FasterXML/jackson-databind · error · IllegalArgumentException

Cannot use includeAs of

Error message

Cannot use includeAs of {} for Default Typing

What it means

Thrown by MapperBuilder.activateDefaultTyping(PolymorphicTypeValidator, DefaultTyping, JsonTypeInfo.As) when includeAs is JsonTypeInfo.As.EXTERNAL_PROPERTY. Default Typing cannot use external-property inclusion because the type metadata must be embedded alongside values globally; Jackson explicitly rejects this combination to make the limitation obvious.

Solutions

  1. Use one of the supported inclusion styles: JsonTypeInfo.As.WRAPPER_ARRAY (default), WRAPPER_OBJECT, or PROPERTY.
  2. If you genuinely need EXTERNAL_PROPERTY, configure it per-type via @JsonTypeInfo on the target type instead of global Default Typing.
  3. Use activateDefaultTyping(validator, applicability) (two-arg) to get the safe default WRAPPER_ARRAY.

Example fix

// before
builder.activateDefaultTyping(validator,
    DefaultTyping.NON_FINAL,
    JsonTypeInfo.As.EXTERNAL_PROPERTY);

// after
builder.activateDefaultTyping(validator,
    DefaultTyping.NON_FINAL,
    JsonTypeInfo.As.WRAPPER_ARRAY);
Defensive patterns

Strategy: validation

Validate before calling

JsonTypeInfo.As includeAs = JsonTypeInfo.As.EXTERNAL_PROPERTY; // from config
if (includeAs == JsonTypeInfo.As.EXTERNAL_PROPERTY) {
    includeAs = JsonTypeInfo.As.WRAPPER_ARRAY; // or reject
}
builder.activateDefaultTyping(validator, applicability, includeAs);

Prevention

When it happens

Trigger: Calling activateDefaultTyping(validator, applicability, JsonTypeInfo.As.EXTERNAL_PROPERTY) on a MapperBuilder.

Common situations: Migrating from per-type @JsonTypeInfo(use=Id.CLASS, include=As.EXTERNAL_PROPERTY) to global Default Typing and reusing the same As enum; copy-paste of an include-mode constant; misreading the docs about which As values are valid for default typing.

Related errors


AI-assisted analysis of FasterXML/jackson-databind@87876ca5c0 (2026-08-11). Data as JSON: /api/errors/3f403428c70655de. Report an issue: GitHub.

Appendix: source

Thrown at src/main/java/tools/jackson/databind/cfg/MapperBuilder.java:1785

     * and attempts of do so will throw an {@link IllegalArgumentException} to make
     * this limitation explicit.
     *<p>
     * NOTE: choice of {@link PolymorphicTypeValidator} to configure is of
     * crucial importance to security when deserializing untrusted content:
     * this because allowing deserializing of any type can lead to malicious
     * attacks using "deserialization gadgets". Implementations should use
     * allow-listing to specify acceptable types unless source of content
     * is fully trusted to only send safe types.
     *
     * @param applicability Defines kinds of types for which additional type information
     *    is added; see {@link DefaultTyping} for more information.
     */
    public B activateDefaultTyping(PolymorphicTypeValidator subtypeValidator,
            DefaultTyping applicability, JsonTypeInfo.As includeAs)
    {
        // Use if "As.EXTERNAL_PROPERTY" will not work, check to ensure no attempts made
        if (includeAs == JsonTypeInfo.As.EXTERNAL_PROPERTY) {
            throw new IllegalArgumentException("Cannot use includeAs of "+includeAs+" for Default Typing");
        }
        return setDefaultTyping(_defaultDefaultTypingResolver(subtypeValidator,
                applicability, includeAs));
    }

    /**
     * Method for enabling automatic inclusion of type information -- needed
     * for proper deserialization of polymorphic types (unless types
     * have been annotated with {@link com.fasterxml.jackson.annotation.JsonTypeInfo}) --
     * using "As.PROPERTY" inclusion mechanism and specified property name
     * to use for inclusion (default being "@class" since default type information
     * always uses class name as type identifier)
     *<p>
     * NOTE: choice of {@link PolymorphicTypeValidator} to configure is of
     * crucial importance to security when deserializing untrusted content:
     * this because allowing deserializing of any type can lead to malicious
     * attacks using "deserialization gadgets". Implementations should use
     * allow-listing to specify acceptable types unless source of content

View on GitHub (pinned to 87876ca5c0)