{"record":{"id":"54cecab32e49582d","repo":"mongodb/node-mongodb-native","slug":"cannot-set-both-proxyoptions-and-kmsconnectcallbac-54ceca","errorCode":null,"errorMessage":"Cannot set both proxyOptions and kmsConnectCallback","messagePattern":"Cannot set both proxyOptions and kmsConnectCallback","errorType":"exception","errorClass":"MongoCryptInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/client-side-encryption/client_encryption.ts","lineNumber":132,"sourceCode":"   *\n   * @example\n   * ```ts\n   * new ClientEncryption(mongoClient, {\n   *   keyVaultNamespace: 'client.encryption',\n   *   kmsProviders: {\n   *     aws: {\n   *       accessKeyId: AWS_ACCESS_KEY,\n   *       secretAccessKey: AWS_SECRET_KEY\n   *     }\n   *   }\n   * });\n   * ```\n   */\n  constructor(client: MongoClient, options: ClientEncryptionOptions) {\n    this._client = client;\n    this._proxyOptions = options.proxyOptions ?? {};\n    if (this._proxyOptions.proxyHost && options.kmsConnectCallback) {\n      throw new MongoCryptInvalidArgumentError(\n        'Cannot set both proxyOptions and kmsConnectCallback'\n      );\n    }\n    this._tlsOptions = options.tlsOptions ?? {};\n    this._kmsConnectCallback = options.kmsConnectCallback;\n    this._kmsProviders = options.kmsProviders || {};\n    const { timeoutMS } = resolveTimeoutOptions(client, options);\n    this._timeoutMS = timeoutMS;\n    this._credentialProviders = options.credentialProviders;\n\n    if (options.credentialProviders?.aws && !isEmptyCredentials('aws', this._kmsProviders)) {\n      throw new MongoCryptInvalidArgumentError(\n        'Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching'\n      );\n    }\n\n    if (options.keyVaultNamespace == null) {\n      throw new MongoCryptInvalidArgumentError('Missing required option `keyVaultNamespace`');","sourceCodeStart":114,"sourceCodeEnd":150,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/client-side-encryption/client_encryption.ts#L114-L150","documentation":"Thrown by the ClientEncryption constructor when both proxyOptions (with a proxyHost) and kmsConnectCallback are provided. These are mutually exclusive KMS connection mechanisms: proxyOptions sets up a SOCKS5 proxy, while kmsConnectCallback lets you provide a custom socket factory. Only one can be active. This is a MongoCryptInvalidArgumentError.","triggerScenarios":"Creating a new ClientEncryption instance with options that include both proxyOptions: { proxyHost: '...' } and kmsConnectCallback: fn.","commonSituations":"Configuring explicit encryption (not auto-encryption) with both proxy mechanisms specified; merging configuration presets that each set one of these options; corporate proxy environments where multiple proxy approaches were attempted.","solutions":["Choose one KMS connection mechanism: either proxyOptions or kmsConnectCallback","For HTTP CONNECT proxies, use kmsConnectCallback and omit proxyOptions","For SOCKS5 proxies, use proxyOptions and omit kmsConnectCallback"],"exampleFix":"// before\nnew ClientEncryption(client, {\n  keyVaultNamespace: 'encryption.__keyVault',\n  proxyOptions: { proxyHost: 'proxy.example.com', proxyPort: 1080 },\n  kmsConnectCallback: myCallback,\n  kmsProviders: { ... }\n});\n\n// after (choose one)\nnew ClientEncryption(client, {\n  keyVaultNamespace: 'encryption.__keyVault',\n  kmsConnectCallback: myCallback,\n  kmsProviders: { ... }\n});","handlingStrategy":"validation","validationCode":"// Before creating ClientEncryption\nconst { proxyOptions, kmsConnectCallback } = options;\nif (proxyOptions?.proxyHost && kmsConnectCallback) {\n  throw new Error('Cannot set both proxyOptions and kmsConnectCallback; choose one');\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Review ClientEncryption options for conflicting KMS connection mechanisms","Use kmsConnectCallback for HTTP CONNECT proxies; use proxyOptions for SOCKS5","Validate configuration objects before passing them to the constructor"],"tags":["csfle","configuration","kms","proxy","client-encryption"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}