TL;DR: `WRONGPASS` means a password was sent but the server rejected it. On Upstash the classic cause is pasting the REST token where the Redis password goes. They are different credentials on the same page. Re-copy the password from the Redis/TCP section and update `REDIS_PWD`.

```text
WRONGPASS invalid username-password pair or user is disabled.
```

## Fix it

1. Verify the password directly, bypassing the MCP layer:

```bash
redis-cli -u "rediss://your-endpoint:6379" ping
```

   Expected: `PONG`. If you get WRONGPASS here, the value is wrong, not the MCP server.

2. On Upstash: open the database Details page and copy from the **Redis/TCP** section, not the REST section. The REST token and the Redis password are different strings. Build `rediss://:PASSWORD@ENDPOINT:PORT`.

3. On Redis Cloud: same idea. Copy the connection details from the Connect wizard, and note the port is a per-database high port, not always 6379.

4. Update `REDIS_PWD` (and `REDIS_USERNAME` if ACLs) in the server env and restart.

   Expected: WRONGPASS is gone, tools work.

## When to use this

- `WRONGPASS` on every command, especially with Upstash or Redis Cloud.
- It worked before and stopped after a credential rotation.

## When NOT to use this

- The error is `NOAUTH`. No password is being sent at all. Set one instead of fixing the value.
- The error is `NOPERM`. Auth succeeded; the ACL user lacks permission for the command.

## Compatibility

- redis/mcp-redis against Upstash, Redis Cloud, or self-hosted Redis with ACLs/requirepass.

## Why it happens

Managed Redis consoles show several credentials side by side: REST tokens, Redis passwords, connection strings for different protocols. They look interchangeable but are not. The TCP password authenticates the Redis protocol; the REST token authenticates the HTTP API. Swapping them produces WRONGPASS every time, and the error gives no hint which credential you used.

## Edge cases

- After rotating a password on the provider, the old one stops working immediately. Update the MCP env at the same time.
- Redis Cloud free tiers sometimes show a placeholder port. Always copy the port from the panel.
- If `default` user is disabled under RBAC, use a data-access role username and password from Access Control instead.