{"record":{"id":"926242488f689341","repo":"mongodb/node-mongodb-native","slug":"no-autoencrypter-available-for-encryption","errorCode":null,"errorMessage":"No AutoEncrypter available for encryption","messagePattern":"No AutoEncrypter available for encryption","errorType":"exception","errorClass":"MongoRuntimeError","httpStatus":null,"severity":"error","filePath":"src/cmap/connection.ts","lineNumber":882,"sourceCode":"    options: CommandOptions | undefined,\n    responseType: T\n  ): Promise<InstanceType<T>>;\n\n  public override async command(\n    ns: MongoDBNamespace,\n    command: Document,\n    options?: CommandOptions\n  ): Promise<Document>;\n\n  override async command<T extends MongoDBResponseConstructor>(\n    ns: MongoDBNamespace,\n    cmd: Document,\n    options?: CommandOptions,\n    responseType?: T\n  ): Promise<Document> {\n    const { autoEncrypter } = this;\n    if (!autoEncrypter) {\n      throw new MongoRuntimeError('No AutoEncrypter available for encryption');\n    }\n\n    const serverWireVersion = maxWireVersion(this);\n    if (serverWireVersion === 0) {\n      // This means the initial handshake hasn't happened yet\n      return await super.command<T>(ns, cmd, options, responseType);\n    }\n\n    // Save sort or indexKeys based on the command being run\n    // the encrypt API serializes our JS objects to BSON to pass to the native code layer\n    // and then deserializes the encrypted result, the protocol level components\n    // of the command (ex. sort) are then converted to JS objects potentially losing\n    // import key order information. These fields are never encrypted so we can save the values\n    // from before the encryption and replace them after encryption has been performed\n    const sort: Map<string, number> | null = cmd.find || cmd.findAndModify ? cmd.sort : null;\n    const indexKeys: Map<string, number>[] | null = cmd.createIndexes\n      ? cmd.indexes.map((index: { key: Map<string, number> }) => index.key)\n      : null;","sourceCodeStart":864,"sourceCodeEnd":900,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/connection.ts#L864-L900","documentation":"A MongoRuntimeError thrown in CryptoConnection.command when autoEncrypter is not set. CryptoConnection is the connection subclass used for Client-Side Field Level Encryption (CSFLE) / Queryable Encryption; its command override expects an AutoEncrypter instance to encrypt outbound commands. Reaching this throw means the connection is a CryptoConnection but was constructed without the autoEncrypter option — an internal misconfiguration.","triggerScenarios":"The driver instantiated a CryptoConnection (because autoEncryption was configured on the client) but the autoEncrypter was not attached — typically due to the mongodb-client-encryption native module failing to load or an internal wiring bug. The user-facing trigger is performing any CRUD/command after enabling autoEncryption when the native crypto dependency is missing or broken.","commonSituations":"Installing mongodb without the required mongodb-client-encryption native dependency; a broken/missing libmongocrypt on the system; version mismatch between driver and mongodb-client-encryption; enabling autoEncryption in config but not installing the shared library.","solutions":["Install mongodb-client-encryption at the correct version: npm install mongodb-client-encryption.","Ensure libmongocrypt is installed and on the library path.","Match the mongodb-client-encryption version to the driver version per the compatibility matrix.","Verify autoEncryption settings (keyVaultNS, kmsProviders) are complete; incomplete config can prevent AutoEncrypter init."],"exampleFix":"// before — autoEncryption enabled but native dep missing\nconst client = new MongoClient(uri, {\n  autoEncryption: { keyVaultNamespace: 'encryption.__keyVault', kmsProviders: { local: { key } } }\n});\n\n// after — install dep then construct\n// npm install mongodb-client-encryption\nconst client = new MongoClient(uri, {\n  autoEncryption: { keyVaultNamespace: 'encryption.__keyVault', kmsProviders: { local: { key } } }\n});","handlingStrategy":"validation","validationCode":"// Verify the native CSFLE module loads before constructing the client\ntry {\n  require('mongodb-client-encryption');\n} catch {\n  throw new Error('mongodb-client-encryption is required for autoEncryption');\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Install mongodb-client-encryption at the version matching the driver.","Ensure libmongocrypt is on the system library path.","Smoke-test the native module load at deploy time."],"tags":["csfle","encryption","auto-encryption","native-dependency"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}