Redis error NOAUTH
NOAUTH Authentication required.
The server needs you to sign in, and your connection sent a command before it did. Give your client the password (and user name, for an ACL user), or send AUTH first.
NOAUTH Authentication required.
Tested on Redis 8.10.2 and Valkey 8.1.10 · Updated 9 October 2026
What it means
Every new connection to Redis starts out signed in as the default user, but only if that user has
no password. Once the server has a password (requirepass), or its default user is turned off,
a connection must sign in before it can run anything else. NOAUTH means your client skipped that
step: it sent a command, and the server refused it without running it.
There are three ways to sign in:
AUTH <password>checks the password of thedefaultuser. That’s the passwordrequirepasssets, and the only kind Redis had before version 6.AUTH <user> <password>signs in as a named ACL user (Redis 6 and later, and Valkey).HELLO 3 AUTH <user> <password>switches the connection to the RESP3 protocol and signs in at the same time.HELLOon its own, before signing in, gets the long form of the error:
NOAUTH HELLO must be called with the client already authenticated, otherwise the HELLO <proto> AUTH <user> <pass> option can be used to authenticate the client and select the RESP protocol version at the same time
NOAUTH means no password was tried. If your client did send one and the server rejected it, you
get WRONGPASS instead (redis-cli then carries
on without signing in, so you see both).
Common causes
- No password in the client’s settings. A URL like
redis://<host>:6379with nothing before the host, an emptyREDIS_PASSWORDenvironment variable, or a library option under a different name from the one you set. - The server gained a password. Someone set
requirepass, or you moved from a local server without one to a hosted Redis that requires one. - A user name but no password.
redis-cli --user <user>without-a,--passor--askpasssends noAUTHat all, and getsNOAUTH. - Something runs before
AUTH. Your code callsAUTHafter its first command, or a library sendsHELLO 3to switch to RESP3 without itsAUTHoption. - The
defaultuser is turned off (user default offin the ACL file), so every connection has to sign in as a named user. - A replica without
masterauth. A replica signs in to its primary like any client. Without the password, its log showsMASTER aborted replication with an error: NOAUTH Authentication required.and it never syncs.
How to fix it
Sign in from redis-cli
Give the user and let redis-cli ask for the password, so it doesn’t land in your shell history:
redis-cli -h <host> -p <port> --user <user> --askpass
For the default user, leave out --user. You can also put the password in the REDISCLI_AUTH
environment variable. -a <password> works too, but redis-cli warns that it may not be safe, since
other users of the machine can see command lines. Inside an interactive session, sign in first:
AUTH <user> <password>
ACL WHOAMI
ACL WHOAMI prints the user you’re now signed in as.
Give your application the password
In a URL, the user and password go before the host. For the default user, leave the user name
empty or write default:
redis://<user>:<password>@<host>:6379/0
redis://:<password>@<host>:6379/0
rediss://default:<password>@<host>:<port>/0
rediss:// is the same with TLS. Characters such as @, :, / and # in the password must be
percent-encoded; see special characters in passwords
and the Redis URL format. Or pass the parts as options:
// node-redis
const client = createClient({ url: 'redis://<user>:<password>@<host>:6379' });
// ioredis
const redis = new Redis({ host: '<host>', port: 6379, username: '<user>', password: '<password>' });
# redis-py
r = redis.Redis(host='<host>', port=6379, username='<user>', password='<password>')
ioredis reports this error as ReplyError: NOAUTH Authentication required. According to its source,
redis-py raises AuthenticationError with the code word dropped: Authentication required.
Find out what the server expects
Signed in as an administrator, ACL LIST shows every user: on or off, nopass for no password,
or a hash of each password. CONFIG GET requirepass shows whether the default user has one set
through requirepass. A default user that’s off means you need a named user.
Sign in with HELLO
If your client speaks RESP3, combine the two:
HELLO 3 AUTH <user> <password>
Give replicas the primary’s password
In the replica’s configuration:
masterauth <password>
masteruser <user>
masteruser is only needed when the replica signs in as an ACL user rather than default. Valkey 8
also accepts the names primaryauth and primaryuser.
Reproduce it
Redis 8.10.2 with requirepass set and two ACL users, using redis-cli 8.10.2 in the server’s
container, with no password:
redis-cli PING
(error) NOAUTH Authentication required.
Selecting a database with -n 15 fails first, then the command:
SELECT 15 failed: NOAUTH Authentication required.
(error) NOAUTH Authentication required.
HELLO 3, and redis-cli started in RESP3 mode (-3):
(error) NOAUTH HELLO must be called with the client already authenticated, otherwise the HELLO <proto> AUTH <user> <pass> option can be used to authenticate the client and select the RESP protocol version at the same time
HELLO 3 failed: NOAUTH HELLO must be called with the client already authenticated, otherwise the HELLO <proto> AUTH <user> <pass> option can be used to authenticate the client and select the RESP protocol version at the same time
(error) NOAUTH Authentication required.
redis-cli --user <user> PING, with no password, also got NOAUTH. Valkey 8.1.10 (with
valkey-cli 8.1.10, which the Valkey image also installs as redis-cli) gave every message word for
word. From Node.js, ioredis 5.11.1 with no password reported
ReplyError: NOAUTH Authentication required.
On a temporary Redis 8.10.2 server without a password, after ACL SETUSER default off, the same
NOAUTH came back for PING, and HELLO 3 AUTH <user> <password> signed in and switched protocol
in one step:
1# "server" => "redis"
2# "version" => "8.10.2"
3# "proto" => (integer) 3
…
A temporary replica pointed at a primary with requirepass, without masterauth, logged:
1:S 09 Oct 2026 15:13:31.320 # Unexpected reply to PSYNC from master: -NOAUTH Authentication required.
1:S 09 Oct 2026 15:13:31.320 # MASTER aborted replication with an error: NOAUTH Authentication required.
1:S 09 Oct 2026 15:13:31.320 * Reconnecting to MASTER 192.168.215.5:6379 after failure
INFO replication on the replica showed master_link_status:down.
In Inlet
When the server answers NOAUTH, Inlet says “The server needs a password.” and the connection
window asks for it there; once the server accepts it, Inlet can save it in the Keychain. Inlet signs
in with a password or an ACL user and password. Paste a redis:// or rediss:// URL and Inlet
fills in the form, so you can check the user, host and port before you connect.
Related
- WRONGPASS invalid username-password pair or user is disabled.
- NOPERM User reader has no permissions to run the 'set' command
- Could not connect to Redis at 127.0.0.1:6379: Connection refused
- Redis connection string: redis:// and rediss:// URLs explained
- Connect to Redis in Docker or Homebrew on your Mac
- Connect to Upstash Redis from your Mac
- Connect to Redis Cloud from your Mac
- Connect to Amazon ElastiCache for Redis OSS or Valkey from your Mac
- Connect to Valkey from your Mac
Sources
- redis.io/docs/latest/commands/auth/
- redis.io/docs/latest/commands/hello/
- redis.io/docs/latest/operate/oss_and_stack/management/security/acl/
- redis.io/docs/latest/operate/oss_and_stack/management/replication/
- redis.io/docs/latest/develop/tools/cli/
- valkey.io/topics/acl/
- github.com/redis/redis-py/blob/master/redis/_parsers/base.py