{"record":{"id":"742a11f707efc6a8","repo":"mongodb/node-mongodb-native","slug":"connection-is-missing-credentials-when-asked-to-re","errorCode":null,"errorMessage":"Connection is missing credentials when asked to reauthenticate","messagePattern":"Connection is missing credentials when asked to reauthenticate","errorType":"exception","errorClass":"MongoMissingCredentialsError","httpStatus":null,"severity":"error","filePath":"src/cmap/connection_pool.ts","lineNumber":530,"sourceCode":"      );\n      conn.destroy();\n    }\n    this.connections.clear();\n    this.emitAndLog(ConnectionPool.CONNECTION_POOL_CLOSED, new ConnectionPoolClosedEvent(this));\n  }\n\n  /**\n   * @internal\n   * Reauthenticate a connection\n   */\n  async reauthenticate(connection: Connection): Promise<void> {\n    const authContext = connection.authContext;\n    if (!authContext) {\n      throw new MongoRuntimeError('No auth context found on connection.');\n    }\n    const credentials = authContext.credentials;\n    if (!credentials) {\n      throw new MongoMissingCredentialsError(\n        'Connection is missing credentials when asked to reauthenticate'\n      );\n    }\n\n    const resolvedCredentials = credentials.resolveAuthMechanism(connection.hello);\n    const provider = this.server.topology.client.s.authProviders.getOrCreateProvider(\n      resolvedCredentials.mechanism,\n      resolvedCredentials.mechanismProperties\n    );\n\n    if (!provider) {\n      throw new MongoMissingCredentialsError(\n        `Reauthenticate failed due to no auth provider for ${credentials.mechanism}`\n      );\n    }\n\n    await provider.reauth(authContext);\n","sourceCodeStart":512,"sourceCodeEnd":548,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/connection_pool.ts#L512-L548","documentation":"A MongoMissingCredentialsError thrown in ConnectionPool.reauthenticate when the authContext exists but its credentials property is missing. Reauthentication requires the original credentials to re-run the SASL exchange; without them the driver cannot produce a valid auth attempt. This points to credentials not being captured during MongoClient construction or being dropped from the context.","triggerScenarios":"Connecting without credentials in the URI but the server later demands reauthentication (because an initial external token expired, or X.509/OIDC credentials were provided out-of-band and not retained). Also possible via an internal wiring bug that drops credentials from the auth context.","commonSituations":"Using X.509 or OIDC where credentials come from a callback that was not persisted; connecting with an authSource mismatch so credentials resolve to empty; driver version with a credentials-propagation regression; token-based auth (AWS, OIDC) where the refresh path lost the credential reference.","solutions":["Provide credentials in the connection string or via authMechanismProperties consistently.","For X.509/OIDC, ensure the credential callback/properties are set on MongoClient options.","Verify authSource is correct so credentials are resolved.","Upgrade the driver to a release with fixes for credential propagation on reauth."],"exampleFix":"// before\nconst client = new MongoClient('mongodb://host/?authMechanism=MONGODB-X509');\n// no tlsCertificateKeyFile / credentials retained\n\n// after\nconst client = new MongoClient('mongodb://host/?authMechanism=MONGODB-X509&tls=true&tlsCertificateKeyFile=./cert.pem');","handlingStrategy":"validation","validationCode":"// Ensure credentials are present before connecting\nif (!uri.includes('@') && !options.credentials) {\n  throw new Error('Credentials required for authenticated deployments');\n}","typeGuard":null,"tryCatchPattern":"try {\n  await operation();\n} catch (e) {\n  if (e instanceof MongoMissingCredentialsError) {\n    // supply credentials and reconnect\n  } else throw e;\n}","preventionTips":["Include credentials in the URI or options consistently.","For X.509/OIDC, set authMechanismProperties on the client.","Verify authSource resolves to a database with the user."],"tags":["auth","credentials","reauthentication","x509","oidc"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}