connection to Redis starts out signed in as the default user, but only if that user has no password. Once the server has a password (requirepass), or its default user is turned off, a connection must sign in before it can run anything else. NOAUTH means your client skipped that step: it sent a command, and the server refused it without running it.

There are three ways to sign in:

  • AUTH <password> checks the password of the default user. That’s the password requirepass sets, and the only kind Redis had before version 6.
  • AUTH <user> <password> signs in as a named ACL user (Redis 6 and later, and Valkey).
  • HELLO 3 AUTH <user> <password> switches the connection to the RESP3 protocol and signs in at the same time. HELLO on its own, before signing in, gets the long form of the error:
NOAUTH HELLO must be called with the client already authenticated, otherwise the HELLO <proto> AUTH <user> <pass> option can be used to authenticate the client and select the RESP protocol version at the same time

NOAUTH means no password was tried. If your client did send one and the server rejected it, you get WRONGPASS instead (redis-cli then carries on without signing in, so you see both).

Common causes

  1. No password in the client’s settings. A URL like redis://<host>:6379 with nothing before the host, an empty REDIS_PASSWORD environment variable, or a library option under a different name from the one you set.
  2. The server gained a password. Someone set requirepass, or you moved from a local server without one to a hosted Redis that requires one.
  3. A user name but no password. redis-cli --user <user> without -a, --pass or --askpass sends no AUTH at all, and gets NOAUTH.
  4. Something runs before AUTH. Your code calls AUTH after its first command, or a library sends HELLO 3 to switch to RESP3 without its AUTH option.
  5. The default user is turned off (user default off in the ACL file), so every connection has to sign in as a named user.
  6. A replica without masterauth. A replica signs in to its primary like any client. Without the password, its log shows MASTER aborted replication with an error: NOAUTH Authentication required. and it never syncs.

How to fix it

Sign in from redis-cli

Give the user and let redis-cli ask for the password, so it doesn’t land in your shell history:

redis-cli -h <host> -p <port> --user <user> --askpass

For the default user, leave out --user. You can also put the password in the REDISCLI_AUTH environment variable. -a <password> works too, but redis-cli warns that it may not be safe, since other users of the machine can see command lines. Inside an interactive session, sign in first:

AUTH <user> <password>
ACL WHOAMI

ACL WHOAMI prints the user you’re now signed in as.

Give your application the password

In a URL, the user and password go before the host. For the default user, leave the user name empty or write default:

redis://<user>:<password>@<host>:6379/0
redis://:<password>@<host>:6379/0
rediss://default:<password>@<host>:<port>/0

rediss:// is the same with TLS. Characters such as @, :, / and # in the password must be percent-encoded; see special characters in passwords and the Redis URL format. Or pass the parts as options:

// node-redis
const client = createClient({ url: 'redis://<user>:<password>@<host>:6379' });
// ioredis
const redis = new Redis({ host: '<host>', port: 6379, username: '<user>', password: '<password>' });
# redis-py
r = redis.Redis(host='<host>', port=6379, username='<user>', password='<password>')

ioredis reports this error as ReplyError: NOAUTH Authentication required. According to its source, redis-py raises AuthenticationError with the code word dropped: Authentication required.

Find out what the server expects

Signed in as an administrator, ACL LIST shows every user: on or off, nopass for no password, or a hash of each password. CONFIG GET requirepass shows whether the default user has one set through requirepass. A default user that’s off means you need a named user.

Sign in with HELLO

If your client speaks RESP3, combine the two:

HELLO 3 AUTH <user> <password>

Give replicas the primary’s password

In the replica’s configuration:

masterauth <password>
masteruser <user>

masteruser is only needed when the replica signs in as an ACL user rather than default. Valkey 8 also accepts the names primaryauth and primaryuser.

Reproduce it

Redis 8.10.2 with requirepass set and two ACL users, using redis-cli 8.10.2 in the server’s container, with no password:

redis-cli PING
(error) NOAUTH Authentication required.

Selecting a database with -n 15 fails first, then the command:

SELECT 15 failed: NOAUTH Authentication required.
(error) NOAUTH Authentication required.

HELLO 3, and redis-cli started in RESP3 mode (-3):

(error) NOAUTH HELLO must be called with the client already authenticated, otherwise the HELLO <proto> AUTH <user> <pass> option can be used to authenticate the client and select the RESP protocol version at the same time
HELLO 3 failed: NOAUTH HELLO must be called with the client already authenticated, otherwise the HELLO <proto> AUTH <user> <pass> option can be used to authenticate the client and select the RESP protocol version at the same time
(error) NOAUTH Authentication required.

redis-cli --user <user> PING, with no password, also got NOAUTH. Valkey 8.1.10 (with valkey-cli 8.1.10, which the Valkey image also installs as redis-cli) gave every message word for word. From Node.js, ioredis 5.11.1 with no password reported ReplyError: NOAUTH Authentication required.

On a temporary Redis 8.10.2 server without a password, after ACL SETUSER default off, the same NOAUTH came back for PING, and HELLO 3 AUTH <user> <password> signed in and switched protocol in one step:

1# "server" => "redis"
2# "version" => "8.10.2"
3# "proto" => (integer) 3
…

A temporary replica pointed at a primary with requirepass, without masterauth, logged:

1:S 09 Oct 2026 15:13:31.320 # Unexpected reply to PSYNC from master: -NOAUTH Authentication required.
1:S 09 Oct 2026 15:13:31.320 # MASTER aborted replication with an error: NOAUTH Authentication required.
1:S 09 Oct 2026 15:13:31.320 * Reconnecting to MASTER 192.168.215.5:6379 after failure

INFO replication on the replica showed master_link_status:down.

In Inlet

When the server answers NOAUTH, Inlet says “The server needs a password.” and the connection window asks for it there; once the server accepts it, Inlet can save it in the Keychain. Inlet signs in with a password or an ACL user and password. Paste a redis:// or rediss:// URL and Inlet fills in the form, so you can check the user, host and port before you connect.

Related

Sources