Redis MCP: WRONGPASS (Upstash REST token pasted as the Redis password)
Fixes the Redis MCP server failing with WRONGPASS when the configured password does not match the Redis server. Common causes are a stale password, a REST token pasted where the Redis password belongs (Upstash), or the wrong ACL username. The fix is correcting the credential value. Use when auth is attempted but rejected; not for NOAUTH.
TL;DR: WRONGPASS means a password was sent but the server rejected it. On Upstash the classic cause is pasting the REST token where the Redis password goes. They are different credentials on the same page. Re-copy the password from the Redis/TCP section and update REDIS_PWD.
WRONGPASS invalid username-password pair or user is disabled.Fix it
- Verify the password directly, bypassing the MCP layer:
redis-cli -u "rediss://your-endpoint:6379" ping Expected: PONG. If you get WRONGPASS here, the value is wrong, not the MCP server.
- On Upstash: open the database Details page and copy from the Redis/TCP section, not the REST section. The REST token and the Redis password are different strings. Build
rediss://:PASSWORD@ENDPOINT:PORT.
- On Redis Cloud: same idea. Copy the connection details from the Connect wizard, and note the port is a per-database high port, not always 6379.
- Update
REDIS_PWD(andREDIS_USERNAMEif ACLs) in the server env and restart.
Expected: WRONGPASS is gone, tools work.
When to use this
WRONGPASSon every command, especially with Upstash or Redis Cloud.- It worked before and stopped after a credential rotation.
When NOT to use this
- The error is
NOAUTH. No password is being sent at all. Set one instead of fixing the value. - The error is
NOPERM. Auth succeeded; the ACL user lacks permission for the command.
Compatibility
- redis/mcp-redis against Upstash, Redis Cloud, or self-hosted Redis with ACLs/requirepass.
Why it happens
Managed Redis consoles show several credentials side by side: REST tokens, Redis passwords, connection strings for different protocols. They look interchangeable but are not. The TCP password authenticates the Redis protocol; the REST token authenticates the HTTP API. Swapping them produces WRONGPASS every time, and the error gives no hint which credential you used.
Edge cases
- After rotating a password on the provider, the old one stops working immediately. Update the MCP env at the same time.
- Redis Cloud free tiers sometimes show a placeholder port. Always copy the port from the panel.
- If
defaultuser is disabled under RBAC, use a data-access role username and password from Access Control instead.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.