VectleSkillsMySQL MCP: Client does not support authentication protocol (caching_sha2_password)

MySQL MCP: Client does not support authentication protocol (caching_sha2_password)

Export

Fixes the MySQL MCP server failing against MySQL 8 with a caching_sha2_password auth plugin error. MySQL 8 changed the default auth plugin and older clients cannot speak it. The fix is switching the user to mysql_native_password or upgrading the client. Use when the error names the auth plugin; not for plain access-denied.

TL;DR: MySQL 8 uses caching_sha2_password by default and your MCP server's MySQL client cannot speak it. Either switch the user back to mysql_native_password, or upgrade the server package to a client that supports the new plugin.

Error: ER_NOT_SUPPORTED_AUTH_MODE: Client does not support authentication protocol requested by server; consider upgrading MySQL client

Fix it

  1. Option A, change the user's plugin (fastest, keeps the old client working):
ALTER USER 'appuser'@'%' IDENTIFIED WITH mysql_native_password BY 'yourpassword';
FLUSH PRIVILEGES;
  1. Option B, upgrade the MCP server package so its MySQL client supports caching_sha2_password. Check the server repo for a version bump, reinstall, restart the client.
  1. Restart the MCP client and retry.

Expected: the server authenticates and tools work.

When to use this

  • The error names caching_sha2_password or says the client does not support the authentication protocol.
  • You recently upgraded MySQL 5.7 to 8.x and the MCP server broke.

When NOT to use this

  • The error is plain ER_ACCESS_DENIED_ERROR with no plugin mentioned. That is wrong credentials.
  • You are on MySQL 5.7 or MariaDB. The plugin default never changed there.

Compatibility

  • benborla/mcp-server-mysql and other Node mysql/mysql2-based MCP servers.
  • MySQL 8.x.

Why it happens

MySQL 8.0 flipped the default auth plugin to caching_sha2_password, which uses a different handshake. Older mysql npm clients predate it and fail the handshake entirely. The server is reachable and the password is right; the two sides just cannot complete the auth protocol.

Edge cases

  • mysql_native_password is weaker and deprecated. Prefer upgrading the client for anything facing a network.
  • Changing the plugin requires re-setting the password in the same statement, or auth breaks differently.
  • Managed MySQL 8 (RDS, Cloud SQL) also defaults to the new plugin. The ALTER USER fix works there too if you have privileges.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=MySQL+MCP%3A+Client+does+not+support+authentication+protocol+%28caching_sha2_password%29&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.