{"record":{"id":"700ec1ee2269d8ac","repo":"mongodb/node-mongodb-native","slug":"token-resource-must-be-set-in-the-auth-mechanism-p-700ec1","errorCode":null,"errorMessage":"TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure.","messagePattern":"TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure\\.","errorType":"exception","errorClass":"MongoAzureError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts","lineNumber":28,"sourceCode":"const ENDPOINT_RESULT_ERROR =\n  'Azure endpoint did not return a value with only access_token and expires_in properties';\n\n/** Error for when the token audience is missing in the environment. */\nconst TOKEN_RESOURCE_MISSING_ERROR =\n  'TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure.';\n\n/**\n * The callback function to be used in the automated callback workflow.\n * @param params - The OIDC callback parameters.\n * @returns The OIDC response.\n */\nexport const azureCallback: OIDCCallbackFunction = async (\n  params: OIDCCallbackParams\n): Promise<OIDCResponse> => {\n  const tokenAudience = params.tokenAudience;\n  const username = params.username;\n  if (!tokenAudience) {\n    throw new MongoAzureError(TOKEN_RESOURCE_MISSING_ERROR);\n  }\n  const response = await getAzureTokenData(tokenAudience, username);\n  if (!isEndpointResultValid(response)) {\n    throw new MongoAzureError(ENDPOINT_RESULT_ERROR);\n  }\n  return response;\n};\n\n/**\n * Hit the Azure endpoint to get the token data.\n */\nasync function getAzureTokenData(tokenAudience: string, username?: string): Promise<OIDCResponse> {\n  const url = new URL(AZURE_BASE_URL);\n  addAzureParams(url, tokenAudience, username);\n  const response = await get(url, {\n    headers: AZURE_HEADERS\n  });\n  if (response.status !== 200) {","sourceCodeStart":10,"sourceCodeEnd":46,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts#L10-L46","documentation":"Thrown by the Azure machine workflow callback when tokenAudience (derived from TOKEN_RESOURCE) is missing at runtime. This is the in-flight equivalent of the validate() TOKEN_RESOURCE check, raised by azureCallback when params.tokenAudience is falsy. The Azure IMDS endpoint cannot mint a properly-scoped token without an audience.","triggerScenarios":"MONGODB-OIDC with ENVIRONMENT='azure' is selected but TOKEN_RESOURCE did not propagate to the callback (params.tokenAudience is undefined). Fires at azure_machine_workflow.ts:28.","commonSituations":"TOKEN_RESOURCE was set in a different options shape than the driver reads, or stripped during option merging. Constructing credentials manually and omitting the property. A connection string parsing issue dropping the property.","solutions":["Ensure authMechanismProperties includes TOKEN_RESOURCE (e.g. TOKEN_RESOURCE:'https://audience') for ENVIRONMENT:'azure'.","In code, confirm the property name is exactly TOKEN_RESOURCE and the value is non-empty.","Re-run with the latest driver patch; if it persists, log mechanismProperties right before connect to confirm propagation."],"exampleFix":"// before\nmechanismProperties: { ENVIRONMENT: 'azure' }\n// after\nmechanismProperties: { ENVIRONMENT: 'azure', TOKEN_RESOURCE: 'https://your-audience' }","handlingStrategy":"validation","validationCode":"function assertAzureTokenResource(props) {\n  if (props?.ENVIRONMENT === 'azure' && !props?.TOKEN_RESOURCE) {\n    throw new Error('ENVIRONMENT azure requires TOKEN_RESOURCE.');\n  }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always set TOKEN_RESOURCE alongside ENVIRONMENT:'azure'.","Validate mechanismProperties in a config layer before connect.","Log the resolved mechanismProperties in dev to confirm propagation."],"tags":["authentication","oidc","azure","configuration"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}