go-sql-driver/mysql · error
this user requires mysql native password authentication
Error message
this user requires mysql native password authentication
What it means
ErrNativePassword is returned from auth() (auth.go:306) when the server requires the mysql_native_password plugin but the DSN explicitly disabled it (allowNativePasswords=false). Because AllowNativePasswords defaults to true (dsn.go:97), this error only appears when an operator deliberately turned native auth off.
Solutions
- Remove allowNativePasswords=false (or set it true) so the driver can answer the native-password challenge.
- Upgrade/switch the account to caching_sha2_password (MySQL 8+) so native auth is genuinely unnecessary.
- Keep the flag disabled only if every reachable server is caching_sha2_password-capable.
Example fix
// before dsn := "user:pass@tcp(mysql57:3306)/db?allowNativePasswords=false" // -> ErrNativePassword // after dsn := "user:pass@tcp(mysql57:3306)/db"
Defensive patterns
Strategy: validation
Validate before calling
// Do not disable native auth unless every target server is // caching_sha2_password-only. dsn := "user:pass@tcp(host:3306)/db" // omit allowNativePasswords=false unless you have verified the server
Type guard
func isNativePasswordDenied(err error) bool {
return errors.Is(err, mysql.ErrNativePassword)
} Try / catch
if errors.Is(err, mysql.ErrNativePassword) {
// remove allowNativePasswords=false from the DSN, or switch the
// account to caching_sha2_password, then retry.
} Prevention
- Leave allowNativePasswords at its default (true) for MySQL 5.x / MariaDB.
- Audit DSNs copied between environments for hardened flags that don't apply.
- Standardize on caching_sha2_password before disabling native auth.
When it happens
Trigger: Connecting with allowNativePasswords=false in the DSN to a server/account whose auth plugin is mysql_native_password (the historical default for MySQL < 8.0 and all MariaDB releases).
Common situations: Hardening a DSN by disabling native passwords in anticipation of caching_sha2_password-only servers, then pointing it at an older MySQL 5.7 or MariaDB instance; copying a hardened DSN between environments with different server versions.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- this authentication plugin is not supported
- invalid max_allowed_packet value
- this user requires clear text authentication. If you still…
- this user requires old password authentication. If you…
- invalid compressed packet: uncompressed length in header is
AI-assisted analysis of go-sql-driver/mysql@03d76c7e07 (2026-08-07).
Data as JSON: /api/errors/add5c07c672be97c.
Report an issue: GitHub.
Appendix: source
Thrown at errors.go:23
// This Source Code Form is subject to the terms of the Mozilla Public
// License, v. 2.0. If a copy of the MPL was not distributed with this file,
// You can obtain one at http://mozilla.org/MPL/2.0/.
package mysql
import (
"errors"
"fmt"
"log"
"os"
)
// Various errors the driver might return. Can change between driver versions.
var (
ErrInvalidConn = errors.New("invalid connection")
ErrMalformPkt = errors.New("malformed packet")
ErrNoTLS = errors.New("TLS requested but server does not support TLS")
ErrCleartextPassword = errors.New("this user requires clear text authentication. If you still want to use it, please add 'allowCleartextPasswords=1' to your DSN")
ErrNativePassword = errors.New("this user requires mysql native password authentication")
ErrOldPassword = errors.New("this user requires old password authentication. If you still want to use it, please add 'allowOldPasswords=1' to your DSN. See also https://github.com/go-sql-driver/mysql/wiki/old_passwords")
ErrUnknownPlugin = errors.New("this authentication plugin is not supported")
ErrOldProtocol = errors.New("MySQL server does not support required protocol 41+")
ErrPktSync = errors.New("commands out of sync. You can't run this command now")
ErrPktSyncMul = errors.New("commands out of sync. Did you run multiple statements at once?")
ErrPktTooLarge = errors.New("packet for query is too large. Try adjusting the `Config.MaxAllowedPacket`")
ErrBusyBuffer = errors.New("busy buffer")
// errBadConnNoWrite is used for connection errors where nothing was sent to the database yet.
// If this happens first in a function starting a database interaction, it should be replaced by driver.ErrBadConn
// to trigger a resend. Use mc.markBadConn(err) to do this.
// See https://github.com/go-sql-driver/mysql/pull/302
errBadConnNoWrite = errors.New("bad connection")
)
var defaultLogger = Logger(log.New(os.Stderr, "[mysql] ", log.Ldate|log.Ltime))
View on GitHub (pinned to 03d76c7e07)