Illegal arguments: undefined, string 🔐 Authentication

bcrypt error: Illegal arguments: undefined, string / data and salt arguments required / data and hash arguments required

bcrypt.compare/hash received undefined — the password field or stored hash wasn’t passed.

Seen on: REST API

Meaning

The request body wasn’t parsed (missing express.json()), the field name differs (pass vs password), or the user query didn’t select the password column (select: false in Mongoose/Prisma omit).

Common causes

  • Body not parsed (no JSON/body middleware)
  • Field name mismatch
  • Password hash not selected from the database
  • User not found, hash undefined

⚡ Quick fix

  1. Add express.json() and validate input
  2. Explicitly select the password field (+password)
  3. Handle user-not-found before comparing

Detailed fix by platform

JavaScript

  1. `const user = await User.findOne({ email }).select("+password"); if (!user
  2. !password) return res.status(401).end(); const ok = await bcrypt.compare(password, user.password);`

How to diagnose

  1. Inputs — Values passed to compare
  2. Query — Password selected?
  3. Body — Parsed?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.