{"record":{"id":"694bf394722d498a","repo":"mongodb/node-mongodb-native","slug":"reauthenticate-failed-due-to-no-auth-provider-for","errorCode":null,"errorMessage":"Reauthenticate failed due to no auth provider for ${credentials.mechanism}","messagePattern":"Reauthenticate failed due to no auth provider for (.+?)","errorType":"exception","errorClass":"MongoMissingCredentialsError","httpStatus":null,"severity":"error","filePath":"src/cmap/connection_pool.ts","lineNumber":542,"sourceCode":"    const authContext = connection.authContext;\n    if (!authContext) {\n      throw new MongoRuntimeError('No auth context found on connection.');\n    }\n    const credentials = authContext.credentials;\n    if (!credentials) {\n      throw new MongoMissingCredentialsError(\n        'Connection is missing credentials when asked to reauthenticate'\n      );\n    }\n\n    const resolvedCredentials = credentials.resolveAuthMechanism(connection.hello);\n    const provider = this.server.topology.client.s.authProviders.getOrCreateProvider(\n      resolvedCredentials.mechanism,\n      resolvedCredentials.mechanismProperties\n    );\n\n    if (!provider) {\n      throw new MongoMissingCredentialsError(\n        `Reauthenticate failed due to no auth provider for ${credentials.mechanism}`\n      );\n    }\n\n    await provider.reauth(authContext);\n\n    return;\n  }\n\n  /** Clear the min pool size timer */\n  private clearMinPoolSizeTimer(): void {\n    const minPoolSizeTimer = this.minPoolSizeTimer;\n    if (minPoolSizeTimer) {\n      clearTimeout(minPoolSizeTimer);\n    }\n  }\n\n  private destroyConnection(","sourceCodeStart":524,"sourceCodeEnd":560,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/connection_pool.ts#L524-L560","documentation":"A MongoMissingCredentialsError thrown in ConnectionPool.reauthenticate when no auth provider is registered for the credential's mechanism. The driver looks up a provider (SCRAM, X.509, AWS, OIDC, Kerberos, PLAIN) in the auth provider registry; if the mechanism has no installed provider, reauth cannot proceed. This typically means an optional auth plugin (e.g., kerberos native module) is not installed.","triggerScenarios":"Authenticating with a mechanism whose provider requires an optional native dependency that is not installed, then the server requests reauthentication. For example, GSSAPI (Kerberos) without the kerberos npm package, or MONGODB-AWS without the aws credentials provider available.","commonSituations":"Using GSSAPI/Kerberos auth without installing the kerberos package; MONGODB-OIDC without the provider configured; driver version where a mechanism provider was renamed/removed; production deploy missing optional native deps installed in dev.","solutions":["Install the optional dependency for the mechanism: npm install kerberos (GSSAPI), ensure AWS SDK for MONGODB-AWS.","Confirm the mechanism string matches a supported value (SCRAM-SHA-256, SCRAM-SHA-1, MONGODB-X509, MONGODB-AWS, MONGODB-OIDC, GSSAPI, PLAIN).","Upgrade driver and optional deps together per the compatibility matrix.","Pin the mechanism explicitly to avoid auto-negotiation landing on an unsupported one."],"exampleFix":"// before — GSSAPI used without native kerberos\nconst client = new MongoClient('mongodb://host/?authMechanism=GSSAPI');\n\n// after\n// npm install kerberos\nconst client = new MongoClient('mongodb://host/?authMechanism=GSSAPI&authSource=$external');","handlingStrategy":"validation","validationCode":"const SUPPORTED = ['SCRAM-SHA-1','SCRAM-SHA-256','MONGODB-X509','MONGODB-AWS','MONGODB-OIDC','GSSAPI','PLAIN'];\nif (!SUPPORTED.includes(mechanism)) {\n  throw new Error(`Unsupported auth mechanism: ${mechanism}`);\n}\nif (mechanism === 'GSSAPI') {\n  require('kerberos'); // ensure native dep\n}","typeGuard":null,"tryCatchPattern":"try {\n  await operation();\n} catch (e) {\n  if (e instanceof MongoMissingCredentialsError && /no auth provider/.test(e.message)) {\n    // install the optional native dep for the mechanism, then reconnect\n  } else throw e;\n}","preventionTips":["Install optional native deps for the chosen mechanism (kerberos, etc.).","Pin the mechanism explicitly to a supported value.","Match driver and optional-dep versions per the compatibility matrix."],"tags":["auth","reauthentication","sasl","kerberos","native-dependency"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}