Redis error WRONGPASS
WRONGPASS invalid username-password pair or user is disabled.
The server didn’t accept the user name and password you signed in with. Redis gives the same answer for a wrong password, a user that doesn’t exist and a user that’s turned off, so check all three.
WRONGPASS invalid username-password pair or user is disabled.
Tested on Redis 8.10.2 and Valkey 8.1.10 · Updated 9 October 2026
What it means
Your client sent AUTH (or HELLO … AUTH), and the server didn’t accept the user name and password
in it. The server gives this one answer when:
- the password is wrong,
- no user by that name exists, or
- the user exists but is turned off (
off).
It doesn’t say which, so the reply gives away nothing about which user names exist. An
administrator can see which user name was tried in ACL LOG (below).
The wording depends on the version. These come from Redis’s source, not from a server tested here:
- Redis 6.0:
WRONGPASS invalid username-password pair, without “or user is disabled.” (Redis 6.2 added it.) - Redis 5 and earlier, which had no users:
ERR invalid password.
Two other replies look similar but mean something else:
NOAUTH Authentication required.means no password was sent at all; see NOAUTH.ERR AUTH <password> called without any password configured for the default user. Are you sure your configuration is correct?means you sent a password to a server that doesn’t have one. (Redis 5 saidERR Client sent AUTH, but no password is set.) Remove the password from your client, or give the server one.
Passwords and users
Since Redis 6 (and in Valkey), every sign-in is a user name and a password:
requirepassin redis.conf sets the password of the user nameddefault.AUTH <password>, with no user name, checks that user. So does a URL with an empty user name,redis://:<password>@….- ACL users are named users with their own passwords, key patterns and allowed commands, defined in
redis.conf (
user <name> on ><password> …), in an ACL file, or withACL SETUSER. Their passwords work only together with their names:AUTH <user> <password>.
A user can have several passwords at once, which is how you change one without downtime: add the new password, move your clients over, then remove the old one.
Common causes
- The password is wrong: a typo, an old password after a rotation, or one read from a file or secret with a newline or space at the end.
- A named user’s password sent without the name.
AUTH <password>orredis-cli -a <password>checks thedefaultuser, whose password is different. - A user name the server doesn’t have. A client set up for an ACL user, pointed at a server that
only has
requirepass(and so only thedefaultuser), or at a different server than you think. - The user is turned off. Its password is right, but the user is
off, so it can’t sign in. - Special characters in a URL. In a
redis://URL,%starts an escape and@,:,/and#split the URL. A password containing them, written as is, reaches the server changed, or the client misreads the host.
How to fix it
Try the pair from redis-cli
redis-cli -h <host> -p <port> --user <user> --askpass PING
--askpass asks for the password, so it doesn’t go into your shell history. A PONG means the pair
is right and the problem is in your application’s settings. For the default user, leave out
--user.
See what was tried
Signed in as an administrator, ACL LOG lists recent failed sign-ins with the user name each one
tried and where it came from:
ACL LOG 5
Look for entries with reason auth: username is the user the client tried, and client-info
shows its address. A username of default means the client sent a password without a user name.
Check the user
ACL GETUSER <user>
flags shows on or off; (nil) means there’s no such user. To turn a user back on:
ACL SETUSER <user> on
Set a new password
For the default user:
CONFIG SET requirepass <new password>
CONFIG REWRITE
CONFIG REWRITE writes the change into redis.conf so it survives a restart (a server started
without a config file, as in Docker by default, answers ERR The server is running without a config file; set the password where you start it instead). For an ACL user, > adds a password and <
removes one, so you can add the new password and remove the old one once nothing uses it. For a user
named app:
ACL SETUSER app >new-password
ACL SETUSER app <old-password
Then save it where the users are defined: ACL SAVE if the server uses an ACL file, or the user
line in redis.conf. On a hosted Redis, reset the password in the provider’s console instead.
Encode the password in URLs
Percent-encode the special characters: p@ss:w/rd#1 becomes p%40ss%3Aw%2Frd%231, and a literal
% becomes %25. See special characters in passwords.
Passing the password as a separate option (--pass, password:) avoids encoding altogether.
Reproduce it
Redis 8.10.2 with requirepass and two ACL users, using redis-cli 8.10.2 in the server’s container.
A wrong password for the default user:
redis-cli -a <wrong password> PING
Warning: Using a password with '-a' or '-u' option on the command line interface may not be safe.
AUTH failed: WRONGPASS invalid username-password pair or user is disabled.
(error) NOAUTH Authentication required.
redis-cli carries on after the failed AUTH, so the PING then gets NOAUTH. A wrong password for
an ACL user (--user <user> --pass <wrong password>) and a user name that doesn’t exist printed the
same three lines. In an interactive session, AUTH <user> <wrong password> and
HELLO 3 AUTH <user> <wrong password> both replied:
(error) WRONGPASS invalid username-password pair or user is disabled.
Valkey 8.1.10 gave the same messages. From Node.js, ioredis 5.11.1 reported
ReplyError: WRONGPASS invalid username-password pair or user is disabled. According to its source,
redis-py raises AuthenticationError with the code word dropped.
On a temporary Redis 8.10.2 server, with requirepass and an ACL user app that has its own
password:
-
redis-cli -a <app’s password> PING(no user name) gotWRONGPASS, andACL LOGshowed:1) 1) "count" 2) (integer) 1 3) "reason" 4) "auth" 5) "context" 6) "toplevel" 7) "object" 8) "AUTH" 9) "username" 10) "default" … -
A user created turned off (
ACL SETUSER old off >oldpass ~* +@all), signing in with the right password, got the sameWRONGPASS;ACL GETUSER oldlisted the flagoff. -
A user whose password contains
%41, in a URL without encoding (redis://pct:ab%41cd@…), gotWRONGPASS: redis-cli decoded%41toA. Encoded asab%2541cd, it answeredPONG. A password with@,:,/and#written as is broke the URL instead:Could not connect to Redis at ss:0: Name or service not known.
On a temporary server with no password at all:
(error) ERR AUTH <password> called without any password configured for the default user. Are you sure your configuration is correct?
There, AUTH default <anything> replied OK, because a user with no password accepts any.
In Inlet
When the server answers WRONGPASS, Inlet says “Wrong user name or password.” and the connection
window asks for the password there; once the server accepts it, Inlet can save it in the Keychain.
Inlet signs in with a password or an ACL user and password. Paste a redis:// or rediss:// URL and
Inlet fills in the form, so you can see which user it will sign in as.
Related
- NOAUTH Authentication required.
- NOPERM User reader has no permissions to run the 'set' command
- Could not connect to Redis at 127.0.0.1:6379: Connection refused
- Redis connection string: redis:// and rediss:// URLs explained
- Special characters in database passwords: percent-encoding connection URLs
- Connect to Redis in Docker or Homebrew on your Mac
- Connect to Upstash Redis from your Mac
- Connect to Redis Cloud from your Mac
- Connect to Amazon ElastiCache for Redis OSS or Valkey from your Mac
- Connect to Valkey from your Mac
Sources
- redis.io/docs/latest/commands/auth/
- redis.io/docs/latest/operate/oss_and_stack/management/security/acl/
- redis.io/docs/latest/commands/acl-log/
- redis.io/docs/latest/commands/acl-getuser/
- redis.io/docs/latest/develop/tools/cli/
- valkey.io/topics/acl/
- github.com/redis/redis/blob/5.0/src/server.c
- github.com/redis/redis/blob/6.0/src/acl.c
- github.com/redis/redis-py/blob/master/redis/_parsers/base.py