{"record":{"id":"9358ed5968f35ca8","repo":"mongodb/node-mongodb-native","slug":"authcontext-must-provide-credentials-9358ed","errorCode":null,"errorMessage":"AuthContext must provide credentials.","messagePattern":"AuthContext must provide credentials\\.","errorType":"exception","errorClass":"MongoMissingCredentialsError","httpStatus":null,"severity":"critical","filePath":"src/cmap/auth/mongodb_oidc.ts","lineNumber":182,"sourceCode":"   */\n  override async prepare(\n    handshakeDoc: HandshakeDocument,\n    authContext: AuthContext\n  ): Promise<HandshakeDocument> {\n    const { connection } = authContext;\n    const credentials = getCredentials(authContext);\n    const result = await this.workflow.speculativeAuth(connection, credentials);\n    return { ...handshakeDoc, ...result };\n  }\n}\n\n/**\n * Get credentials from the auth context, throwing if they do not exist.\n */\nfunction getCredentials(authContext: AuthContext): MongoCredentials {\n  const { credentials } = authContext;\n  if (!credentials) {\n    throw new MongoMissingCredentialsError(MISSING_CREDENTIALS_ERROR);\n  }\n  return credentials;\n}\n","sourceCodeStart":164,"sourceCodeEnd":186,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongodb_oidc.ts#L164-L186","documentation":"Thrown by getCredentials in the OIDC auth provider (mongodb_oidc.ts:182) when the AuthContext has no credentials object at all. OIDC still requires a MongoCredentials to carry mechanismProperties (ENVIRONMENT, TOKEN_RESOURCE) and optional username; if connection parsing produced no credentials, the OIDC provider cannot run. Raised as MongoMissingCredentialsError.","triggerScenarios":"Selecting MONGODB-OIDC auth but the connection/options did not yield a MongoCredentials object (e.g., authMechanism set without the supporting mechanismProperties, or a programmatic MongoClient with no credentials option).","commonSituations":"Setting authMechanism=MONGODB-OIDC on a connection string with no username and no mechanismProperties. Building MongoClient programmatically and passing auth: { mechanism: 'MONGODB-OIDC' } without mechanismProperties. A mismatch between the auth source and the mechanism leaving credentials null.","solutions":["Provide the OIDC mechanismProperties so credentials parse: authMechanismProperties=ENVIRONMENT:<env>,TOKEN_RESOURCE:<audience>","If using the callback flow, ensure oidc callback / mechanismProperties are set on the MongoClient options","Verify the connection string is well-formed and the auth section is not stripped"],"exampleFix":"// before\nconst client = new MongoClient('mongodb://host/?authMechanism=MONGODB-OIDC');\n\n// after\nconst client = new MongoClient(\n  'mongodb://host/?authMechanism=MONGODB-OIDC&authMechanismProperties=ENVIRONMENT:gcp,TOKEN_RESOURCE:<audience>'\n);","handlingStrategy":"validation","validationCode":"const mech = clientOptions.auth?.mechanism;\nconst hasCreds =\n  clientOptions.auth?.username !== undefined ||\n  /:[^:@]*@/.test(uri); // crude user:pass in URI\nif (mech === 'MONGODB-OIDC' && !clientOptions.auth?.mechananismProperties && !hasCreds) {\n  throw new Error('OIDC selected but no mechanismProperties/credentials provided');\n}","typeGuard":null,"tryCatchPattern":"try {\n  await client.connect();\n} catch (err) {\n  if (err instanceof MongoMissingCredentialsError) {\n    // rebuild the URI with authMechanismProperties and retry once\n  } else throw err;\n}","preventionTips":["Always pair MONGODB-OIDC with mechanismProperties (ENVIRONMENT at minimum)","Validate auth options in a shared config module before passing to MongoClient","Log the resolved auth mechanism/properties at startup (redacted)"],"tags":["oidc","authentication","configuration","credentials"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}