Change a MySQL User Password with ALTER USER
Change your own or another MySQL account password with ALTER USER, and rotate application credentials safely.
When changing a MySQL account password, identify the exact user@host account and every application that uses it. A password change does not update credentials stored in applications, connection pools, or scheduled jobs. See the MySQL 8.4 ALTER USER reference.
Reset an account password as an administrator
Use an administrator account with permission to alter MySQL users. On MySQL 8.0.18 and later, including MySQL 8.4, ask MySQL to generate a random password:
ALTER USER 'app_user'@'localhost' IDENTIFIED BY RANDOM PASSWORD;
MySQL returns the generated password in the result set. Store it in your password manager or application secret store, then update every application that connects as this account. Do not put the generated value in source code or commit it to a repository.
Replace 'app_user'@'localhost' with the exact account to change. MySQL accounts are identified by both user and host; changing 'app_user'@'localhost' does not change a separate account such as 'app_user'@'%'.
If you must choose the password yourself, use a unique secret and protect the SQL statement from shell history, client history, and server logs:
ALTER USER 'app_user'@'localhost' IDENTIFIED BY 'replace-with-a-unique-secret';
The quoted value is a placeholder; replace it before running the statement. MySQL warns that cleartext password statements can be recorded in logs or client history under some circumstances. See MySQL password logging guidance.
Change your own password
If your account is permitted to change its own password, you can refer to the authenticated account without typing its name:
ALTER USER USER() IDENTIFIED BY RANDOM PASSWORD;
Save the generated password before closing the session, then reconnect with it. To verify which account MySQL authenticated, run:
SELECT CURRENT_USER();
For an account that is locked, follow the MySQL account-locking tutorial; changing its password alone does not unlock it.
Rotate an application password with less disruption
On MySQL versions that support dual passwords, an administrator can retain the old password while applications move to the new one:
ALTER USER 'app_user'@'localhost'
IDENTIFIED BY RANDOM PASSWORD
RETAIN CURRENT PASSWORD;
MySQL returns the new password. Store it securely and roll it out to every application instance. Both the old and new passwords work during the transition. After confirming that all clients use the new value, remove the old password:
ALTER USER 'app_user'@'localhost' DISCARD OLD PASSWORD;
Retaining or discarding a secondary password requires the appropriate account-management privileges. See the MySQL 8.4 ALTER USER documentation.
Avoid outdated password changes
Do not update mysql.user directly or call PASSWORD() to build a password hash. MySQL recommends account-management statements such as ALTER USER; PASSWORD() was removed in MySQL 8.0.11. You do not need FLUSH PRIVILEGES after a successful ALTER USER statement. See MySQL 8.0 changes and the SET PASSWORD reference, which notes that ALTER USER is preferred.
For creating a new account, see MySQL CREATE USER. For other account administration tasks, browse MySQL user and privilege tutorials.