MySQL Error 1524: Plugin 'mysql_native_password' Is Not Loaded
Fix MySQL Error 1524 on MySQL 8.4 by switching accounts to caching_sha2_password, or temporarily enable the deprecated plugin while migrating.
On this page
MySQL Error 1524 with the message Plugin 'mysql_native_password' is not loaded means the server cannot use that authentication plugin for the requested account operation. A common cause is MySQL 8.4, where mysql_native_password is disabled by default. The plugin is removed in MySQL 9.0, so switching accounts to caching_sha2_password is the durable fix. See Oracle’s native authentication documentation and Error 1524 reference.
Confirm the server version and account plugin
Check which server you reached:
SELECT VERSION();
An administrator can inspect the authentication plugin configured for an account:
SELECT User, Host, plugin
FROM mysql.user
WHERE User = 'app_user';
Replace app_user with the affected MySQL account and confirm the matching Host row. Querying mysql.user requires administrative access. Do not share query output that includes account names or other sensitive details publicly.
In MySQL 8.4, accounts configured with mysql_native_password cannot use the disabled server-side plugin. CREATE USER or ALTER USER statements that request this plugin can return Error 1524. In MySQL 9.0, the plugin has been removed entirely; enabling it is not an option.
Preferred fix: use caching_sha2_password
For a new account, use MySQL 8.4’s default authentication plugin and let MySQL generate the password:
CREATE USER 'app_user'@'localhost'
IDENTIFIED WITH caching_sha2_password BY RANDOM PASSWORD;
MySQL returns the generated password once. Save it in a secret manager and configure the application with it. This syntax requires MySQL 8.0.18 or later.
For an existing account, an administrator can change its authentication plugin and generate a replacement password:
ALTER USER 'app_user'@'localhost'
IDENTIFIED WITH caching_sha2_password BY RANDOM PASSWORD;
Use the exact account host from the server’s grant table. Changing the password invalidates the old credential, so coordinate updating application secrets and connection pools. The client library must support caching_sha2_password; for the first connection after a password change, use TLS or the documented RSA password exchange. See Caching SHA-2 authentication and encrypted connections.
If the client cannot use caching_sha2_password, update its driver or connector before changing the account. For broader post-upgrade checks, see how to upgrade MySQL 8.0 to 8.4 LTS and the guide to MySQL Error 1045: Access denied.
Temporary compatibility option for MySQL 8.4
If a legacy application cannot be updated immediately, MySQL 8.4 can temporarily enable its built-in mysql_native_password server plugin. Add this option to the server configuration file:
[mysqld]
mysql_native_password=ON
Restart MySQL using the service manager for your platform, then retry the account operation. This restores a deprecated authentication method and requires a server restart. Use it only as a short migration bridge while updating clients and accounts. MySQL 9.0 removes the plugin, so this workaround cannot carry forward to that release.
Do not edit mysql.user directly to change an account’s authentication plugin. Use ALTER USER after the server-side plugin is available, or move the account to caching_sha2_password as described above. For password changes, see the MySQL account password guide.
Distinguish related authentication errors
- Error 1524 while creating or altering an account: the requested server-side plugin is not loaded. In MySQL 8.4, check whether
mysql_native_passwordis disabled. - Error 1045 while connecting: the server rejected the account or credentials. Check the matching
user@host, password, grants, and client authentication support; see Error 1045 troubleshooting. - A client-side plugin-loading error with a different code: check the complete client error and update the client library. It is not necessarily the same server-side Error 1524 condition.