{"record":{"id":"e42842f61cd6c690","repo":"mongodb/node-mongodb-native","slug":"no-password-is-allowed-in-environment-this-mech","errorCode":null,"errorMessage":"No password is allowed in ENVIRONMENT '${this.mechanismProperties.ENVIRONMENT}' for '${this.mechanism}'.","messagePattern":"No password is allowed in ENVIRONMENT '(.+?)' for '(.+?)'\\.","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongo_credentials.ts","lineNumber":203,"sourceCode":"        this.mechanism === AuthMechanism.MONGODB_SCRAM_SHA256) &&\n      !this.username\n    ) {\n      throw new MongoMissingCredentialsError(`Username required for mechanism '${this.mechanism}'`);\n    }\n\n    if (this.mechanism === AuthMechanism.MONGODB_OIDC) {\n      if (\n        this.username &&\n        this.mechanismProperties.ENVIRONMENT &&\n        this.mechanismProperties.ENVIRONMENT !== 'azure'\n      ) {\n        throw new MongoInvalidArgumentError(\n          `username and ENVIRONMENT '${this.mechanismProperties.ENVIRONMENT}' may not be used together for mechanism '${this.mechanism}'.`\n        );\n      }\n\n      if (this.username && this.password) {\n        throw new MongoInvalidArgumentError(\n          `No password is allowed in ENVIRONMENT '${this.mechanismProperties.ENVIRONMENT}' for '${this.mechanism}'.`\n        );\n      }\n\n      if (\n        (this.mechanismProperties.ENVIRONMENT === 'azure' ||\n          this.mechanismProperties.ENVIRONMENT === 'gcp') &&\n        !this.mechanismProperties.TOKEN_RESOURCE\n      ) {\n        throw new MongoInvalidArgumentError(TOKEN_RESOURCE_MISSING_ERROR);\n      }\n\n      if (\n        this.mechanismProperties.ENVIRONMENT &&\n        !ALLOWED_ENVIRONMENT_NAMES.includes(this.mechanismProperties.ENVIRONMENT)\n      ) {\n        throw new MongoInvalidArgumentError(\n          `Currently only a ENVIRONMENT in ${ALLOWED_ENVIRONMENT_NAMES.join(","sourceCodeStart":185,"sourceCodeEnd":221,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongo_credentials.ts#L185-L221","documentation":"Thrown by MongoCredentials.validate() when the MONGODB-OIDC mechanism is configured with both a username and a password. OIDC authentication issues tokens from an identity provider, so a static password is never valid alongside a principal username. The driver rejects this combination up front because the OIDC workflow has no way to consume a password.","triggerScenarios":"Constructing a MongoClient with authMechanism='MONGODB-OIDC' (or passing credentials that resolve to OIDC) while simultaneously supplying both username and password in the credentials/connection string. The error fires during the first authentication attempt when validate() runs.","commonSituations":"Copy-pasting a SCRAM username/password connection string and only swapping the authMechanism value to MONGODB-OIDC. Configuring an Azure/service-account OIDC principal (which legitimately takes a username) and accidentally leaving an old password field populated.","solutions":["Remove the password from your connection string or credentials object; OIDC tokens are obtained via ENVIRONMENT or a callback, not a password.","If you supplied the password inadvertently via code, delete the password property from the options passed to new MongoClient.","Confirm that username-only is intentional (only allowed for the 'azure' ENVIRONMENT); otherwise remove the username too."],"exampleFix":"// before\nnew MongoClient('mongodb://host/?authMechanism=MONGODB-OIDC&username=app&password=secret');\n// after\nnew MongoClient('mongodb://host/?authMechanism=MONGODB-OIDC&username=app');","handlingStrategy":"validation","validationCode":"function assertNoOidcPassword(opts) {\n  if (opts.auth?.mechanism === 'MONGODB-OIDC' && opts.auth?.username && opts.auth?.password != null) {\n    throw new Error('MONGODB-OIDC does not accept a password when a username is set.');\n  }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Centralize connection-string building in one helper that forbids password for OIDC.","Run a unit test asserting OIDC credentials never include a password.","Treat username-only OIDC as valid only for the azure ENVIRONMENT."],"tags":["authentication","oidc","configuration","credentials"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}