{"record":{"id":"cc4fc9f29ad685c0","repo":"go-sql-driver/mysql","slug":"this-authentication-plugin-is-not-supported","errorCode":null,"errorMessage":"this authentication plugin is not supported","messagePattern":"this authentication plugin is not supported","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"errors.go","lineNumber":25,"sourceCode":"// You can obtain one at http://mozilla.org/MPL/2.0/.\n\npackage mysql\n\nimport (\n\t\"errors\"\n\t\"fmt\"\n\t\"log\"\n\t\"os\"\n)\n\n// Various errors the driver might return. Can change between driver versions.\nvar (\n\tErrInvalidConn       = errors.New(\"invalid connection\")\n\tErrMalformPkt        = errors.New(\"malformed packet\")\n\tErrNoTLS             = errors.New(\"TLS requested but server does not support TLS\")\n\tErrCleartextPassword = errors.New(\"this user requires clear text authentication. If you still want to use it, please add 'allowCleartextPasswords=1' to your DSN\")\n\tErrNativePassword    = errors.New(\"this user requires mysql native password authentication\")\n\tErrOldPassword       = errors.New(\"this user requires old password authentication. If you still want to use it, please add 'allowOldPasswords=1' to your DSN. See also https://github.com/go-sql-driver/mysql/wiki/old_passwords\")\n\tErrUnknownPlugin     = errors.New(\"this authentication plugin is not supported\")\n\tErrOldProtocol       = errors.New(\"MySQL server does not support required protocol 41+\")\n\tErrPktSync           = errors.New(\"commands out of sync. You can't run this command now\")\n\tErrPktSyncMul        = errors.New(\"commands out of sync. Did you run multiple statements at once?\")\n\tErrPktTooLarge       = errors.New(\"packet for query is too large. Try adjusting the `Config.MaxAllowedPacket`\")\n\tErrBusyBuffer        = errors.New(\"busy buffer\")\n\n\t// errBadConnNoWrite is used for connection errors where nothing was sent to the database yet.\n\t// If this happens first in a function starting a database interaction, it should be replaced by driver.ErrBadConn\n\t// to trigger a resend. Use mc.markBadConn(err) to do this.\n\t// See https://github.com/go-sql-driver/mysql/pull/302\n\terrBadConnNoWrite = errors.New(\"bad connection\")\n)\n\nvar defaultLogger = Logger(log.New(os.Stderr, \"[mysql] \", log.Ldate|log.Ltime))\n\n// Logger is used to log critical error messages.\ntype Logger interface {","sourceCodeStart":7,"sourceCodeEnd":43,"githubUrl":"https://github.com/go-sql-driver/mysql/blob/03d76c7e07908e255ce62d126d07ede3f2365d86/errors.go#L7-L43","documentation":"ErrUnknownPlugin is returned from auth() (auth.go:342) when the server's negotiated authentication plugin is not one the driver implements (caching_sha2_password, mysql_native_password, mysql_old_password, mysql_clear_password, sha256_password, client_ed25519). The unknown plugin name is logged before the error is returned.","triggerScenarios":"An auth-switch request from the server to a plugin the driver has no handler for, or an initial handshake advertising an exotic/proprietary plugin; also when a newer server defaults to a plugin added after this driver version.","commonSituations":"Connecting to a server using a custom or commercial auth plugin; running an older driver against a newer server that introduced a new default plugin; MariaDB ed25519 accounts without client_ed25519 support compiled/enabled.","solutions":["Upgrade go-sql-driver/mysql to a version that supports the plugin the server is requesting.","Change the account's auth plugin to one the driver supports (e.g. caching_sha2_password or mysql_native_password).","Check the driver log line (\"unknown auth plugin: <name>\") to identify exactly which plugin is missing.","For MariaDB ed25519, ensure you are on a driver version with client_ed25519 support."],"exampleFix":"// before: older driver, server account uses a plugin the driver lacks\n//   auth switch -> \"unknown auth plugin: auth_pam_compat\"\n\n// after: modernize the account to a supported plugin\n//   ALTER USER 'user'@'%' IDENTIFIED WITH 'caching_sha2_password' BY 'pass';\n// and/or upgrade the module:\n//   go get github.com/go-sql-driver/mysql@latest","handlingStrategy":"type-guard","validationCode":"// Before relying on a connection, probe the account's plugin so you can\n// fail fast with a clear message instead of a generic auth error.\n// (Run once per environment against an admin connection.)\n//   SELECT plugin FROM mysql.user WHERE user='app';","typeGuard":"func isUnknownPlugin(err error) bool {\n    return errors.Is(err, mysql.ErrUnknownPlugin)\n}","tryCatchPattern":"if errors.Is(err, mysql.ErrUnknownPlugin) {\n    // log includes \"unknown auth plugin: <name>\"; upgrade the driver or\n    // change the account to a supported plugin, then retry.\n}","preventionTips":["Pin a recent go-sql-driver/mysql version that supports your server's plugins.","Standardize account auth plugins across environments.","Watch the driver's critical log lines — the unknown plugin name is printed there."],"tags":["authentication","compatibility","config"],"backgroundTag":null,"analyzedSha":"03d76c7e07908e255ce62d126d07ede3f2365d86","analyzedAt":"2026-08-07T10:39:17.340Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}