{"record":{"id":"69b67bb264034efd","repo":"mongodb/node-mongodb-native","slug":"status-code-response-status-returned-from-the-g","errorCode":null,"errorMessage":"Status code ${response.status} returned from the GCP endpoint. Response body: ${response.body}","messagePattern":"Status code (.+?) returned from the GCP endpoint\\. Response body: (.+?)","errorType":"exception","errorClass":"MongoGCPError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongodb_oidc/gcp_machine_workflow.ts","lineNumber":41,"sourceCode":"): Promise<OIDCResponse> => {\n  const tokenAudience = params.tokenAudience;\n  if (!tokenAudience) {\n    throw new MongoGCPError(TOKEN_RESOURCE_MISSING_ERROR);\n  }\n  return await getGcpTokenData(tokenAudience);\n};\n\n/**\n * Hit the GCP endpoint to get the token data.\n */\nasync function getGcpTokenData(tokenAudience: string): Promise<OIDCResponse> {\n  const url = new URL(GCP_BASE_URL);\n  url.searchParams.append('audience', tokenAudience);\n  const response = await get(url, {\n    headers: GCP_HEADERS\n  });\n  if (response.status !== 200) {\n    throw new MongoGCPError(\n      `Status code ${response.status} returned from the GCP endpoint. Response body: ${response.body}`\n    );\n  }\n  return { accessToken: response.body };\n}\n","sourceCodeStart":23,"sourceCodeEnd":47,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_oidc/gcp_machine_workflow.ts#L23-L47","documentation":"Thrown by getGcpTokenData (gcp_machine_workflow.ts:41) when the GCP instance metadata service returns any status other than 200 while fetching an OIDC token. The driver calls the metadata endpoint with a Metadata-Flavor: Google header and expects the token body; a non-200 status means the metadata service rejected the request. The thrown MongoGCPError includes the status code and response body to aid diagnosis.","triggerScenarios":"Running with ENVIRONMENT=gcp and the metadata service returns an error: invalid/unauthorized audience (TOKEN_RESOURCE), the compute instance service account cannot mint tokens, the metadata endpoint is proxied/blocked, or the process is not actually on a GCE/GKE/Cloud Run instance and the metadata host resolves to something that returns a non-200 body.","commonSituations":"Running the gcp workflow on a developer laptop or on-prem (the http://metadata host is not reachable as the real service). TOKEN_RESOURCE audience not whitelisted on the Atlas workload identity provider. The instance service account lacks the permissions to mint tokens for the requested audience. A corporate proxy intercepting the metadata URL.","solutions":["Confirm the process runs on a real GCP compute instance with access to the metadata service","Read the response body embedded in the error message for the GCP-specific failure reason","Verify TOKEN_RESOURCE matches the audience configured in Atlas OIDC exactly","Ensure the instance service account has token-creator / iam.serviceAccounts.actAs on the target","Check that no HTTP proxy rewrites http://metadata to a different host"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"import { get } from 'http';\n// Best-effort reachability check before connecting on GCP:\nfunction checkGcpMetadata(): Promise<boolean> {\n  return new Promise((resolve) => {\n    const req = get(\n      'http://metadata/computeMetadata/v1/instance/service-accounts/default/identity?audience=test',\n      { headers: { 'Metadata-Flavor': 'Google' }, timeout: 1000 },\n      (res) => resolve(res.statusCode !== undefined)\n    );\n    req.on('error', () => resolve(false));\n    req.on('timeout', () => { req.destroy(); resolve(false); });\n  });\n}","typeGuard":null,"tryCatchPattern":"try {\n  await client.connect();\n} catch (err) {\n  if (err instanceof MongoGCPError && /GCP endpoint/.test(err.message)) {\n    // err.message includes the status and body; surface to ops, verify instance/service account\n    logger.error('GCP metadata call failed', { message: err.message });\n  }\n  throw err;\n}","preventionTips":["Run a startup probe against the GCP metadata service before opening MongoClient connections","Keep the instance service account and audience whitelisting in Terraform/IaC so they stay in sync with TOKEN_RESOURCE","Surface the embedded response body from the error in alerts for faster diagnosis"],"tags":["oidc","gcp","network","metadata-service","authentication"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}