{"record":{"id":"2420213b26ff26ef","repo":"mongodb/node-mongodb-native","slug":"unable-to-complete-creating-data-keys-cause-mes","errorCode":null,"errorMessage":"Unable to complete creating data keys: ${cause.message}","messagePattern":"Unable to complete creating data keys: (.+?)","errorType":"exception","errorClass":"MongoCryptCreateDataKeyError","httpStatus":null,"severity":"error","filePath":"src/client-side-encryption/client_encryption.ts","lineNumber":621,"sourceCode":"              keyId: await this.createDataKey(provider, {\n                masterKey,\n                // clone the timeoutContext\n                // in order to avoid sharing the same timeout for server selection and connection checkout across different concurrent operations\n                timeoutContext: timeoutContext?.csotEnabled() ? timeoutContext?.clone() : undefined\n              })\n            }\n      );\n      const createDataKeyResolutions = await Promise.allSettled(createDataKeyPromises);\n\n      encryptedFields.fields = createDataKeyResolutions.map((resolution, index) =>\n        resolution.status === 'fulfilled' ? resolution.value : encryptedFields.fields[index]\n      );\n\n      const rejection = createDataKeyResolutions.find(\n        (result): result is PromiseRejectedResult => result.status === 'rejected'\n      );\n      if (rejection != null) {\n        throw new MongoCryptCreateDataKeyError(encryptedFields, { cause: rejection.reason });\n      }\n    }\n\n    try {\n      const collection = await db.createCollection<TSchema>(name, {\n        ...createCollectionOptions,\n        encryptedFields,\n        timeoutMS: timeoutContext?.csotEnabled()\n          ? timeoutContext?.getRemainingTimeMSOrThrow()\n          : undefined\n      });\n      return { collection, encryptedFields };\n    } catch (cause) {\n      throw new MongoCryptCreateEncryptedCollectionError(encryptedFields, { cause });\n    }\n  }\n\n  /**","sourceCodeStart":603,"sourceCodeEnd":639,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/client-side-encryption/client_encryption.ts#L603-L639","documentation":"Thrown by ClientEncryption.createEncryptedCollection() when one or more createDataKey() calls fail during the collection creation process. This method creates data keys for encryptedFields that lack a keyId, then creates the collection. If data key creation fails partway through, this error includes the partial encryptedFields that were successfully generated. This is a MongoCryptCreateDataKeyError.","triggerScenarios":"Calling createEncryptedCollection() with encryptedFields containing fields that need new data keys, but the KMS provider is unreachable, credentials are invalid, or the key vault collection has issues. The error's cause property contains the underlying rejection reason.","commonSituations":"KMS connectivity issues (AWS, Azure, GCP unreachable); invalid KMS credentials; the key vault MongoDB collection does not exist or is not writable; network partitions during key creation; concurrent calls to createEncryptedCollection for the same fields.","solutions":["Check the error.cause for the specific failure reason (KMS error, network error, etc.)","Verify KMS provider connectivity and credentials before calling createEncryptedCollection","Ensure the key vault collection exists and is writable","The error.encryptedFields property contains partially generated fields; inspect it to understand which keys succeeded"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Before calling createEncryptedCollection, verify KMS connectivity\n// Test KMS credentials by creating a test data key first\ntry {\n  await clientEncryption.createDataKey(provider, { masterKey });\n} catch (e) {\n  console.error('KMS connectivity test failed:', e.message);\n}","typeGuard":null,"tryCatchPattern":"try {\n  const result = await clientEncryption.createEncryptedCollection(db, name, options);\n} catch (error) {\n  if (error instanceof MongoCryptCreateDataKeyError) {\n    // Data key creation failed; error.encryptedFields has partial results\n    console.error('Failed to create data keys:', error.cause?.message);\n    console.error('Partial encryptedFields:', error.encryptedFields);\n    // Fix KMS connectivity and retry\n  }\n}","preventionTips":["Verify KMS provider connectivity and credentials before calling createEncryptedCollection","Ensure the key vault collection exists and is writable","Test data key creation in isolation before attempting full collection creation"],"tags":["csfle","client-encryption","kms","data-key","encrypted-collection"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}