{"record":{"id":"4c6afc8c1b124488","repo":"mongodb/node-mongodb-native","slug":"status-code-response-status-returned-from-the-a","errorCode":null,"errorMessage":"Status code ${response.status} returned from the Azure endpoint. Response body: ${response.body}","messagePattern":"Status code (.+?) returned from the Azure endpoint\\. Response body: (.+?)","errorType":"exception","errorClass":"MongoAzureError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts","lineNumber":47,"sourceCode":"  }\n  const response = await getAzureTokenData(tokenAudience, username);\n  if (!isEndpointResultValid(response)) {\n    throw new MongoAzureError(ENDPOINT_RESULT_ERROR);\n  }\n  return response;\n};\n\n/**\n * Hit the Azure endpoint to get the token data.\n */\nasync function getAzureTokenData(tokenAudience: string, username?: string): Promise<OIDCResponse> {\n  const url = new URL(AZURE_BASE_URL);\n  addAzureParams(url, tokenAudience, username);\n  const response = await get(url, {\n    headers: AZURE_HEADERS\n  });\n  if (response.status !== 200) {\n    throw new MongoAzureError(\n      `Status code ${response.status} returned from the Azure endpoint. Response body: ${response.body}`\n    );\n  }\n  const result = JSON.parse(response.body);\n  return {\n    accessToken: result.access_token,\n    expiresInSeconds: Number(result.expires_in)\n  };\n}\n\n/**\n * Determines if a result returned from the endpoint is valid.\n * This means the result is not nullish, contains the access_token required field\n * and the expires_in required field.\n */\nfunction isEndpointResultValid(\n  token: unknown\n): token is { access_token: unknown; expires_in: unknown } {","sourceCodeStart":29,"sourceCodeEnd":65,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts#L29-L65","documentation":"Thrown by the Azure machine workflow when the HTTP GET to the Azure IMDS endpoint returns a non-200 status code. The error includes the status and response body to help diagnose why Azure refused the token request (auth, identity, audience, or network issues).","triggerScenarios":"getAzureTokenData() issues the metadata request and response.status !== 200. Fires at azure_machine_workflow.ts:47. Common non-200 causes: 403 (identity/permission), 404 (wrong resource path), 429 (throttle), 5xx (Azure outage).","commonSituations":"No system-assigned managed identity on the VM. User-assigned identity not specified (username/clientId param). TOKEN_RESOURCE/audience rejected by Azure. Azure IMDS temporarily unavailable or throttling. Network/firewall blocking 169.254.169.254.","solutions":["Read the response body in the error message: 403/404 usually indicate missing/wrong managed identity or audience.","Ensure a system-assigned identity is enabled on the compute resource, or pass the user-assigned clientId as the username.","Confirm network access to the IMDS endpoint (169.254.169.254) and retry; if throttled (429), back off."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await client.connect();\n} catch (e) {\n  if (e instanceof MongoAzureError && /Status code/.test(e.message)) {\n    const code = Number(e.message.match(/(\\d{3})/)?.[1]);\n    if (code === 403 || code === 404) {\n      // fix managed identity / clientId / audience\n    } else if (code === 429 || code >= 500) {\n      // transient: retry with backoff\n    }\n  }\n  throw e;\n}","preventionTips":["Ensure a system-assigned identity is enabled or pass the user-assigned clientId as username.","Confirm network access to 169.254.169.254 from the runtime.","Implement retry with backoff for 429/5xx Azure responses."],"tags":["authentication","oidc","azure","metadata-service","http","runtime"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}