MySQL ERROR 1045 (28000): Access denied for user
MySQL rejected the login — wrong password, wrong user/host combination, or the user doesn’t exist.
Meaning
MySQL accounts are user@host pairs. 'app'@'localhost' and 'app'@'%' are different accounts with possibly different passwords. The message tells you which host MySQL matched and whether a password was sent (“using password: YES/NO”).
Common causes
- Wrong password (or special characters mangled by the shell/config)
- User exists for a different host (
localhostvs127.0.0.1vs%) - “using password: NO” — the app didn’t send any password (empty env var)
- Root uses
auth_socketon Ubuntu, so password login fails - Docker: connecting to
localhostinstead of the DB container hostname - User was created but privileges not granted on the database
⚡ Quick fix
- Check “using password: YES/NO” — NO means your config is empty
- Log in as root and list accounts:
SELECT user, host, plugin FROM mysql.user; - Create/alter the user for the exact host the app connects from
- Grant privileges on the database
- In Docker, use the service name as host (e.g.
db)
Detailed fix by platform
MySQL
- Create or fix the user (MySQL 8 / MariaDB):sql
CREATE USER IF NOT EXISTS 'app'@'localhost' IDENTIFIED BY 'StrongPass!23'; ALTER USER 'app'@'localhost' IDENTIFIED BY 'StrongPass!23'; GRANT ALL PRIVILEGES ON appdb.* TO 'app'@'localhost'; FLUSH PRIVILEGES;
Linux
- Ubuntu root via socket:
sudo mysqlworks without a password; use it to create a separate app user instead of using root.
PHP
- Check the DSN host and that
.envvalues are loaded (Laravel:php artisan config:clearafter editing .env).
Docker
- Use
MYSQL_USER/MYSQL_PASSWORDenv vars on first start only — changing them later doesn’t update an existing data volume.
Code examples
Test exactly what the app uses
bash
mysql -h 127.0.0.1 -P 3306 -u app -p appdb-h localhost uses the Unix socket; -h 127.0.0.1 uses TCP — they can match different accounts.
How to diagnose
- Message — Which user@host, and password YES or NO?
- Accounts — Does that exact user@host exist?
- Password — Correct and not mangled by quoting?
- Privileges — Granted on the target database?
- Network — Right host (socket vs TCP vs container name)?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026