"password authentication failed": check the string before rotating
Shows how to fix "password authentication failed": check the string before rotating. Use it when you hit this exact problem. Skip it when your error message or symptom looks different.
TL;DR
For "FATAL: password authentication failed for user "[role]"": the password actually was reset (teammate rotated it, branch was recreated). The connection string was hand-edited and the password got truncated or mangled; special characters in generated passwords must be URL-encoded in the string.
FATAL: password authentication failed for user "[role]"Steps
- The connection string was hand-edited and the password got truncated or mangled; special characters in generated passwords must be URL-encoded in the string.
- Wrong role for the string: the password belongs to a different role than the one in the URL.
- The password actually was reset (teammate rotated it, branch was recreated).
- - Use the Console-copied string verbatim; URL-encode special characters if you must embed the password manually.
- Store it in a secret manager, not pasted across chat and docs.
- If it really was rotated, update every deployment that uses it, then verify each.
When to use
You are seeing this: FATAL: password authentication failed for user "[role]". Use this skill when you run into ""password authentication failed": check the string before rotating".
When not to use
If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.
Versions
No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.
Why this happens
The connection string was hand-edited and the password got truncated or mangled; special characters in generated passwords must be URL-encoded in the string.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.