{"record":{"id":"c18aa6ed5e972753","repo":"mongodb/node-mongodb-native","slug":"authmechanism-credentials-mechanism-not-suppo","errorCode":null,"errorMessage":"AuthMechanism '${credentials.mechanism}' not supported","messagePattern":"AuthMechanism '(.+?)' not supported","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/cmap/connect.ts","lineNumber":104,"sourceCode":"  }, but this version of the Node.js Driver requires at least ${MIN_SUPPORTED_WIRE_VERSION} (MongoDB ${MIN_SUPPORTED_SERVER_VERSION})`;\n  return new MongoCompatibilityError(message);\n}\n\nexport async function performInitialHandshake(\n  conn: Connection,\n  options: ConnectionOptions\n): Promise<void> {\n  const credentials = options.credentials;\n\n  if (credentials) {\n    if (\n      !(credentials.mechanism === AuthMechanism.MONGODB_DEFAULT) &&\n      !options.authProviders.getOrCreateProvider(\n        credentials.mechanism,\n        credentials.mechanismProperties\n      )\n    ) {\n      throw new MongoInvalidArgumentError(`AuthMechanism '${credentials.mechanism}' not supported`);\n    }\n  }\n\n  const authContext = new AuthContext(conn, credentials, options);\n  conn.authContext = authContext;\n\n  // If we encounter an error preparing the handshake document, do NOT apply backpressure labels.  Errors\n  // encountered building the handshake document are all client-side, and do not indicate an overloaded server.\n  const handshakeDoc = await prepareHandshakeDocument(authContext);\n\n  // @ts-expect-error: TODO(NODE-5141): The options need to be filtered properly, Connection options differ from Command options\n  const handshakeOptions: CommandOptions = { ...options, raw: false };\n  if (typeof options.connectTimeoutMS === 'number') {\n    // The handshake technically is a monitoring check, so its socket timeout should be connectTimeoutMS\n    handshakeOptions.socketTimeoutMS = options.connectTimeoutMS;\n  }\n\n  const start = new Date().getTime();","sourceCodeStart":86,"sourceCodeEnd":122,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/connect.ts#L86-L122","documentation":"Thrown as a MongoInvalidArgumentError in performInitialHandshake() when credentials are present and the mechanism is not MONGODB_DEFAULT, but authProviders.getOrCreateProvider(mechanism, mechanismProperties) returns null/undefined — meaning no provider class is registered for that auth mechanism. This is the early, pre-handshake check (before the server is even contacted).","triggerScenarios":"Configuring an authMechanism the driver does not recognize (e.g. a typo like 'SCRAM-SHA-512', or a mechanism whose optional dependency is missing such as MONGODB-AWS without the aws sdk, MONGODB-CR which was removed, or PLAIN/GSSAPI without their libs). The check runs at the start of performInitialHandshake.","commonSituations":"Typo in the authMechanism query parameter; using MONGODB-AWS in an environment without @aws-sdk/credential-providers; requesting MONGODB-CR (removed in driver 4.0); requesting GSSAPI without the kerberos package installed.","solutions":["Correct the authMechanism spelling (valid: SCRAM-SHA-1, SCRAM-SHA-256, MONGODB-X509, MONGODB-AWS, MONGODB-OIDC, GSSAPI, PLAIN, MONGODB-CR-SESSION)","Install the optional dependency for the chosen mechanism (aws sdk, kerberos)","Omit authMechanism to let the driver and server negotiate (MONGODB_DEFAULT)"],"exampleFix":"// before\nconst client = new MongoClient('mongodb://host/db?authMechanism=SCRAM-SHA-512');\n\n// after\nconst client = new MongoClient('mongodb://user:pass@host/db'); // let driver negotiate","handlingStrategy":"validation","validationCode":"const SUPPORTED = new Set(['SCRAM-SHA-1','SCRAM-SHA-256','MONGODB-X509','MONGODB-AWS','MONGODB-OIDC','GSSAPI','PLAIN','MONGODB-CR-SESSION','MONGODB-DEFAULT']);\nconst m = new URL(uri).searchParams.get('authMechanism');\nif (m && !SUPPORTED.has(m.toUpperCase())) throw new Error(`Unsupported authMechanism: ${m}`);","typeGuard":"function isSupportedMechanism(m: string): boolean {\n  return ['SCRAM-SHA-1','SCRAM-SHA-256','MONGODB-X509','MONGODB-AWS','MONGODB-OIDC','GSSAPI','PLAIN','MONGODB-CR-SESSION'].includes(m);\n}","tryCatchPattern":null,"preventionTips":["Spell authMechanism exactly (case-sensitive in many paths); prefer omitting it to let the driver negotiate","Install optional dependencies before using GSSAPI/AWS/OIDC","Avoid removed mechanisms like MONGODB-CR"],"tags":["authentication","configuration","auth-mechanism","credentials"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}