{"record":{"id":"45ce5fed9352f246","repo":"mongodb/node-mongodb-native","slug":"authmechanism-name-not-supported","errorCode":null,"errorMessage":"authMechanism ${name} not supported","messagePattern":"authMechanism (.+?) not supported","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/mongo_client_auth_providers.ts","lineNumber":60,"sourceCode":"   * We don't want to create all providers at once, as some providers may not be used.\n   * @param name - The name of the provider to get or create.\n   * @param credentials - The credentials.\n   * @returns The provider.\n   * @throws MongoInvalidArgumentError if the mechanism is not supported.\n   * @internal\n   */\n  getOrCreateProvider(\n    name: AuthMechanism | string,\n    authMechanismProperties: AuthMechanismProperties\n  ): AuthProvider {\n    const authProvider = this.existingProviders.get(name);\n    if (authProvider) {\n      return authProvider;\n    }\n\n    const providerFunction = AUTH_PROVIDERS.get(name);\n    if (!providerFunction) {\n      throw new MongoInvalidArgumentError(`authMechanism ${name} not supported`);\n    }\n\n    const provider = providerFunction(authMechanismProperties);\n    this.existingProviders.set(name, provider);\n    return provider;\n  }\n}\n\n/**\n * Gets either a device workflow or callback workflow.\n */\nfunction getWorkflow(authMechanismProperties: AuthMechanismProperties): Workflow {\n  if (authMechanismProperties.OIDC_HUMAN_CALLBACK) {\n    return new HumanCallbackWorkflow(new TokenCache(), authMechanismProperties.OIDC_HUMAN_CALLBACK);\n  } else if (authMechanismProperties.OIDC_CALLBACK) {\n    return new AutomatedCallbackWorkflow(new TokenCache(), authMechanismProperties.OIDC_CALLBACK);\n  } else {\n    const environment = authMechanismProperties.ENVIRONMENT;","sourceCodeStart":42,"sourceCodeEnd":78,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/mongo_client_auth_providers.ts#L42-L78","documentation":"Thrown when the credentials' authMechanism is not one of the registered providers (MONGODB-AWS, MONGODB-GSSAPI, MONGODB-OIDC, MONGODB-PLAIN, MONGODB-SCRAM-SHA1, MONGODB-SCRAM-SHA256, MONGODB-X509). The driver looks the name up in its AUTH_PROVIDERS map at first authentication and refuses to proceed with an unknown mechanism.","triggerScenarios":"Passing a misspelled or unsupported authMechanism in the connection string (e.g. ?authMechanism=SCRAM-SHA-256) or in MongoClient options credentials.mechanism. Also triggered by using a custom mechanism name without registering a provider.","commonSituations":"Connection-string typos (hyphens vs. underscores, wrong casing, version suffixes like -256); copying credentials between projects with different driver versions; assuming a mechanism like 'LDAP' exists when the driver only exposes MONGODB-PLAIN for LDAP.","solutions":["Use one of the supported mechanism strings exactly: 'MONGODB-AWS', 'MONGODB-GSSAPI', 'MONGODB-OIDC', 'MONGODB-PLAIN', 'MONGODB-SCRAM-SHA1', 'MONGODB-SCRAM-SHA256', 'MONGODB-X509'.","If using SCRAM, prefer the default (omit authMechanism) so the driver negotiates SCRAM-SHA-256 automatically.","For Kerberos/LDAP, remember the driver exposes them as MONGODB-GSSAPI and MONGODB-PLAIN respectively."],"exampleFix":"// before\nconst client = new MongoClient('mongodb://u:p@h/?authMechanism=SCRAM-SHA-256');\n\n// after\nconst client = new MongoClient('mongodb://u:p@h/'); // driver picks SCRAM-SHA-256\n// or explicit:\nconst client = new MongoClient('mongodb://u:p@h/?authMechanism=MONGODB-SCRAM-SHA256');","handlingStrategy":"validation","validationCode":"const SUPPORTED = new Set([\n  'MONGODB-AWS', 'MONGODB-GSSAPI', 'MONGODB-OIDC',\n  'MONGODB-PLAIN', 'MONGODB-SCRAM-SHA1',\n  'MONGODB-SCRAM-SHA256', 'MONGODB-X509'\n]);\nif (mechanism && !SUPPORTED.has(mechanism.toUpperCase())) {\n  throw new Error(`Unsupported authMechanism: ${mechanism}`);\n}","typeGuard":"import { AuthMechanism } from 'mongodb';\nconst isAuthMechanism = (v: string): v is AuthMechanism =>\n  Object.values(AuthMechanism).includes(v as AuthMechanism);","tryCatchPattern":"try {\n  await client.connect();\n} catch (e) {\n  if (/authMechanism .* not supported/.test(e.message)) {\n    // fix the connection string and retry with a new client\n  }\n  throw e;\n}","preventionTips":["Prefer omitting authMechanism for SCRAM and let the driver negotiate.","Validate the connection string against the supported list at app startup."],"tags":["authentication","connection-string","config"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}