{"record":{"id":"a609a834148c4649","repo":"mongodb/node-mongodb-native","slug":"username-and-password-cannot-be-provided-when-usin","errorCode":null,"errorMessage":"username and password cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.","messagePattern":"username and password cannot be provided when using MONGODB-AWS\\. Credentials must be provided in a manner that can be read by the AWS SDK\\.","errorType":"exception","errorClass":"MongoAPIError","httpStatus":null,"severity":"error","filePath":"src/connection_string.ts","lineNumber":424,"sourceCode":"      );\n    }\n\n    if (\n      !(isGssapi || isX509 || isAws || isOidc) &&\n      mongoOptions.dbName &&\n      !allProvidedOptions.has('authSource')\n    ) {\n      // inherit the dbName unless GSSAPI or X509, then silently ignore dbName\n      // and there was no specific authSource given\n      mongoOptions.credentials = MongoCredentials.merge(mongoOptions.credentials, {\n        source: mongoOptions.dbName\n      });\n    }\n\n    if (isAws) {\n      const { username, password } = mongoOptions.credentials;\n      if (username || password) {\n        throw new MongoAPIError(\n          'username and password cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.'\n        );\n      }\n      if (mongoOptions.credentials.mechanismProperties.AWS_SESSION_TOKEN) {\n        throw new MongoAPIError(\n          'AWS_SESSION_TOKEN cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.'\n        );\n      }\n    }\n\n    mongoOptions.credentials.validate();\n\n    // Check if the only auth related option provided was authSource, if so we can remove credentials\n    if (\n      mongoOptions.credentials.password === '' &&\n      mongoOptions.credentials.username === '' &&\n      mongoOptions.credentials.mechanism === AuthMechanism.MONGODB_DEFAULT &&\n      Object.keys(mongoOptions.credentials.mechanismProperties).length === 0","sourceCodeStart":406,"sourceCodeEnd":442,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/connection_string.ts#L406-L442","documentation":"Thrown by MongoAPIError when the connection uses authMechanism=MONGODB-AWS but a username or password is also present (in the URI or options). For MONGODB-AWS, the driver delegates credential discovery to the AWS SDK (env vars, ECS/EKS, EC2 IMDS, shared config), so embedding credentials in the URI defeats that and is rejected. Found at src/connection_string.ts:424 inside the isAws branch of credential post-processing.","triggerScenarios":"Call `new MongoClient('mongodb+srv://user:pass@cluster.mongodb.net/?authMechanism=MONGODB-AWS')` or pass `{ auth: { username, password }, authMechanism: 'MONGODB-AWS' }` in options. Any non-empty username or password on credentials when mechanism is MONGODB-AWS triggers it.","commonSituations":"Copying a SCRAM-SHA connection string and just appending `&authMechanism=MONGODB-AWS`; assuming AWS auth accepts IAM access-key id / secret as the URI user/password; mixing an IAM role assumption workflow with a static-credential URI template.","solutions":["Remove the username:password segment from the URI and remove the `auth` option; let the AWS SDK supply credentials via AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY env vars (or role/IMDS).","If you must pass static IAM credentials, set env vars AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY (and AWS_SESSION_TOKEN if using temporary creds) instead of the URI.","Switch authMechanism to a SCRAM mechanism (SCRAM-SHA-256 default) if the account is a normal database user, not an IAM principal."],"exampleFix":"// before\nnew MongoClient('mongodb+srv://AKIAxxxx:secret@cluster.example.mongodb.net/?authMechanism=MONGODB-AWS')\n\n// after (let AWS SDK read env vars)\nnew MongoClient('mongodb+srv://cluster.example.mongodb.net/?authMechanism=MONGODB-AWS')","handlingStrategy":"validation","validationCode":"function assertAwsNoUserPass(uri, options = {}) {\n  const mechanism = options.authMechanism ?? (uri.match(/authMechanism=([^&]+)/i)?.[1]);\n  const hasUserInfo = /^[^?]+:\\/\\/[^\\/\\?]*:[^@\\?]+@/.test(uri) || (options.auth && (options.auth.username || options.auth.password));\n  if (/aws/i.test(mechanism || '') && hasUserInfo) {\n    throw new Error('MONGODB-AWS forbids username/password in the URI; use AWS SDK env vars.');\n  }\n}","typeGuard":null,"tryCatchPattern":"try { const client = new MongoClient(uri, options); } catch (e) { if (e instanceof MongoAPIError && /MONGODB-AWS/.test(e.message)) { /* strip credentials and retry with env-based auth */ } else throw e; }","preventionTips":["For MONGODB-AWS, never put IAM access key id / secret in the URI; rely on the AWS SDK default credential chain.","Unit-test URI construction so that any AWS-mechanism template cannot be combined with user info.","Keep one config module that knows the auth mechanism and emits the URI accordingly."],"tags":["authentication","aws","connection-string","mongodb-aws"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}