mongodb/node-mongodb-native · error · MongoAzureError
Azure endpoint did not return a value with only…
Error message
Azure endpoint did not return a value with only access_token and expires_in properties
What it means
Thrown by the Azure machine workflow when the Azure IMDS endpoint response does not contain a valid access_token and expires_in. After fetching the token JSON and mapping it to { accessToken, expiresInSeconds }, isEndpointResultValid() returns false if either field is missing or the wrong type, indicating the endpoint returned an unexpected shape.
Solutions
- Verify the managed identity is assigned to the VM/container and has permission to request tokens for the configured audience.
- Confirm TOKEN_RESOURCE matches the audience Azure is configured to issue.
- Inspect the raw IMDS response manually (curl with Metadata:true) to see what JSON shape is returned and adjust accordingly.
Defensive patterns
Strategy: try-catch
Validate before calling
function looksLikeAzureToken(j) {
return j && typeof j.access_token === 'string' && j.expires_in != null;
} Type guard
function isAzureTokenShape(j): j is { access_token: string; expires_in: number|string } {
return !!j && typeof j.access_token === 'string' && j.expires_in != null;
} Try / catch
try {
await client.connect();
} catch (e) {
if (e instanceof MongoAzureError && /access_token and expires_in/.test(e.message)) {
// curl the IMDS endpoint manually to inspect the actual payload
}
throw e;
} Prevention
- Verify the managed identity is assigned to the resource.
- Confirm the TOKEN_RESOURCE/audience is accepted by Azure.
- Inspect the raw IMDS response when the shape is unexpected.
When it happens
Trigger: Azure IMDS replied with a 200 body that lacks access_token / expires_in, or includes them as wrong types. Fires at azure_machine_workflow.ts:32 after the response is parsed and validated.
Common situations: The Azure endpoint changed its response shape. Wrong TOKEN_RESOURCE/audience causing Azure to return a different JSON structure (e.g. an error envelope with 200 status). Managed identity not assigned to the resource, returning an error payload.
Related errors
- Status code returned from the Azure endpoint. Response body
- Status code returned from the GCP endpoint. Response body
- TOKEN_RESOURCE must be set in the auth mechanism properties…
- TOKEN_RESOURCE must be set in the auth mechanism properties…
- Auth mechanism property ALLOWED_HOSTS must be an array of…
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/838ebabacdfe7b4e.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts:32
const TOKEN_RESOURCE_MISSING_ERROR =
'TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure.';
/**
* The callback function to be used in the automated callback workflow.
* @param params - The OIDC callback parameters.
* @returns The OIDC response.
*/
export const azureCallback: OIDCCallbackFunction = async (
params: OIDCCallbackParams
): Promise<OIDCResponse> => {
const tokenAudience = params.tokenAudience;
const username = params.username;
if (!tokenAudience) {
throw new MongoAzureError(TOKEN_RESOURCE_MISSING_ERROR);
}
const response = await getAzureTokenData(tokenAudience, username);
if (!isEndpointResultValid(response)) {
throw new MongoAzureError(ENDPOINT_RESULT_ERROR);
}
return response;
};
/**
* Hit the Azure endpoint to get the token data.
*/
async function getAzureTokenData(tokenAudience: string, username?: string): Promise<OIDCResponse> {
const url = new URL(AZURE_BASE_URL);
addAzureParams(url, tokenAudience, username);
const response = await get(url, {
headers: AZURE_HEADERS
});
if (response.status !== 200) {
throw new MongoAzureError(
`Status code ${response.status} returned from the Azure endpoint. Response body: ${response.body}`
);
}View on GitHub (pinned to dce7939f86)