{"record":{"id":"660d60282aeb9050","repo":"mongodb/node-mongodb-native","slug":"could-not-obtain-temporary-mongodb-aws-credentials","errorCode":null,"errorMessage":"Could not obtain temporary MONGODB-AWS credentials","messagePattern":"Could not obtain temporary MONGODB-AWS credentials","errorType":"exception","errorClass":"MongoMissingCredentialsError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongodb_aws.ts","lineNumber":144,"sourceCode":"\n    const saslContinue = {\n      saslContinue: 1,\n      conversationId: saslStartResponse.conversationId,\n      payload: BSON.serialize(payload, bsonOptions)\n    };\n\n    await connection.command(ns(`${db}.$cmd`), saslContinue, undefined);\n  }\n}\n\nasync function makeTempCredentials(\n  credentials: MongoCredentials,\n  awsCredentialFetcher: AWSSDKCredentialProvider\n): Promise<MongoCredentials> {\n  function makeMongoCredentialsFromAWSTemp(creds: AWSTempCredentials) {\n    // The AWS session token (creds.Token) may or may not be set.\n    if (!creds.AccessKeyId || !creds.SecretAccessKey) {\n      throw new MongoMissingCredentialsError('Could not obtain temporary MONGODB-AWS credentials');\n    }\n\n    return new MongoCredentials({\n      username: creds.AccessKeyId,\n      password: creds.SecretAccessKey,\n      source: credentials.source,\n      mechanism: AuthMechanism.MONGODB_AWS,\n      mechanismProperties: {\n        AWS_SESSION_TOKEN: creds.Token\n      }\n    });\n  }\n  const temporaryCredentials = await awsCredentialFetcher.getCredentials();\n\n  return makeMongoCredentialsFromAWSTemp(temporaryCredentials);\n}\n\nfunction deriveRegion(host: string) {","sourceCodeStart":126,"sourceCodeEnd":162,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_aws.ts#L126-L162","documentation":"Thrown inside makeTempCredentials() when the AWS credential provider returned temporary credentials that lack AccessKeyId or SecretAccessKey. After attempting to fetch credentials from the environment/IMDS/IAM role, the result was incomplete, so the driver cannot construct a valid MongoCredentials for MONGODB-AWS.","triggerScenarios":"AWSSDKCredentialProvider.getCredentials() resolves but the returned object has no AccessKeyId and/or no SecretAccessKey. Fires at mongodb_aws.ts:144.","commonSituations":"Running on an EC2/ECS/EKS instance whose IAM role has no permission, or IMDS is unreachable returning empty data. AWS env vars set to empty strings. A misconfigured credential provider. Instance metadata service throttled/denied.","solutions":["If using an IAM role, verify the role is attached and IMDS connectivity works (curl http://169.254.169.254/latest/meta-data/iam/security-credentials/).","Provide static credentials explicitly (AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY env vars or username/password) to bypass the metadata path.","Check for AWS_SESSION_TOKEN requirements when using temporary STS credentials."],"exampleFix":"// before: relying on IMDS that returns nothing\nnew MongoClient('mongodb://host/?authMechanism=MONGODB-AWS');\n// after: explicit static credentials\nprocess.env.AWS_ACCESS_KEY_ID='AKIA...';\nprocess.env.AWS_SECRET_ACCESS_KEY='secret';\nnew MongoClient('mongodb://host/?authMechanism=MONGODB-AWS');","handlingStrategy":"validation","validationCode":"async function assertAwsCredsResolvable(fetcher) {\n  const c = await fetcher.getCredentials();\n  if (!c.AccessKeyId || !c.SecretAccessKey) {\n    throw new Error('AWS credential provider returned incomplete credentials.');\n  }\n}","typeGuard":null,"tryCatchPattern":"try {\n  await client.connect();\n} catch (e) {\n  if (e instanceof MongoMissingCredentialsError && /temporary MONGODB-AWS/.test(e.message)) {\n    // fall back to explicit AWS env vars or static keys\n  }\n  throw e;\n}","preventionTips":["Set AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY explicitly in dev.","Verify the IAM role/IMDS path works before relying on it in prod.","Add a pre-connect credential probe in startup scripts."],"tags":["authentication","aws","credentials","iam","environment"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}