mongodb/node-mongodb-native · critical · MongoMissingCredentialsError
AuthContext must provide credentials.
Error message
AuthContext must provide credentials.
What it means
Thrown by ScramSHA.prepare (scram.ts:32) when the AuthContext has no credentials during the speculative-authentication handshake step. SCRAM needs username/password/source to build the first SASL message, so a missing credentials object aborts prepare. Raised as MongoMissingCredentialsError.
Solutions
- Provide username and password in the connection string
- If authenticating to a specific db, set authSource appropriately
- When building MongoClient programmatically, pass auth: { username, password }
Example fix
// before
const client = new MongoClient('mongodb://cluster.example.net');
// after
const client = new MongoClient('mongodb://user:pass@cluster.example.net/?authSource=admin'); Defensive patterns
Strategy: validation
Validate before calling
const u = clientOptions.auth?.username;
const p = clientOptions.auth?.password;
if ((u === undefined || p === undefined) && !/:[^:@]+@/.test(uri)) {
throw new Error('SCRAM auth requires username and password');
} Type guard
function hasScramCreds(auth: { username?: unknown; password?: unknown }): auth is { username: string; password: string } {
return typeof auth.username === 'string' && typeof auth.password === 'string' && auth.password.length > 0;
} Try / catch
try {
await client.connect();
} catch (err) {
if (err instanceof MongoMissingCredentialsError) {
// gather credentials (e.g., secret manager) and reconnect
} else throw err;
} Prevention
- Always provide username and password for auth-enabled clusters
- Set authSource to the database where the user is defined (often 'admin')
- Fetch credentials from a secrets manager at startup, never hardcode
When it happens
Trigger: Connecting with SCRAM-SHA-1 or SCRAM-SHA-256 (the default) but the AuthContext.credentials is null, typically because no username/password were supplied and the server requires authentication.
Common situations: Connecting to an authenticated cluster with mongodb://host:port (no credentials). Default mechanism auto-selection picking SCRAM on a server that requires auth. A programmatic MongoClient with no auth options against an auth-enabled deployment.
Related errors
- Password cannot be empty
- Username required for mechanism
- AuthContext must provide credentials.
- AuthContext must provide credentials.
- AuthContext must provide credentials.
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/3748464d166937fc.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/scram.ts:32
type CryptoMethod = 'sha1' | 'sha256';
class ScramSHA extends AuthProvider {
cryptoMethod: CryptoMethod;
constructor(cryptoMethod: CryptoMethod) {
super();
this.cryptoMethod = cryptoMethod || 'sha1';
}
override async prepare(
handshakeDoc: HandshakeDocument,
authContext: AuthContext
): Promise<HandshakeDocument> {
const cryptoMethod = this.cryptoMethod;
const credentials = authContext.credentials;
if (!credentials) {
throw new MongoMissingCredentialsError('AuthContext must provide credentials.');
}
const nonce = await randomBytes(24);
// store the nonce for later use
authContext.nonce = nonce;
const request = {
...handshakeDoc,
speculativeAuthenticate: {
...makeFirstMessage(cryptoMethod, credentials, nonce),
db: credentials.source
}
};
return request;
}
override async auth(authContext: AuthContext) {View on GitHub (pinned to dce7939f86)