MySQL Error 1045: Access Denied for User (28000)
Fix MySQL Error 1045 by checking the password, user@host account, server and protocol, and account authentication or lock status.
On this page
MySQL Error 1045 (28000, ER_ACCESS_DENIED_ERROR) means the server rejected the connection during authentication. A common message is:
ERROR 1045 (28000): Access denied for user 'app_user'@'localhost' (using password: YES)
using password: YES means the client sent a password; it does not mean the password was correct. The MySQL 8.4 error reference lists the code and message.
Run a local connection triage
Use this decision helper to separate authentication failures—including server-side Error 1524 and client-side Error 2059—from connection and database-privilege errors. It asks only which error code appeared, whether the message says a password was sent, and how the client connects. The choices stay in your browser; the helper does not ask for credentials, host names, or SQL and does not send the selections to analytics.
MySQL connection error triage
Confirm which server and account the client is reaching
Check the host, port, user name, and connection method in the application or MySQL client. For an interactive command-line login, specify the password option without putting the password in the command:
mysql --host=db.example.com --port=3306 --user=app_user --password
The client prompts for the password. MySQL recommends prompting rather than exposing the password on the command line in its password security guidance.
MySQL accounts include both a user name and a host. An account named 'app_user'@'localhost' is distinct from 'app_user'@'%'; a grant or password change for one account does not necessarily apply to the other. On Unix-like systems, classic MySQL clients usually connect to localhost through a socket, while 127.0.0.1 uses TCP. Changing the host can therefore change which account MySQL matches. See the MySQL connection transport documentation.
To check whether a local connection is failing because the client chose a different transport, you can explicitly try TCP:
mysql --host=localhost --port=3306 --protocol=TCP --user=app_user --password
This forces TCP even when the host is localhost; it does not bypass authentication and may cause MySQL to match a different user@host account. The client prompts for the password. See the --protocol connection option.
Check credentials and account settings
If the host, port, and user are correct, verify the password through the client’s prompt or protected secret configuration. Avoid printing secrets into shell history, logs, or support messages.
If the password may be wrong or the account may not exist, ask a database administrator to check the exact user@host account. MySQL connection verification checks the user, client host, credentials, and authentication plugin; an administrator can inspect the account with SHOW CREATE USER and reset it with ALTER USER if appropriate. Update the application’s stored secret at the same time as any password reset.
If this began after upgrading to MySQL 8.4, check the account’s authentication plugin as well as the client connector version. MySQL 8.4 disables mysql_native_password by default; an existing account using it can fail to connect with Error 1045. Error 1524 instead appears when an account operation requests the unloaded server plugin, while Error 2059 means the client library could not load a client-side plugin. See Error 1524 troubleshooting and Error 2059 troubleshooting.
After a connection succeeds, SELECT USER(), CURRENT_USER(); can help confirm the client identity and the account MySQL authenticated. CURRENT_USER() reports the account that determines the session’s privileges; it may differ from USER().
If the server explicitly reports that the account is locked, follow the MySQL account-locking tutorial instead of treating the message as a password mismatch.
Distinguish Errors 2003, 1045, 1130, and 1044
- Error 2003 (
CR_CONN_HOST_ERROR): the client cannot connect to the specified server and port. Check the network route before investigating passwords; see MySQL Error 2003 troubleshooting. - Error 1045 (
28000): the server rejected account authentication. Check the username, host-specific account, credentials, authentication plugin, and lock status. - Error 1130 (
HY000): the server says the client host is not allowed to connect. Check which host the server sees and whether a MySQL'user'@'host'account matches it; see MySQL Error 1130 troubleshooting. - Error 1044 (
42000): the account connected, but lacks a privilege required to access a database. See MySQL Error 1044 troubleshooting.
Granting database privileges does not fix a wrong password or an unmatched client host. For user creation syntax, see the MySQL CREATE USER tutorial. Browse more fixes in MySQL error troubleshooting.