InletDownload

Redis error WRONGPASS

WRONGPASS invalid username-password pair or user is disabled.

The server didn’t accept the user name and password you signed in with. Redis gives the same answer for a wrong password, a user that doesn’t exist and a user that’s turned off, so check all three.

WRONGPASS invalid username-password pair or user is disabled.

Tested on Redis 8.10.2 and Valkey 8.1.10 · Updated 9 October 2026

What it means

Your client sent AUTH (or HELLO … AUTH), and the server didn’t accept the user name and password in it. The server gives this one answer when:

  • the password is wrong,
  • no user by that name exists, or
  • the user exists but is turned off (off).

It doesn’t say which, so the reply gives away nothing about which user names exist. An administrator can see which user name was tried in ACL LOG (below).

The wording depends on the version. These come from Redis’s source, not from a server tested here:

  • Redis 6.0: WRONGPASS invalid username-password pair, without “or user is disabled.” (Redis 6.2 added it.)
  • Redis 5 and earlier, which had no users: ERR invalid password.

Two other replies look similar but mean something else:

  • NOAUTH Authentication required. means no password was sent at all; see NOAUTH.
  • ERR AUTH <password> called without any password configured for the default user. Are you sure your configuration is correct? means you sent a password to a server that doesn’t have one. (Redis 5 said ERR Client sent AUTH, but no password is set.) Remove the password from your client, or give the server one.

Passwords and users

Since Redis 6 (and in Valkey), every sign-in is a user name and a password:

  • requirepass in redis.conf sets the password of the user named default. AUTH <password>, with no user name, checks that user. So does a URL with an empty user name, redis://:<password>@….
  • ACL users are named users with their own passwords, key patterns and allowed commands, defined in redis.conf (user <name> on ><password> …), in an ACL file, or with ACL SETUSER. Their passwords work only together with their names: AUTH <user> <password>.

A user can have several passwords at once, which is how you change one without downtime: add the new password, move your clients over, then remove the old one.

Common causes

  1. The password is wrong: a typo, an old password after a rotation, or one read from a file or secret with a newline or space at the end.
  2. A named user’s password sent without the name. AUTH <password> or redis-cli -a <password> checks the default user, whose password is different.
  3. A user name the server doesn’t have. A client set up for an ACL user, pointed at a server that only has requirepass (and so only the default user), or at a different server than you think.
  4. The user is turned off. Its password is right, but the user is off, so it can’t sign in.
  5. Special characters in a URL. In a redis:// URL, % starts an escape and @, :, / and # split the URL. A password containing them, written as is, reaches the server changed, or the client misreads the host.

How to fix it

Try the pair from redis-cli

redis-cli -h <host> -p <port> --user <user> --askpass PING

--askpass asks for the password, so it doesn’t go into your shell history. A PONG means the pair is right and the problem is in your application’s settings. For the default user, leave out --user.

See what was tried

Signed in as an administrator, ACL LOG lists recent failed sign-ins with the user name each one tried and where it came from:

ACL LOG 5

Look for entries with reason auth: username is the user the client tried, and client-info shows its address. A username of default means the client sent a password without a user name.

Check the user

ACL GETUSER <user>

flags shows on or off; (nil) means there’s no such user. To turn a user back on:

ACL SETUSER <user> on

Set a new password

For the default user:

CONFIG SET requirepass <new password>
CONFIG REWRITE

CONFIG REWRITE writes the change into redis.conf so it survives a restart (a server started without a config file, as in Docker by default, answers ERR The server is running without a config file; set the password where you start it instead). For an ACL user, > adds a password and < removes one, so you can add the new password and remove the old one once nothing uses it. For a user named app:

ACL SETUSER app >new-password
ACL SETUSER app <old-password

Then save it where the users are defined: ACL SAVE if the server uses an ACL file, or the user line in redis.conf. On a hosted Redis, reset the password in the provider’s console instead.

Encode the password in URLs

Percent-encode the special characters: p@ss:w/rd#1 becomes p%40ss%3Aw%2Frd%231, and a literal % becomes %25. See special characters in passwords. Passing the password as a separate option (--pass, password:) avoids encoding altogether.

Reproduce it

Redis 8.10.2 with requirepass and two ACL users, using redis-cli 8.10.2 in the server’s container. A wrong password for the default user:

redis-cli -a <wrong password> PING
Warning: Using a password with '-a' or '-u' option on the command line interface may not be safe.
AUTH failed: WRONGPASS invalid username-password pair or user is disabled.
(error) NOAUTH Authentication required.

redis-cli carries on after the failed AUTH, so the PING then gets NOAUTH. A wrong password for an ACL user (--user <user> --pass <wrong password>) and a user name that doesn’t exist printed the same three lines. In an interactive session, AUTH <user> <wrong password> and HELLO 3 AUTH <user> <wrong password> both replied:

(error) WRONGPASS invalid username-password pair or user is disabled.

Valkey 8.1.10 gave the same messages. From Node.js, ioredis 5.11.1 reported ReplyError: WRONGPASS invalid username-password pair or user is disabled. According to its source, redis-py raises AuthenticationError with the code word dropped.

On a temporary Redis 8.10.2 server, with requirepass and an ACL user app that has its own password:

  • redis-cli -a <app’s password> PING (no user name) got WRONGPASS, and ACL LOG showed:

    1)  1) "count"
        2) (integer) 1
        3) "reason"
        4) "auth"
        5) "context"
        6) "toplevel"
        7) "object"
        8) "AUTH"
        9) "username"
       10) "default"
    …
    
  • A user created turned off (ACL SETUSER old off >oldpass ~* +@all), signing in with the right password, got the same WRONGPASS; ACL GETUSER old listed the flag off.

  • A user whose password contains %41, in a URL without encoding (redis://pct:ab%41cd@…), got WRONGPASS: redis-cli decoded %41 to A. Encoded as ab%2541cd, it answered PONG. A password with @, :, / and # written as is broke the URL instead: Could not connect to Redis at ss:0: Name or service not known.

On a temporary server with no password at all:

(error) ERR AUTH <password> called without any password configured for the default user. Are you sure your configuration is correct?

There, AUTH default <anything> replied OK, because a user with no password accepts any.

In Inlet

When the server answers WRONGPASS, Inlet says “Wrong user name or password.” and the connection window asks for the password there; once the server accepts it, Inlet can save it in the Keychain. Inlet signs in with a password or an ACL user and password. Paste a redis:// or rediss:// URL and Inlet fills in the form, so you can see which user it will sign in as.

Related

Sources