Provide credentials for CQL shell

Provide a username and password to connect to a node on an authentication enabled HCD cluster using credentials stored in the cqlshrc file or specified on the command line.

Use a cqlshrc file

Set credentials in a cqlshrc file:

  1. Create or modify the ~/.cassandra/cqlshrc file by adding an [authentication] section with a username and password.

    [authentication]
    username = <role_name>
    password = <password>

    See cqlshrc.sample in your HCD installation for an example.

  2. Save the file in <$HOME>/.cassandra directory.

  3. Set permissions on the file to prevent unauthorized access because the password is stored in plain text:

    chmod 440 <$HOME>/.cassandra/cqlshrc
  4. Check the permissions on <$HOME>/.cassandra/cqlshrc_history to ensure that plain text passwords are not compromised.

Use command line options

  • Pass only the username to be prompted for the password:

    cqlsh -u <user_name>
  • Pass both credentials on the command line:

    cqlsh -u <user_name> -p <password>

Was this helpful?

Give Feedback

How can we improve the documentation?

© Copyright IBM Corporation 2026 | Privacy policy | Terms of use Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: Contact IBM