{"record":{"id":"f578c0ca7f4dded4","repo":"mongodb/node-mongodb-native","slug":"node-js-crypto-module-is-required-for-scram-sha-1","errorCode":null,"errorMessage":"Node.js crypto module is required for SCRAM-SHA-1 authentication","messagePattern":"Node\\.js crypto module is required for SCRAM-SHA-1 authentication","errorType":"exception","errorClass":"MongoRuntimeError","httpStatus":null,"severity":"critical","filePath":"src/cmap/auth/scram.ts","lineNumber":236,"sourceCode":"  if (typeof username !== 'string') {\n    throw new MongoInvalidArgumentError('Username must be a string');\n  }\n\n  if (typeof password !== 'string') {\n    throw new MongoInvalidArgumentError('Password must be a string');\n  }\n\n  if (password.length === 0) {\n    throw new MongoInvalidArgumentError('Password cannot be empty');\n  }\n\n  let nodeCrypto;\n  try {\n    // TODO: NODE-7424 - remove dependency on 'crypto' for SCRAM-SHA-1 authentication\n    // eslint-disable-next-line @typescript-eslint/no-require-imports\n    nodeCrypto = require('crypto');\n  } catch (e) {\n    throw new MongoRuntimeError(\n      'Node.js crypto module is required for SCRAM-SHA-1 authentication',\n      {\n        cause: e\n      }\n    );\n  }\n\n  try {\n    const md5 = nodeCrypto.createHash('md5');\n    md5.update(`${username}:mongo:${password}`, 'utf8');\n    return md5.digest('hex');\n  } catch (err) {\n    if (nodeCrypto.getFips()) {\n      // This error is (slightly) more helpful than what comes from OpenSSL directly, e.g.\n      // 'Error: error:060800C8:digital envelope routines:EVP_DigestInit_ex:disabled for FIPS'\n      throw new Error('Auth mechanism SCRAM-SHA-1 is not supported in FIPS mode');\n    }\n    throw err;","sourceCodeStart":218,"sourceCodeEnd":254,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/scram.ts#L218-L254","documentation":"Thrown as a MongoRuntimeError (with the caught require error as cause) when require('crypto') fails inside passwordDigest(). The Node.js 'crypto' built-in module is required specifically for the SCRAM-SHA-1 MD5 digest; the SCRAM-SHA-256 path uses the WebCrypto global (crypto.subtle) instead. A failing require of a built-in module is abnormal and signals a broken or non-standard runtime.","triggerScenarios":"Authenticating via SCRAM-SHA-1 in an environment where the Node.js 'crypto' built-in is unavailable or blocked: certain bundlers (webpack/browserify) that shim require(), sandboxed serverless runtimes that strip built-ins, or a corrupted Node.js install. Also reachable if a custom module loader intercepts require('crypto').","commonSituations":"Bundling the driver for a browser/edge runtime that lacks Node 'crypto'; running under a hardened Lambda/container that blocks the crypto native addon; a misconfigured ts-serverless or esbuild setup that polyfills 'crypto' with an error stub.","solutions":["Run the driver in a standard Node.js runtime where the 'crypto' built-in is available","If targeting a bundler, mark 'crypto' as external (webpack node.exports or esbuild --external:crypto)","Switch the auth mechanism to SCRAM-SHA-256 (which uses WebCrypto) if the environment supports crypto.subtle but not the crypto module","Reinstall or repair the Node.js installation if the built-in module is genuinely missing"],"exampleFix":"// before: SCRAM-SHA-1 requires Node crypto module\nconst client = new MongoClient('mongodb://user:pass@host/db?authMechanism=SCRAM-SHA-1');\n\n// after: prefer SCRAM-SHA-256 (server 4.0+) which uses WebCrypto\nconst client = new MongoClient('mongodb://user:pass@host/db?authMechanism=SCRAM-SHA-256');","handlingStrategy":"validation","validationCode":"let cryptoOk = true;\ntry { require('crypto'); } catch { cryptoOk = false; }\nif (!cryptoOk && uri.includes('SCRAM-SHA-1')) {\n  throw new Error('SCRAM-SHA-1 needs Node crypto module; use SCRAM-SHA-256 or run under Node');\n}","typeGuard":"function nodeCryptoAvailable(): boolean {\n  try { require('crypto'); return true; } catch { return false; }\n}","tryCatchPattern":null,"preventionTips":["Run the driver under a full Node.js runtime, not a browser/edge bundle","Mark 'crypto' as external in bundler configs","Prefer SCRAM-SHA-256 (WebCrypto) for environments that lack the Node crypto module"],"tags":["authentication","scram","runtime","bundling","node-js"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}