{"record":{"id":"81122c04512beb96","repo":"mongodb/node-mongodb-native","slug":"authmechanismproperties-must-be-an-object","errorCode":null,"errorMessage":"AuthMechanismProperties must be an object","messagePattern":"AuthMechanismProperties must be an object","errorType":"exception","errorClass":"MongoParseError","httpStatus":null,"severity":"error","filePath":"src/connection_string.ts","lineNumber":721,"sourceCode":"    target: 'credentials',\n    transform({ options, values }): MongoCredentials {\n      // We can have a combination of options passed in the URI and options passed\n      // as an object to the MongoClient. So we must transform the string options\n      // as well as merge them together with a potentially provided object.\n      let mechanismProperties = Object.create(null);\n\n      for (const optionValue of values) {\n        if (typeof optionValue === 'string') {\n          for (const [key, value] of entriesFromString(optionValue)) {\n            try {\n              mechanismProperties[key] = getBoolean(key, value);\n            } catch {\n              mechanismProperties[key] = value;\n            }\n          }\n        } else {\n          if (!isRecord(optionValue)) {\n            throw new MongoParseError('AuthMechanismProperties must be an object');\n          }\n          mechanismProperties = { ...optionValue };\n        }\n      }\n      return MongoCredentials.merge(options.credentials, {\n        mechanismProperties\n      });\n    }\n  },\n  authSource: {\n    target: 'credentials',\n    transform({ options, values: [value] }): MongoCredentials {\n      const source = String(value);\n      return MongoCredentials.merge(options.credentials, { source });\n    }\n  },\n  autoEncryption: {\n    type: 'record'","sourceCodeStart":703,"sourceCodeEnd":739,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/connection_string.ts#L703-L739","documentation":"Thrown by MongoParseError at src/connection_string.ts:721 in the `authMechanismProperties` transform. When a value is supplied as an object (not a URI string), it must be a plain record; anything else (array, string-coerced primitive, null) is rejected. String values are parsed as key:value pairs and are not subject to this check.","triggerScenarios":"`{ authMechanismProperties: ['AWS_SESSION_TOKEN:x'] }`, `{ authMechanismProperties: 42 }`, or `null` passed where an object was expected.","commonSituations":"Passing mechanism properties as an array because the URI form looks comma-like; loading the value from a config file as the wrong YAML/JSON type.","solutions":["Pass `authMechanismProperties` as a plain object, e.g. `{ ALLOWED_HOSTS: ['example.com'] }` for OIDC.","If passing via the URI, use the string form `?authMechanismProperties=K:V,K2:V2` (the driver parses it).","Validate the value is a non-null object before assigning it."],"exampleFix":"// before\nnew MongoClient(uri, { authMechanism: 'MONGODB-OIDC', authMechanismProperties: 'ALLOWED_HOSTS:example.com' })\n\n// after (object form when not in URI)\nnew MongoClient(uri, { authMechanism: 'MONGODB-OIDC', authMechanismProperties: { ALLOWED_HOSTS: ['example.com'] } })","handlingStrategy":"type-guard","validationCode":"function isPlainObject(v) { return typeof v === 'object' && v !== null && !Array.isArray(v); }\nfunction assertMechPropsObject(options) { const p = options.authMechanismProperties; if (p != null && typeof p !== 'string' && !isPlainObject(p)) throw new Error('authMechanismProperties must be a string or plain object.'); }","typeGuard":"function isMechProps(v): v is Record<string, unknown> { return typeof v === 'object' && v !== null && !Array.isArray(v); }","tryCatchPattern":"try { new MongoClient(uri, options); } catch (e) { if (e instanceof MongoParseError && /AuthMechanismProperties must be an object/.test(e.message)) { options.authMechanismProperties = typeof options.authMechanismProperties === 'string' ? options.authMechanismProperties : {}; } else throw e; }","preventionTips":["Prefer the URI string form for authMechanismProperties (the driver parses it) unless you need structured values like OIDC ALLOWED_HOSTS arrays.","Validate that any object form is a plain object before assignment."],"tags":["connection-string","authentication","options","type-validation"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}