{"record":{"id":"edab17b85107ebfb","repo":"mongodb/node-mongodb-native","slug":"can-only-provide-a-custom-aws-credential-provider","errorCode":null,"errorMessage":"Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching","messagePattern":"Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching","errorType":"exception","errorClass":"MongoCryptInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/client-side-encryption/auto_encrypter.ts","lineNumber":264,"sourceCode":"    this._client = client;\n    this._bypassEncryption = options.bypassAutoEncryption === true;\n\n    this._keyVaultNamespace = options.keyVaultNamespace || 'admin.datakeys';\n    this._keyVaultClient = options.keyVaultClient || client;\n    this._metaDataClient = options.metadataClient || client;\n    this._proxyOptions = options.proxyOptions || {};\n    if (this._proxyOptions.proxyHost && options.kmsConnectCallback) {\n      throw new MongoCryptInvalidArgumentError(\n        'Cannot set both proxyOptions and kmsConnectCallback'\n      );\n    }\n    this._tlsOptions = options.tlsOptions || {};\n    this._kmsConnectCallback = options.kmsConnectCallback;\n    this._kmsProviders = options.kmsProviders || {};\n    this._credentialProviders = options.credentialProviders;\n\n    if (options.credentialProviders?.aws && !isEmptyCredentials('aws', this._kmsProviders)) {\n      throw new MongoCryptInvalidArgumentError(\n        'Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching'\n      );\n    }\n\n    const mongoCryptOptions: MongoCryptOptions = {\n      errorWrapper: defaultErrorWrapper\n    };\n    if (options.schemaMap) {\n      if (ByteUtils.isUint8Array(options.schemaMap)) {\n        mongoCryptOptions.schemaMap = options.schemaMap;\n      } else {\n        mongoCryptOptions.schemaMap = serialize(options.schemaMap);\n      }\n    }\n\n    if (options.encryptedFieldsMap) {\n      if (ByteUtils.isUint8Array(options.encryptedFieldsMap)) {\n        mongoCryptOptions.encryptedFieldsMap = options.encryptedFieldsMap;","sourceCodeStart":246,"sourceCodeEnd":282,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/client-side-encryption/auto_encrypter.ts#L246-L282","documentation":"Thrown by the AutoEncrypter constructor when credentialProviders.aws is defined (a custom AWS credential provider) but kmsProviders.aws contains non-empty static credentials. The driver requires that when using automatic AWS credential fetching via credentialProviders, the kmsProviders.aws entry must be an empty object ({}) to signal that credentials should be obtained dynamically. This is a MongoCryptInvalidArgumentError.","triggerScenarios":"Configuring autoEncryption with both kmsProviders: { aws: { accessKeyId: '...', secretAccessKey: '...' } } and credentialProviders: { aws: async () => {...} }. The conflict is that static credentials are already provided, making the dynamic provider unnecessary and ambiguous.","commonSituations":"Migrating from static AWS credentials to dynamic credential fetching without removing the old kmsProviders.aws credentials; merging config from environment variables (which set static keys) with code that adds a credential provider; misunderstanding that kmsProviders.aws must be {} when using credentialProviders.aws.","solutions":["Set kmsProviders.aws to an empty object {} when using credentialProviders.aws for automatic credential fetching","Remove the credentialProviders.aws callback if you want to keep using static credentials in kmsProviders.aws"],"exampleFix":"// before\nnew MongoClient(uri, {\n  autoEncryption: {\n    kmsProviders: {\n      aws: { accessKeyId: 'AKIA...', secretAccessKey: '...' }\n    },\n    credentialProviders: { aws: myAwsProvider }\n  }\n});\n\n// after (use dynamic fetching)\nnew MongoClient(uri, {\n  autoEncryption: {\n    kmsProviders: { aws: {} },\n    credentialProviders: { aws: myAwsProvider }\n  }\n});","handlingStrategy":"validation","validationCode":"// Before creating the MongoClient\nconst { kmsProviders, credentialProviders } = autoEncryptionConfig;\nif (credentialProviders?.aws && kmsProviders?.aws && Object.keys(kmsProviders.aws).length > 0) {\n  throw new Error('Set kmsProviders.aws to {} when using credentialProviders.aws');\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["When using dynamic AWS credential providers, always set kmsProviders.aws to {}","Do not merge static credentials from environment variables with credentialProviders config","Document which credential strategy is in use to avoid conflicting configurations"],"tags":["csfle","configuration","kms","aws","credentials"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}