mongodb/node-mongodb-native · error · MongoAzureError

Azure endpoint did not return a value with only…

Error message

Azure endpoint did not return a value with only access_token and expires_in properties

What it means

Thrown by the Azure machine workflow when the Azure IMDS endpoint response does not contain a valid access_token and expires_in. After fetching the token JSON and mapping it to { accessToken, expiresInSeconds }, isEndpointResultValid() returns false if either field is missing or the wrong type, indicating the endpoint returned an unexpected shape.

Solutions

  1. Verify the managed identity is assigned to the VM/container and has permission to request tokens for the configured audience.
  2. Confirm TOKEN_RESOURCE matches the audience Azure is configured to issue.
  3. Inspect the raw IMDS response manually (curl with Metadata:true) to see what JSON shape is returned and adjust accordingly.
Defensive patterns

Strategy: try-catch

Validate before calling

function looksLikeAzureToken(j) {
  return j && typeof j.access_token === 'string' && j.expires_in != null;
}

Type guard

function isAzureTokenShape(j): j is { access_token: string; expires_in: number|string } {
  return !!j && typeof j.access_token === 'string' && j.expires_in != null;
}

Try / catch

try {
  await client.connect();
} catch (e) {
  if (e instanceof MongoAzureError && /access_token and expires_in/.test(e.message)) {
    // curl the IMDS endpoint manually to inspect the actual payload
  }
  throw e;
}

Prevention

When it happens

Trigger: Azure IMDS replied with a 200 body that lacks access_token / expires_in, or includes them as wrong types. Fires at azure_machine_workflow.ts:32 after the response is parsed and validated.

Common situations: The Azure endpoint changed its response shape. Wrong TOKEN_RESOURCE/audience causing Azure to return a different JSON structure (e.g. an error envelope with 200 status). Managed identity not assigned to the resource, returning an error payload.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/838ebabacdfe7b4e. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts:32

const TOKEN_RESOURCE_MISSING_ERROR =
  'TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure.';

/**
 * The callback function to be used in the automated callback workflow.
 * @param params - The OIDC callback parameters.
 * @returns The OIDC response.
 */
export const azureCallback: OIDCCallbackFunction = async (
  params: OIDCCallbackParams
): Promise<OIDCResponse> => {
  const tokenAudience = params.tokenAudience;
  const username = params.username;
  if (!tokenAudience) {
    throw new MongoAzureError(TOKEN_RESOURCE_MISSING_ERROR);
  }
  const response = await getAzureTokenData(tokenAudience, username);
  if (!isEndpointResultValid(response)) {
    throw new MongoAzureError(ENDPOINT_RESULT_ERROR);
  }
  return response;
};

/**
 * Hit the Azure endpoint to get the token data.
 */
async function getAzureTokenData(tokenAudience: string, username?: string): Promise<OIDCResponse> {
  const url = new URL(AZURE_BASE_URL);
  addAzureParams(url, tokenAudience, username);
  const response = await get(url, {
    headers: AZURE_HEADERS
  });
  if (response.status !== 200) {
    throw new MongoAzureError(
      `Status code ${response.status} returned from the Azure endpoint. Response body: ${response.body}`
    );
  }

View on GitHub (pinned to dce7939f86)