{"record":{"id":"3748464d166937fc","repo":"mongodb/node-mongodb-native","slug":"authcontext-must-provide-credentials-374846","errorCode":null,"errorMessage":"AuthContext must provide credentials.","messagePattern":"AuthContext must provide credentials\\.","errorType":"exception","errorClass":"MongoMissingCredentialsError","httpStatus":null,"severity":"critical","filePath":"src/cmap/auth/scram.ts","lineNumber":32,"sourceCode":"\ntype CryptoMethod = 'sha1' | 'sha256';\n\nclass ScramSHA extends AuthProvider {\n  cryptoMethod: CryptoMethod;\n\n  constructor(cryptoMethod: CryptoMethod) {\n    super();\n    this.cryptoMethod = cryptoMethod || 'sha1';\n  }\n\n  override async prepare(\n    handshakeDoc: HandshakeDocument,\n    authContext: AuthContext\n  ): Promise<HandshakeDocument> {\n    const cryptoMethod = this.cryptoMethod;\n    const credentials = authContext.credentials;\n    if (!credentials) {\n      throw new MongoMissingCredentialsError('AuthContext must provide credentials.');\n    }\n\n    const nonce = await randomBytes(24);\n    // store the nonce for later use\n    authContext.nonce = nonce;\n\n    const request = {\n      ...handshakeDoc,\n      speculativeAuthenticate: {\n        ...makeFirstMessage(cryptoMethod, credentials, nonce),\n        db: credentials.source\n      }\n    };\n\n    return request;\n  }\n\n  override async auth(authContext: AuthContext) {","sourceCodeStart":14,"sourceCodeEnd":50,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/scram.ts#L14-L50","documentation":"Thrown by ScramSHA.prepare (scram.ts:32) when the AuthContext has no credentials during the speculative-authentication handshake step. SCRAM needs username/password/source to build the first SASL message, so a missing credentials object aborts prepare. Raised as MongoMissingCredentialsError.","triggerScenarios":"Connecting with SCRAM-SHA-1 or SCRAM-SHA-256 (the default) but the AuthContext.credentials is null, typically because no username/password were supplied and the server requires authentication.","commonSituations":"Connecting to an authenticated cluster with mongodb://host:port (no credentials). Default mechanism auto-selection picking SCRAM on a server that requires auth. A programmatic MongoClient with no auth options against an auth-enabled deployment.","solutions":["Provide username and password in the connection string","If authenticating to a specific db, set authSource appropriately","When building MongoClient programmatically, pass auth: { username, password }"],"exampleFix":"// before\nconst client = new MongoClient('mongodb://cluster.example.net');\n\n// after\nconst client = new MongoClient('mongodb://user:pass@cluster.example.net/?authSource=admin');","handlingStrategy":"validation","validationCode":"const u = clientOptions.auth?.username;\nconst p = clientOptions.auth?.password;\nif ((u === undefined || p === undefined) && !/:[^:@]+@/.test(uri)) {\n  throw new Error('SCRAM auth requires username and password');\n}","typeGuard":"function hasScramCreds(auth: { username?: unknown; password?: unknown }): auth is { username: string; password: string } {\n  return typeof auth.username === 'string' && typeof auth.password === 'string' && auth.password.length > 0;\n}","tryCatchPattern":"try {\n  await client.connect();\n} catch (err) {\n  if (err instanceof MongoMissingCredentialsError) {\n    // gather credentials (e.g., secret manager) and reconnect\n  } else throw err;\n}","preventionTips":["Always provide username and password for auth-enabled clusters","Set authSource to the database where the user is defined (often 'admin')","Fetch credentials from a secrets manager at startup, never hardcode"],"tags":["scram","authentication","credentials","configuration"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}