bcrypt error: Illegal arguments: undefined, string / data and salt arguments required / data and hash arguments required
bcrypt.compare/hash received undefined — the password field or stored hash wasn’t passed.
Seen on:
REST API
Meaning
The request body wasn’t parsed (missing express.json()), the field name differs (pass vs password), or the user query didn’t select the password column (select: false in Mongoose/Prisma omit).
Common causes
- Body not parsed (no JSON/body middleware)
- Field name mismatch
- Password hash not selected from the database
- User not found, hash undefined
⚡ Quick fix
- Add express.json() and validate input
- Explicitly select the password field (+password)
- Handle user-not-found before comparing
Detailed fix by platform
JavaScript
- `const user = await User.findOne({ email }).select("+password"); if (!user
- !password) return res.status(401).end(); const ok = await bcrypt.compare(password, user.password);`
How to diagnose
- Inputs — Values passed to compare
- Query — Password selected?
- Body — Parsed?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026