Redis ACL Rule Decoder

Paste an ACL line, from a config file or an ACL SETUSER command, and see what each rule does and what the user ends up with. Both the user prefix and bare rules are accepted.

Paste below, or drop a file anywhere on this panel

Or drop a file anywhere on this panel. Nothing is uploaded: the analysis runs in this tab.

The answer appears here

Paste on the left and press Decode. Nothing leaves this tab.

Examples

Real input you can load into the tool above. Each one shows a different thing going wrong, because that is what the tool is for.

An application user

What each rule contributes, and what the user ends up able to do

user app on >s3cret ~app:* +@read +@write

Order reverses the meaning

A rule set that reads as restrictive and grants everything

user ops on >s3cret ~* -@dangerous +@all

Common mistakes

These are the ones that fail silently. The config is accepted, nothing raises an error, and the consequence arrives later.

  1. Writing `-@dangerous +@all`

    Rules apply strictly left to right, so `+@all` overwrites the revocation and the user has every command. ACL GETUSER shows the resulting permissions rather than the mistake.

    Instead:`+@all -@dangerous`. Grant first, subtract after.

  2. Granting commands without a key pattern

    Keys and commands are independent axes. The user can run everything and touch nothing, and the NOPERM error names the key, which sends people looking in the wrong place.

    Instead:Add `~pattern` alongside the command rules.

  3. Reading nopass as no access

    It means ANY password authenticates, including an empty one. It is unrestricted access for anyone who can reach the port.

    Instead:`off` disables a user. `nopass` opens it.

Rules apply left to right, and that is the whole difficulty

An ACL is not a set of permissions, it is a sequence of edits to one. The order decides the result, and the result is what Redis enforces regardless of how the sequence reads.

+@all after a revocation undoes it

-@dangerous +@all grants everything, because +@all came last. +@all -@dangerous is the restrictive one. Nothing warns about the first form, and ACL GETUSER shows the resulting permission set rather than the mistake, so reviewing the output does not catch it either.

Keys, channels and commands are three independent axes

A user with +@all and no ~ pattern can run every command and touch no keys. The resulting error is NOPERM naming the key, which reads as a key problem rather than a missing grant, and sends people to the wrong place. Since Redis 7.0 the same applies to channels, because acl-pubsub-default changed to resetchannels.

nopass is not the same as no access

nopass means ANY password authenticates, including an empty one. It is unrestricted access for anyone who can reach the port, not a locked account. off is the locked one.

The password forms differ in what leaks

The > form takes clear text, which then exists in the config file, in shell history if it was typed, and in any log that captured the command. The # form takes a SHA-256 hash, so the clear text never appears. ACL GETUSER shows existing password hashes, which is how you convert without knowing the original.

What this cannot see

It reads the rules you paste. It does not know which commands are in which category on your server version, since categories gain commands as Redis adds them, and it cannot tell you whether a key pattern matches your actual keys. ACL DRYRUN on a real server answers the specific question of whether a given user may run a given command on a given key.

More redis tools

Redis Hash Slot Calculator Which of the 16,384 slots does this key land in? Redis Hash Tag Tester Will these keys survive a multi-key command? Redis RESP Protocol Decoder Read what the server actually sent Redis RESP2 vs RESP3 Reply Decoder What the same reply looks like on each protocol Redis Command to RESP Exactly what your client puts on the socket Redis Glob Pattern Tester Redis globs are not shell globs Redis Connection URL Parser The path is the database number Redis Memory Unit Converter 1g and 1gb are not the same number Redis TTL Converter -1 and -2 are not durations Redis Stream ID Parser The first half is a millisecond timestamp redis.conf Validator Will Redis start with this file? Redis Production Config Linter The settings that cause incidents redis.conf to CONFIG SET Which of these can you change without a restart? Redis ACL Validator Find the rule that does nothing Redis INFO Analyzer The numbers INFO does not print Redis SLOWLOG Analyzer What blocked everyone else Redis CLUSTER NODES Parser Read the topology, and find the gap Redis Cluster Slot Distribution Who owns how much, and what is missing Redis Keyspace Notification Flags Why your events never arrive Redis Memory Calculator The encoding decides, not the data Redis Key Count to Memory The fixed cost per key Redis Encoding Threshold Calculator One field more, several times the memory Redis Bitmap Memory Calculator Sized by the highest bit, not the set ones Redis HyperLogLog Calculator 12 KB whether you count a thousand or a billion Redis Cluster Sizing Only 60% of each node is usable Redis RDB and AOF Size Calculator The fork needs memory, not disk Redis Replication Bandwidth Calculator How long the backlog actually covers Redis Connection Pool Calculator More connections is not more throughput Redis Pipeline Calculator It removes round trips, not work Redis Cache Hit Rate Calculator 99% to 90% is ten times the backend load Redis Eviction Policy Simulator volatile- with no TTLs is noeviction Redis Cost Estimator Your rates, so nothing goes stale Redis Config File Generator A redis.conf with the reasons in it Redis ACL Generator A user that can do exactly one job Redis Maxmemory Config Generator The limit, and the headroom it needs Redis Persistence Config Generator How much you can afford to lose Redis Lua Script Generator Atomic, and short enough to stay that way Redis TLS Config Generator Encrypted, and the old port actually closed Redis Sentinel Config Generator Failover that can actually be authorised Redis Cluster Config Generator Three primaries, and the bus port open Redis Docker Compose Generator Local Redis that is not on the internet Redis Client Config Generator Timeouts on both sides, and a sane pool Redis MEMORY STATS Analyzer Which number actually matters Redis Bigkeys Output Analyzer Elements are not bytes Redis CLIENT LIST Analyzer Find the connection hurting you Redis LATENCY Report Analyzer An empty report may mean nothing was recorded Redis Keyspace Prefix Analyzer Which key family is growing Redis SET Command Builder A plain SET clears the TTL Redis ZRANGE Query Builder REV reverses the argument order Redis SCAN Iteration Planner COUNT is a hint, not a page size Redis Key Name Validator Legal is not the same as workable Redis Cluster Compatibility Checker Works now, breaks when you shard

Elsewhere on the site