MySQL MCP: using password NO (MYSQL_* vars set in shell, not client env block)
Fixes the MySQL MCP server ignoring credentials because MYSQL_USER and MYSQL_PASS were set in the shell instead of the client config. MCP clients spawn servers with a clean environment, so shell exports are invisible. The fix is putting all MYSQL_* vars in the client's env block. Use when the server behaves as if no credentials were given; not for wrong-password errors.
TL;DR: You exported MYSQL_PASS in your terminal, but the MCP server never saw it. MCP clients launch servers with a clean environment. Put every MYSQL_* variable in the client config's env block instead.
ER_ACCESS_DENIED_ERROR: Access denied for user 'appuser'@'host' (using password value NO)(The tell is using password value NO even though you set one.)
Fix it
- Move all five variables into the server's
envblock in your client config:
{
"mcpServers": {
"mysql": {
"command": "npx",
"args": ["-y", "mcp-server-mysql"],
"env": {
"MYSQL_HOST": "YOUR_MYSQL_HOST",
"MYSQL_PORT": "3306",
"MYSQL_USER": "appuser",
"MYSQL_PASS": "yourpassword",
"MYSQL_DB": "mydb"
}
}
}
}- Fully quit and restart the client. Servers spawn at client launch.
Expected: (using password value YES) in any subsequent error, and with correct values, a working connection.
When to use this
- The error says
using password value NObut you definitely set a password somewhere. echo $MYSQL_PASSworks in your terminal but the server acts like it is empty.- You are on Windows, where GUI-launched servers do not inherit terminal env at all.
When NOT to use this
- The error says
using password value YESand still denies access. The value is reaching the server but is wrong. - The error is
ECONNREFUSEDorUnknown database. Those are host and database problems.
Compatibility
- benborla/mcp-server-mysql and any env-configured MCP database server.
- Claude Desktop, Claude Code, Cursor, Windsurf.
Why it happens
export affects your shell and its children. The MCP client is not your shell's child (especially GUI apps), so it never sees those variables, and the server it spawns inherits the client's clean environment. The env block exists precisely to bridge this gap.
Edge cases
- JSON-escape backslashes and double quotes inside passwords in the config file.
- If you use a secrets manager or 1Password-style env injection, make sure the injection applies to the client process, not just your terminal.
- After moving the vars, unset the shell exports to avoid confusion about which value is live.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.