{"record":{"id":"838ebabacdfe7b4e","repo":"mongodb/node-mongodb-native","slug":"azure-endpoint-did-not-return-a-value-with-only-ac","errorCode":null,"errorMessage":"Azure endpoint did not return a value with only access_token and expires_in properties","messagePattern":"Azure endpoint did not return a value with only access_token and expires_in properties","errorType":"exception","errorClass":"MongoAzureError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts","lineNumber":32,"sourceCode":"const TOKEN_RESOURCE_MISSING_ERROR =\n  'TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure.';\n\n/**\n * The callback function to be used in the automated callback workflow.\n * @param params - The OIDC callback parameters.\n * @returns The OIDC response.\n */\nexport const azureCallback: OIDCCallbackFunction = async (\n  params: OIDCCallbackParams\n): Promise<OIDCResponse> => {\n  const tokenAudience = params.tokenAudience;\n  const username = params.username;\n  if (!tokenAudience) {\n    throw new MongoAzureError(TOKEN_RESOURCE_MISSING_ERROR);\n  }\n  const response = await getAzureTokenData(tokenAudience, username);\n  if (!isEndpointResultValid(response)) {\n    throw new MongoAzureError(ENDPOINT_RESULT_ERROR);\n  }\n  return response;\n};\n\n/**\n * Hit the Azure endpoint to get the token data.\n */\nasync function getAzureTokenData(tokenAudience: string, username?: string): Promise<OIDCResponse> {\n  const url = new URL(AZURE_BASE_URL);\n  addAzureParams(url, tokenAudience, username);\n  const response = await get(url, {\n    headers: AZURE_HEADERS\n  });\n  if (response.status !== 200) {\n    throw new MongoAzureError(\n      `Status code ${response.status} returned from the Azure endpoint. Response body: ${response.body}`\n    );\n  }","sourceCodeStart":14,"sourceCodeEnd":50,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts#L14-L50","documentation":"Thrown by the Azure machine workflow when the Azure IMDS endpoint response does not contain a valid access_token and expires_in. After fetching the token JSON and mapping it to { accessToken, expiresInSeconds }, isEndpointResultValid() returns false if either field is missing or the wrong type, indicating the endpoint returned an unexpected shape.","triggerScenarios":"Azure IMDS replied with a 200 body that lacks access_token / expires_in, or includes them as wrong types. Fires at azure_machine_workflow.ts:32 after the response is parsed and validated.","commonSituations":"The Azure endpoint changed its response shape. Wrong TOKEN_RESOURCE/audience causing Azure to return a different JSON structure (e.g. an error envelope with 200 status). Managed identity not assigned to the resource, returning an error payload.","solutions":["Verify the managed identity is assigned to the VM/container and has permission to request tokens for the configured audience.","Confirm TOKEN_RESOURCE matches the audience Azure is configured to issue.","Inspect the raw IMDS response manually (curl with Metadata:true) to see what JSON shape is returned and adjust accordingly."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"function looksLikeAzureToken(j) {\n  return j && typeof j.access_token === 'string' && j.expires_in != null;\n}","typeGuard":"function isAzureTokenShape(j): j is { access_token: string; expires_in: number|string } {\n  return !!j && typeof j.access_token === 'string' && j.expires_in != null;\n}","tryCatchPattern":"try {\n  await client.connect();\n} catch (e) {\n  if (e instanceof MongoAzureError && /access_token and expires_in/.test(e.message)) {\n    // curl the IMDS endpoint manually to inspect the actual payload\n  }\n  throw e;\n}","preventionTips":["Verify the managed identity is assigned to the resource.","Confirm the TOKEN_RESOURCE/audience is accepted by Azure.","Inspect the raw IMDS response when the shape is unexpected."],"tags":["authentication","oidc","azure","metadata-service","runtime"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}