{"record":{"id":"56f2ddd91a1d9e3f","repo":"mongodb/node-mongodb-native","slug":"no-authprovider-for-authmechanism-mongodb-scram","errorCode":null,"errorMessage":"No AuthProvider for ${AuthMechanism.MONGODB_SCRAM_SHA256} defined.","messagePattern":"No AuthProvider for (.+?) defined\\.","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"critical","filePath":"src/cmap/connect.ts","lineNumber":266,"sourceCode":"    compression: compressors\n  };\n\n  if (options.loadBalanced === true) {\n    handshakeDoc.loadBalanced = true;\n  }\n\n  const credentials = authContext.credentials;\n  if (credentials) {\n    if (credentials.mechanism === AuthMechanism.MONGODB_DEFAULT && credentials.username) {\n      handshakeDoc.saslSupportedMechs = `${credentials.source}.${credentials.username}`;\n\n      const provider = authContext.options.authProviders.getOrCreateProvider(\n        AuthMechanism.MONGODB_SCRAM_SHA256,\n        credentials.mechanismProperties\n      );\n      if (!provider) {\n        // This auth mechanism is always present.\n        throw new MongoInvalidArgumentError(\n          `No AuthProvider for ${AuthMechanism.MONGODB_SCRAM_SHA256} defined.`\n        );\n      }\n      return await provider.prepare(handshakeDoc, authContext);\n    }\n    const provider = authContext.options.authProviders.getOrCreateProvider(\n      credentials.mechanism,\n      credentials.mechanismProperties\n    );\n    if (!provider) {\n      throw new MongoInvalidArgumentError(`No AuthProvider for ${credentials.mechanism} defined.`);\n    }\n    return await provider.prepare(handshakeDoc, authContext);\n  }\n  return handshakeDoc;\n}\n\n/**","sourceCodeStart":248,"sourceCodeEnd":284,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/connect.ts#L248-L284","documentation":"Thrown as a MongoInvalidArgumentError in prepareHandshakeDocument() when credentials use MONGODB_DEFAULT with a username, the driver tries to use SCRAM-SHA-256 for speculative auth, and getOrCreateProvider(MONGODB_SCRAM_SHA256) returns null. The adjacent comment ('This auth mechanism is always present') makes clear this is a defensive invariant — SCRAM-SHA-256 is a built-in provider and should never be absent.","triggerScenarios":"Effectively unreachable in normal operation: SCRAM-SHA-256 is a core built-in provider. Would only fire if a custom AuthProvider registry was constructed that explicitly omitted ScramSHA256, or if internal provider registration was broken (e.g. a bad monkey-patch or a driver bug).","commonSituations":"Custom code that reconfigures the authProviders registry and removes SCRAM-SHA-256; a corrupted/modified driver build; extremely unlikely in stock usage.","solutions":["Do not remove or override the default AuthProvider registry","If you construct a custom MongoClient options object with authProviders, ensure SCRAM-SHA-256 remains registered","Report as a driver bug if hit with an unmodified driver"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try { await client.connect(); } catch (e) {\n  if (e instanceof MongoInvalidArgumentError && /No AuthProvider for.*SCRAM-SHA-256/.test(e.message)) {\n    // do not strip the default auth provider registry; report as a bug\n  }\n  throw e;\n}","preventionTips":["Never remove the default SCRAM-SHA-256 provider from the auth provider registry","Treat occurrences as driver/environment bugs and report them","Avoid monkey-patching the internal auth provider map"],"tags":["authentication","scram","internal","invariant"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}