{"record":{"id":"1572906f81eb898d","repo":"mongodb/node-mongodb-native","slug":"malformed-response-body-missing-field-access-to","errorCode":null,"errorMessage":"Malformed response body - missing field `access_token`.","messagePattern":"Malformed response body - missing field `access_token`\\.","errorType":"exception","errorClass":"MongoCryptAzureKMSRequestError","httpStatus":null,"severity":"error","filePath":"src/client-side-encryption/providers/azure.ts","lineNumber":84,"sourceCode":"  body: string;\n  status?: number;\n}): Promise<AzureTokenCacheEntry> {\n  const { status, body: rawBody } = response;\n\n  const body: { expires_in?: number; access_token?: string } = (() => {\n    try {\n      return JSON.parse(rawBody);\n    } catch {\n      throw new MongoCryptAzureKMSRequestError('Malformed JSON body in GET request.');\n    }\n  })();\n\n  if (status !== 200) {\n    throw new MongoCryptAzureKMSRequestError('Unable to complete request.', body);\n  }\n\n  if (!body.access_token) {\n    throw new MongoCryptAzureKMSRequestError(\n      'Malformed response body - missing field `access_token`.'\n    );\n  }\n\n  if (!body.expires_in) {\n    throw new MongoCryptAzureKMSRequestError(\n      'Malformed response body - missing field `expires_in`.'\n    );\n  }\n\n  const expiresInMS = Number(body.expires_in) * 1000;\n  if (Number.isNaN(expiresInMS)) {\n    throw new MongoCryptAzureKMSRequestError(\n      'Malformed response body - unable to parse int from `expires_in` field.'\n    );\n  }\n\n  return {","sourceCodeStart":66,"sourceCodeEnd":102,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/client-side-encryption/providers/azure.ts#L66-L102","documentation":"Raised when the Azure IMDS response parsed as JSON but contains no access_token field. The Azure access token is the credential libmongocrypt uses to unwrap the Customer Master Key in Azure Key Vault; its absence means the response is malformed for this provider. MongoCryptAzureKMSRequestError.","triggerScenarios":"IMDS returns JSON but with a different shape (e.g. an error envelope like { 'error': {...} } with no access_token); requesting a resource value Azure does not recognize; the managed identity has no permission to the target resource.","commonSituations":"Wrong 'resource' audience (should be https://vault.azure.net); Azure returning { error, error_description } for a denied token request; the response being a partial JSON object due to truncation; using a custom test URL that omits the token field.","solutions":["Inspect the error's attached body payload for the Azure error/error_description to find the real cause (often 'identity not found' or 'resource disabled').","Verify the managed identity is enabled and assigned to the resource, and that the Key Vault is in the same tenant.","Confirm the request reaches the standard resource https://vault.azure.net (the driver sets this; do not override the resource in tests).","Retry after reassigning the managed identity; propagation can lag."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await clientEncryption.createEncryptedCollection(...);\n} catch (e) {\n  if (e instanceof MongoCryptAzureKMSRequestError && /access_token/.test(e.message)) {\n    // inspect the attached body for Azure error_description, fix IAM, retry\n  }\n}","preventionTips":["Ensure the managed identity has permission to request tokens for https://vault.azure.net.","Log the error's payload field to capture Azure's error_description."],"tags":["csfle","azure","kms","iam"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}