{"record":{"id":"29437668f2594604","repo":"mongodb/node-mongodb-native","slug":"aws-session-token-cannot-be-provided-when-using-mo","errorCode":null,"errorMessage":"AWS_SESSION_TOKEN cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.","messagePattern":"AWS_SESSION_TOKEN cannot be provided when using MONGODB-AWS\\. Credentials must be provided in a manner that can be read by the AWS SDK\\.","errorType":"exception","errorClass":"MongoAPIError","httpStatus":null,"severity":"error","filePath":"src/connection_string.ts","lineNumber":429,"sourceCode":"      mongoOptions.dbName &&\n      !allProvidedOptions.has('authSource')\n    ) {\n      // inherit the dbName unless GSSAPI or X509, then silently ignore dbName\n      // and there was no specific authSource given\n      mongoOptions.credentials = MongoCredentials.merge(mongoOptions.credentials, {\n        source: mongoOptions.dbName\n      });\n    }\n\n    if (isAws) {\n      const { username, password } = mongoOptions.credentials;\n      if (username || password) {\n        throw new MongoAPIError(\n          'username and password cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.'\n        );\n      }\n      if (mongoOptions.credentials.mechanismProperties.AWS_SESSION_TOKEN) {\n        throw new MongoAPIError(\n          'AWS_SESSION_TOKEN cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.'\n        );\n      }\n    }\n\n    mongoOptions.credentials.validate();\n\n    // Check if the only auth related option provided was authSource, if so we can remove credentials\n    if (\n      mongoOptions.credentials.password === '' &&\n      mongoOptions.credentials.username === '' &&\n      mongoOptions.credentials.mechanism === AuthMechanism.MONGODB_DEFAULT &&\n      Object.keys(mongoOptions.credentials.mechanismProperties).length === 0\n    ) {\n      delete mongoOptions.credentials;\n    }\n  }\n","sourceCodeStart":411,"sourceCodeEnd":447,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/connection_string.ts#L411-L447","documentation":"Thrown by MongoAPIError when authMechanism=MONGODB-AWS and `AWS_SESSION_TOKEN` is set inside `authMechanismProperties` (URI or options). The session token must come through the AWS SDK's own discovery chain, not through driver options. Located at src/connection_string.ts:429, immediately after the username/password check in the isAws branch.","triggerScenarios":"URI `...?authMechanism=MONGODB-AWS&authMechanismProperties=AWS_SESSION_TOKEN:FwoG...` or options `{ authMechanism: 'MONGODB-AWS', authMechanismProperties: { AWS_SESSION_TOKEN: '...' } }`.","commonSituations":"Using STS temporary credentials and trying to pass the session token via authMechanismProperties; copy-pasting an example that worked for a different driver language; assuming the token is read like other mechanism props.","solutions":["Remove AWS_SESSION_TOKEN from authMechanismProperties and set the AWS_SESSION_TOKEN environment variable instead.","Supply all three temporary credentials (access key id, secret, session token) via AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY / AWS_SESSION_TOKEN env vars; the AWS SDK will pick them up.","If running on EC2/ECS/EKS, drop static token passing entirely and attach an IAM role to the compute."],"exampleFix":"// before\nnew MongoClient('mongodb+srv://host/?authMechanism=MONGODB-AWS&authMechanismProperties=AWS_SESSION_TOKEN:FwoGZX...')\n\n// after\nprocess.env.AWS_SESSION_TOKEN = 'FwoGZX...'\nnew MongoClient('mongodb+srv://host/?authMechanism=MONGODB-AWS')","handlingStrategy":"validation","validationCode":"function assertAwsNoSessionToken(options = {}, uri = '') {\n  const amp = options.authMechanismProperties?.AWS_SESSION_TOKEN || (uri.match(/AWS_SESSION_TOKEN:([^&]+)/)?.[1]);\n  const isAws = /aws/i.test(options.authMechanism || '') || /authMechanism=MONGODB-AWS/i.test(uri);\n  if (isAws && amp) throw new Error('Pass AWS_SESSION_TOKEN via env var, not authMechanismProperties.');\n}","typeGuard":null,"tryCatchPattern":"try { new MongoClient(uri, options); } catch (e) { if (e instanceof MongoAPIError && /AWS_SESSION_TOKEN/.test(e.message)) { delete options.authMechanismProperties?.AWS_SESSION_TOKEN; process.env.AWS_SESSION_TOKEN = token; } else throw e; }","preventionTips":["For temporary AWS creds, always use AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY / AWS_SESSION_TOKEN env vars.","Audit config files for any AWS_SESSION_TOKEN key under authMechanismProperties."],"tags":["authentication","aws","connection-string","mongodb-aws","session-token"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}