{"record":{"id":"f3a4b397db78e5f2","repo":"mongodb/node-mongodb-native","slug":"token-resource-must-be-set-in-the-auth-mechanism-p","errorCode":null,"errorMessage":"TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure or gcp.","messagePattern":"TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure or gcp\\.","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/mongo_credentials.ts","lineNumber":213,"sourceCode":"        this.mechanismProperties.ENVIRONMENT !== 'azure'\n      ) {\n        throw new MongoInvalidArgumentError(\n          `username and ENVIRONMENT '${this.mechanismProperties.ENVIRONMENT}' may not be used together for mechanism '${this.mechanism}'.`\n        );\n      }\n\n      if (this.username && this.password) {\n        throw new MongoInvalidArgumentError(\n          `No password is allowed in ENVIRONMENT '${this.mechanismProperties.ENVIRONMENT}' for '${this.mechanism}'.`\n        );\n      }\n\n      if (\n        (this.mechanismProperties.ENVIRONMENT === 'azure' ||\n          this.mechanismProperties.ENVIRONMENT === 'gcp') &&\n        !this.mechanismProperties.TOKEN_RESOURCE\n      ) {\n        throw new MongoInvalidArgumentError(TOKEN_RESOURCE_MISSING_ERROR);\n      }\n\n      if (\n        this.mechanismProperties.ENVIRONMENT &&\n        !ALLOWED_ENVIRONMENT_NAMES.includes(this.mechanismProperties.ENVIRONMENT)\n      ) {\n        throw new MongoInvalidArgumentError(\n          `Currently only a ENVIRONMENT in ${ALLOWED_ENVIRONMENT_NAMES.join(\n            ','\n          )} is supported for mechanism '${this.mechanism}'.`\n        );\n      }\n\n      if (\n        !this.mechanismProperties.ENVIRONMENT &&\n        !this.mechanismProperties.OIDC_CALLBACK &&\n        !this.mechanismProperties.OIDC_HUMAN_CALLBACK\n      ) {","sourceCodeStart":195,"sourceCodeEnd":231,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/mongo_credentials.ts#L195-L231","documentation":"Thrown by MongoCredentials.validate() when ENVIRONMENT is set to 'azure' or 'gcp' for MONGODB-OIDC but no TOKEN_RESOURCE (token audience) is supplied. The Azure and GCP metadata endpoints require an audience parameter to mint a token scoped to your MongoDB provider, so the driver refuses to proceed without it.","triggerScenarios":"Setting authMechanismProperties={ ENVIRONMENT: 'azure' } (or 'gcp') without a TOKEN_RESOURCE property. Occurs at connection/auth time inside validate().","commonSituations":"Following a tutorial that enables ENVIRONMENT=azure but omits the TOKEN_RESOURCE parameter. Assuming the cloud metadata endpoint returns a usable token without specifying the intended audience.","solutions":["Add TOKEN_RESOURCE to authMechanismProperties, set to the audience/URI your MongoDB provider expects (e.g. the Atlas/ImmuDB/Data Federation ARN or app ID).","For Azure: authMechanismProperties={ ENVIRONMENT:'azure', TOKEN_RESOURCE:'<audience>' }.","Verify the TOKEN_RESOURCE value matches what the identity provider is configured to issue tokens for."],"exampleFix":"// before\nnew MongoClient(url, { auth: { mechanism:'MONGODB-OIDC', mechanismProperties:{ ENVIRONMENT:'azure' } } });\n// after\nnew MongoClient(url, { auth: { mechanism:'MONGODB-OIDC', mechanismProperties:{ ENVIRONMENT:'azure', TOKEN_RESOURCE:'https://your-audience' } } });","handlingStrategy":"validation","validationCode":"function assertOidcTokenResource(props) {\n  if ((props?.ENVIRONMENT === 'azure' || props?.ENVIRONMENT === 'gcp') && !props?.TOKEN_RESOURCE) {\n    throw new Error('TOKEN_RESOURCE is required for ENVIRONMENT azure/gcp.');\n  }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always pair ENVIRONMENT:'azure'/'gcp' with a TOKEN_RESOURCE constant from config.","Add a startup self-test that validates mechanismProperties before connecting.","Document the required audience value next to the ENVIRONMENT setting."],"tags":["authentication","oidc","azure","gcp","configuration"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}