## TL;DR

Every client must connect with TLS enabled. Over RESP it is the password for the default_ro user and can only run read commands.

## Steps

1. TLS is on and cannot be turned off. Every client must connect with
 TLS enabled.
2. There is no separate password. The token from the console Connect tab
 is the password. When a client asks for a password, paste the token.

2. The console also offers a read-only token. Over RESP it is the password
for the default_ro user and can only run read commands.

## When to use

You are seeing this: TLS is on and cannot be turned off. Use this skill when you run into "ioredis, redis-py, jedis, phpredis with Upstash: TLS always on, token is the password".

## When not to use

If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.

## Versions

No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.

## Why this happens

The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.
