{"record":{"id":"0042aecded465ba8","repo":"mongodb/node-mongodb-native","slug":"authcontext-must-provide-credentials","errorCode":null,"errorMessage":"AuthContext must provide credentials.","messagePattern":"AuthContext must provide credentials\\.","errorType":"exception","errorClass":"MongoMissingCredentialsError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongodb_aws.ts","lineNumber":41,"sourceCode":"\ninterface AWSSaslContinuePayload {\n  a: string;\n  d: string;\n  t?: string;\n}\n\nexport class MongoDBAWS extends AuthProvider {\n  private credentialFetcher: AWSSDKCredentialProvider;\n\n  constructor(credentialProvider?: AWSCredentialProvider) {\n    super();\n    this.credentialFetcher = new AWSSDKCredentialProvider(credentialProvider);\n  }\n\n  override async auth(authContext: AuthContext): Promise<void> {\n    const { connection } = authContext;\n    if (!authContext.credentials) {\n      throw new MongoMissingCredentialsError('AuthContext must provide credentials.');\n    }\n\n    authContext.credentials = await makeTempCredentials(\n      authContext.credentials,\n      this.credentialFetcher\n    );\n\n    const { credentials } = authContext;\n\n    const accessKeyId = credentials.username;\n    const secretAccessKey = credentials.password;\n    // Allow the user to specify an AWS session token for authentication with temporary credentials.\n    const sessionToken = credentials.mechanismProperties.AWS_SESSION_TOKEN;\n\n    // If all three defined, include sessionToken, else only include username and pass\n    const awsCredentials = sessionToken\n      ? { accessKeyId, secretAccessKey, sessionToken }\n      : { accessKeyId, secretAccessKey };","sourceCodeStart":23,"sourceCodeEnd":59,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_aws.ts#L23-L59","documentation":"Thrown at the start of the MONGODB-AWS auth provider's auth() method when the AuthContext carries no credentials. AWS authentication needs an access key id / secret access key (or a credential provider chain to fetch them); without any credentials the workflow cannot begin.","triggerScenarios":"The driver selected MONGODB-AWS as the auth mechanism but no username/password and no AWS credential provider resolved to credentials. Fires at mongodb_aws.ts:41 inside MongoDBAWS.auth().","commonSituations":"Specifying authMechanism=MONGODB-AWS while neither setting AWS env vars (AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY) nor providing credentials, and not running in an IAM-role environment. Forgetting to pass the username/password for static AWS keys.","solutions":["Provide static AWS credentials via username/password in the connection string, or via the AWS_* environment variables.","Run the client on an EC2/ECS/EKS instance with an IAM role so the SDK credential provider chain can fetch temporary credentials.","If using authMechanism=MONGODB-AWS explicitly, ensure at least one credential source is available before connect()."],"exampleFix":"// before\nnew MongoClient('mongodb://host/?authMechanism=MONGODB-AWS');\n// after\nnew MongoClient('mongodb://AKIA...:secret@host/?authMechanism=MONGODB-AWS');","handlingStrategy":"validation","validationCode":"function assertAwsCredentialsPresent(opts, env=process.env) {\n  const hasStatic = opts.auth?.username || env.AWS_ACCESS_KEY_ID;\n  const hasRole = env.AWS_CONTAINER_CREDENTIALS_RELATIVE_URI || env.AWS_WEB_IDENTITY_TOKEN_FILE || env.AWS_ROLE_SESSION_NAME;\n  if (opts.auth?.mechanism === 'MONGODB-AWS' && !hasStatic && !hasRole) {\n    throw new Error('MONGODB-AWS needs static keys, IAM role, or AWS env vars.');\n  }\n}","typeGuard":null,"tryCatchPattern":"try {\n  await client.connect();\n} catch (e) {\n  if (e instanceof MongoMissingCredentialsError && /AWS/.test(String(e.message))) {\n    // surface guidance to attach an IAM role or set AWS env vars\n  }\n  throw e;\n}","preventionTips":["Set AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY in dev, attach an IAM role in prod.","Validate credential availability in a startup check before connecting.","Avoid forcing MONGODB-AWS unless AWS credentials are guaranteed present."],"tags":["authentication","aws","credentials","configuration"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}