mongodb/node-mongodb-native · error · MongoMissingCredentialsError
AuthContext must provide credentials.
Error message
AuthContext must provide credentials.
What it means
Thrown at the start of the MONGODB-AWS auth provider's auth() method when the AuthContext carries no credentials. AWS authentication needs an access key id / secret access key (or a credential provider chain to fetch them); without any credentials the workflow cannot begin.
Solutions
- Provide static AWS credentials via username/password in the connection string, or via the AWS_* environment variables.
- Run the client on an EC2/ECS/EKS instance with an IAM role so the SDK credential provider chain can fetch temporary credentials.
- If using authMechanism=MONGODB-AWS explicitly, ensure at least one credential source is available before connect().
Example fix
// before
new MongoClient('mongodb://host/?authMechanism=MONGODB-AWS');
// after
new MongoClient('mongodb://AKIA...:secret@host/?authMechanism=MONGODB-AWS'); Defensive patterns
Strategy: validation
Validate before calling
function assertAwsCredentialsPresent(opts, env=process.env) {
const hasStatic = opts.auth?.username || env.AWS_ACCESS_KEY_ID;
const hasRole = env.AWS_CONTAINER_CREDENTIALS_RELATIVE_URI || env.AWS_WEB_IDENTITY_TOKEN_FILE || env.AWS_ROLE_SESSION_NAME;
if (opts.auth?.mechanism === 'MONGODB-AWS' && !hasStatic && !hasRole) {
throw new Error('MONGODB-AWS needs static keys, IAM role, or AWS env vars.');
}
} Try / catch
try {
await client.connect();
} catch (e) {
if (e instanceof MongoMissingCredentialsError && /AWS/.test(String(e.message))) {
// surface guidance to attach an IAM role or set AWS env vars
}
throw e;
} Prevention
- Set AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY in dev, attach an IAM role in prod.
- Validate credential availability in a startup check before connecting.
- Avoid forcing MONGODB-AWS unless AWS credentials are guaranteed present.
When it happens
Trigger: The driver selected MONGODB-AWS as the auth mechanism but no username/password and no AWS credential provider resolved to credentials. Fires at mongodb_aws.ts:41 inside MongoDBAWS.auth().
Common situations: Specifying authMechanism=MONGODB-AWS while neither setting AWS env vars (AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY) nor providing credentials, and not running in an IAM-role environment. Forgetting to pass the username/password for static AWS keys.
Related errors
- AuthContext must provide credentials.
- AuthContext must provide credentials.
- AuthContext must provide credentials.
- AuthMechanism ' ' not supported
- Can only provide a custom AWS credential provider when the…
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/0042aecded465ba8.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/mongodb_aws.ts:41
interface AWSSaslContinuePayload {
a: string;
d: string;
t?: string;
}
export class MongoDBAWS extends AuthProvider {
private credentialFetcher: AWSSDKCredentialProvider;
constructor(credentialProvider?: AWSCredentialProvider) {
super();
this.credentialFetcher = new AWSSDKCredentialProvider(credentialProvider);
}
override async auth(authContext: AuthContext): Promise<void> {
const { connection } = authContext;
if (!authContext.credentials) {
throw new MongoMissingCredentialsError('AuthContext must provide credentials.');
}
authContext.credentials = await makeTempCredentials(
authContext.credentials,
this.credentialFetcher
);
const { credentials } = authContext;
const accessKeyId = credentials.username;
const secretAccessKey = credentials.password;
// Allow the user to specify an AWS session token for authentication with temporary credentials.
const sessionToken = credentials.mechanismProperties.AWS_SESSION_TOKEN;
// If all three defined, include sessionToken, else only include username and pass
const awsCredentials = sessionToken
? { accessKeyId, secretAccessKey, sessionToken }
: { accessKeyId, secretAccessKey };View on GitHub (pinned to dce7939f86)