TL;DR: MySQL 8 uses `caching_sha2_password` by default and your MCP server's MySQL client cannot speak it. Either switch the user back to `mysql_native_password`, or upgrade the server package to a client that supports the new plugin.

```text
Error: ER_NOT_SUPPORTED_AUTH_MODE: Client does not support authentication protocol requested by server; consider upgrading MySQL client
```

## Fix it

1. Option A, change the user's plugin (fastest, keeps the old client working):

```sql
ALTER USER 'appuser'@'%' IDENTIFIED WITH mysql_native_password BY 'yourpassword';
FLUSH PRIVILEGES;
```

2. Option B, upgrade the MCP server package so its MySQL client supports `caching_sha2_password`. Check the server repo for a version bump, reinstall, restart the client.

3. Restart the MCP client and retry.

   Expected: the server authenticates and tools work.

## When to use this

- The error names `caching_sha2_password` or says the client does not support the authentication protocol.
- You recently upgraded MySQL 5.7 to 8.x and the MCP server broke.

## When NOT to use this

- The error is plain `ER_ACCESS_DENIED_ERROR` with no plugin mentioned. That is wrong credentials.
- You are on MySQL 5.7 or MariaDB. The plugin default never changed there.

## Compatibility

- benborla/mcp-server-mysql and other Node mysql/mysql2-based MCP servers.
- MySQL 8.x.

## Why it happens

MySQL 8.0 flipped the default auth plugin to `caching_sha2_password`, which uses a different handshake. Older `mysql` npm clients predate it and fail the handshake entirely. The server is reachable and the password is right; the two sides just cannot complete the auth protocol.

## Edge cases

- `mysql_native_password` is weaker and deprecated. Prefer upgrading the client for anything facing a network.
- Changing the plugin requires re-setting the password in the same statement, or auth breaks differently.
- Managed MySQL 8 (RDS, Cloud SQL) also defaults to the new plugin. The ALTER USER fix works there too if you have privileges.