{"record":{"id":"daab19603ae2b884","repo":"mongodb/node-mongodb-native","slug":"can-only-provide-a-custom-aws-credential-provider-daab19","errorCode":null,"errorMessage":"Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching","messagePattern":"Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching","errorType":"exception","errorClass":"MongoCryptInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/client-side-encryption/client_encryption.ts","lineNumber":144,"sourceCode":"   * ```\n   */\n  constructor(client: MongoClient, options: ClientEncryptionOptions) {\n    this._client = client;\n    this._proxyOptions = options.proxyOptions ?? {};\n    if (this._proxyOptions.proxyHost && options.kmsConnectCallback) {\n      throw new MongoCryptInvalidArgumentError(\n        'Cannot set both proxyOptions and kmsConnectCallback'\n      );\n    }\n    this._tlsOptions = options.tlsOptions ?? {};\n    this._kmsConnectCallback = options.kmsConnectCallback;\n    this._kmsProviders = options.kmsProviders || {};\n    const { timeoutMS } = resolveTimeoutOptions(client, options);\n    this._timeoutMS = timeoutMS;\n    this._credentialProviders = options.credentialProviders;\n\n    if (options.credentialProviders?.aws && !isEmptyCredentials('aws', this._kmsProviders)) {\n      throw new MongoCryptInvalidArgumentError(\n        'Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching'\n      );\n    }\n\n    if (options.keyVaultNamespace == null) {\n      throw new MongoCryptInvalidArgumentError('Missing required option `keyVaultNamespace`');\n    }\n\n    const mongoCryptOptions: MongoCryptOptions = {\n      ...options,\n      kmsProviders: serialize(this._kmsProviders),\n      errorWrapper: defaultErrorWrapper\n    };\n\n    this._keyVaultNamespace = options.keyVaultNamespace;\n    this._keyVaultClient = options.keyVaultClient || client;\n    const MongoCrypt = ClientEncryption.getMongoCrypt();\n    this._mongoCrypt = new MongoCrypt(mongoCryptOptions);","sourceCodeStart":126,"sourceCodeEnd":162,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/client-side-encryption/client_encryption.ts#L126-L162","documentation":"Thrown by the ClientEncryption constructor when credentialProviders.aws is defined but kmsProviders.aws contains non-empty static credentials. When using a custom AWS credential provider for dynamic credential fetching, kmsProviders.aws must be an empty object {} to indicate that credentials should be loaded dynamically. Providing both is a configuration conflict. This is a MongoCryptInvalidArgumentError.","triggerScenarios":"Constructing new ClientEncryption with both kmsProviders: { aws: { accessKeyId: '...', secretAccessKey: '...' } } and credentialProviders: { aws: fn }. The constructor rejects this before creating the MongoCrypt context.","commonSituations":"Transitioning from static AWS keys to IAM role-based credential fetching without clearing the old kmsProviders.aws values; configuration templates that pre-populate kmsProviders and code that adds credentialProviders at runtime; environment variables injecting static credentials that conflict with code-level dynamic providers.","solutions":["Set kmsProviders.aws to {} when using credentialProviders.aws for dynamic fetching","Remove credentialProviders.aws if you intend to use static credentials in kmsProviders.aws"],"exampleFix":"// before\nnew ClientEncryption(client, {\n  keyVaultNamespace: 'encryption.__keyVault',\n  kmsProviders: { aws: { accessKeyId: 'AKIA...', secretAccessKey: '...' } },\n  credentialProviders: { aws: myAwsProvider }\n});\n\n// after (dynamic fetching)\nnew ClientEncryption(client, {\n  keyVaultNamespace: 'encryption.__keyVault',\n  kmsProviders: { aws: {} },\n  credentialProviders: { aws: myAwsProvider }\n});","handlingStrategy":"validation","validationCode":"// Before creating ClientEncryption\nconst { kmsProviders, credentialProviders } = options;\nif (credentialProviders?.aws && kmsProviders?.aws && Object.keys(kmsProviders.aws).length > 0) {\n  throw new Error('Set kmsProviders.aws to {} when using credentialProviders.aws');\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["When using credentialProviders.aws, always set kmsProviders.aws to an empty object {}","Do not pre-populate kmsProviders.aws with static credentials when a dynamic provider is configured","Validate the credential configuration strategy before constructing ClientEncryption"],"tags":["csfle","configuration","kms","aws","credentials","client-encryption"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}