{"record":{"id":"fa7bdab88ea17cc8","repo":"mongodb/node-mongodb-native","slug":"could-not-load-workflow-for-environment-authmech","errorCode":null,"errorMessage":"Could not load workflow for environment ${authMechanismProperties.ENVIRONMENT}","messagePattern":"Could not load workflow for environment (.+?)","errorType":"exception","errorClass":"MongoInvalidArgumentError","httpStatus":null,"severity":"error","filePath":"src/mongo_client_auth_providers.ts","lineNumber":81,"sourceCode":"    const provider = providerFunction(authMechanismProperties);\n    this.existingProviders.set(name, provider);\n    return provider;\n  }\n}\n\n/**\n * Gets either a device workflow or callback workflow.\n */\nfunction getWorkflow(authMechanismProperties: AuthMechanismProperties): Workflow {\n  if (authMechanismProperties.OIDC_HUMAN_CALLBACK) {\n    return new HumanCallbackWorkflow(new TokenCache(), authMechanismProperties.OIDC_HUMAN_CALLBACK);\n  } else if (authMechanismProperties.OIDC_CALLBACK) {\n    return new AutomatedCallbackWorkflow(new TokenCache(), authMechanismProperties.OIDC_CALLBACK);\n  } else {\n    const environment = authMechanismProperties.ENVIRONMENT;\n    const workflow = OIDC_WORKFLOWS.get(environment)?.();\n    if (!workflow) {\n      throw new MongoInvalidArgumentError(\n        `Could not load workflow for environment ${authMechanismProperties.ENVIRONMENT}`\n      );\n    }\n    return workflow;\n  }\n}\n","sourceCodeStart":63,"sourceCodeEnd":88,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/mongo_client_auth_providers.ts#L63-L88","documentation":"Thrown during MONGODB-OIDC setup when no callback is supplied and the ENVIRONMENT value is not one of the built-in workflows ('test', 'azure', 'gcp', 'k8s'). The driver needs either an OIDC_CALLBACK/OIDC_HUMAN_CALLBACK or a recognized cloud ENVIRONMENT to construct a token-fetching workflow.","triggerScenarios":"Configuring MONGODB-OIDC with authMechanismProperties.ENVIRONMENT set to an unrecognized value (e.g. 'aws', 'azure-cloud', typo) while omitting both OIDC_CALLBACK and OIDC_HUMAN_CALLBACK.","commonSituations":"Misreading the OIDC spec and assuming AWS is supported via ENVIRONMENT; typos in environment names; using newer cloud providers the driver version doesn't yet ship a built-in workflow for.","solutions":["Use one of the built-in environments: 'test', 'azure', 'gcp', 'k8s'.","If you need a custom or unsupported provider, supply OIDC_CALLBACK (machine) or OIDC_HUMAN_CALLBACK (interactive) via authMechanismProperties instead of ENVIRONMENT.","Upgrade the driver — newer versions may add built-in workflows for additional providers."],"exampleFix":"// before\nconst client = new MongoClient(url, {\n  authMechanismProperties: { ENVIRONMENT: 'aws' } // not supported\n});\n\n// after (custom provider via callback)\nconst client = new MongoClient(url, {\n  authMechanismProperties: { OIDC_CALLBACK: async () => ({ accessToken: getToken() }) }\n});","handlingStrategy":"validation","validationCode":"const OIDC_ENVS = new Set(['test', 'azure', 'gcp', 'k8s']);\nconst props = credentials.authMechanismProperties ?? {};\nif (credentials.mechanism === 'MONGODB-OIDC' && props.ENVIRONMENT &&\n    !OIDC_ENVS.has(props.ENVIRONMENT) &&\n    !props.OIDC_CALLBACK && !props.OIDC_HUMAN_CALLBACK) {\n  throw new Error(`Unknown OIDC ENVIRONMENT: ${props.ENVIRONMENT}`);\n}","typeGuard":"type OidcEnv = 'test' | 'azure' | 'gcp' | 'k8s';\nconst isOidcEnv = (v: unknown): v is OidcEnv =>\n  typeof v === 'string' && ['test','azure','gcp','k8s'].includes(v);","tryCatchPattern":null,"preventionTips":["For custom OIDC providers, prefer OIDC_CALLBACK over ENVIRONMENT.","Pin the driver version so the built-in ENVIRONMENT list does not change under you."],"tags":["authentication","oidc","config"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}