spring-projects/spring-security · error · IllegalArgumentException
The name of the password encoder is improperly formatted or…
Error message
The name of the password encoder is improperly formatted or incomplete. The format should be '%sENCODER%spassword'.
What it means
The stored password contains the prefix or suffix somewhere but is not a well-formed '{id}password' string (e.g. prefix present without suffix, or suffix before prefix). The id cannot be extracted, so the fallback matcher throws this IllegalArgumentException describing the required format.
Solutions
- Rewrite the stored value as a complete '{id}encodedPassword' string and verify it parses (extract the id between '{' and first '}')
- Check whether the column length truncated the value and widen the column, then re-encode the password
- Regenerate the credential using delegatingPasswordEncoder.encode(rawPassword) so the format is guaranteed correct
- Check for accidental double braces and strip the extra layer
Example fix
// before
// stored (truncated): '{bcrypt$2a$10$dXJ3'
// after
// stored: '{bcrypt}$2a$10$dXJ3SW6G7P50lGmMkkmwe.20cQQubK3.HZWzG3YB1tlRy.fqvM/BG'
Defensive patterns
Strategy: validation
Validate before calling
boolean wellFormed = storedPassword != null
&& storedPassword.startsWith("{")
&& storedPassword.indexOf('}') > 1;
if (!wellFormed) {
log.warn("Malformed stored password, missing {id} wrapper");
} Try / catch
try {
return encoder.matches(rawPassword, storedPassword);
} catch (IllegalArgumentException e) {
log.error("Stored password not in '{id}password' format: {}", e.getMessage());
return false;
} Prevention
- Never hand-edit or truncate stored password values; check column length (>= 100 chars recommended)
- Generate stored passwords only via delegatingPasswordEncoder.encode()
- Validate format at import/seed time: starts with '{', contains '}', id between them non-empty
When it happens
Trigger: matches() with a prefixEncodedPassword such as '{bcrypt$2a$...' (missing '}'), 'bcrypt}...' (missing '{'), or '{bcrypt' — strings where indexOf(idPrefix) or indexOf(idSuffix) checks pass individually but no valid '{id}' segment exists.
Common situations: Manual string manipulation/truncation of stored passwords (column length limits cutting off the tail); accidental double-prefixing like '{{noop}secret'; encoding artifacts or data corruption in the credentials column.
Understand the failure class
Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.
Related errors
- Given that there is no default password encoder configured…
- There is no password encoder mapped for the id
- A Bean named mvcHandlerMappingIntrospector of type…
- A Bean named mvcHandlerMappingIntrospector of type…
- A filter chain that matches any request
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/707216669d6e9854.
Report an issue: GitHub.
Appendix: source
Thrown at crypto/src/main/java/org/springframework/security/crypto/password/DelegatingPasswordEncoder.java:307
@Override
protected String encodeNonNullPassword(String rawPassword) {
throw new UnsupportedOperationException("encode is not supported");
}
@Override
protected boolean matchesNonNull(String rawPassword, String prefixEncodedPassword) {
String id = extractId(prefixEncodedPassword);
if (id != null && !id.isBlank()) {
throw new IllegalArgumentException(String.format(NO_PASSWORD_ENCODER_MAPPED, id));
}
if (prefixEncodedPassword != null && !prefixEncodedPassword.isBlank()) {
int start = prefixEncodedPassword.indexOf(DelegatingPasswordEncoder.this.idPrefix);
int end = prefixEncodedPassword.indexOf(DelegatingPasswordEncoder.this.idSuffix, start);
if (start < 0 && end < 0) {
throw new IllegalArgumentException(NO_PASSWORD_ENCODER_PREFIX);
}
}
throw new IllegalArgumentException(String.format(MALFORMED_PASSWORD_ENCODER_PREFIX,
DelegatingPasswordEncoder.this.idPrefix, DelegatingPasswordEncoder.this.idSuffix));
}
}
}
View on GitHub (pinned to 96852e8860)