mongodb/node-mongodb-native · error · MongoCryptInvalidArgumentError
Cannot set both proxyOptions and kmsConnectCallback
Error message
Cannot set both proxyOptions and kmsConnectCallback
What it means
Thrown by the ClientEncryption constructor when both proxyOptions (with a proxyHost) and kmsConnectCallback are provided. These are mutually exclusive KMS connection mechanisms: proxyOptions sets up a SOCKS5 proxy, while kmsConnectCallback lets you provide a custom socket factory. Only one can be active. This is a MongoCryptInvalidArgumentError.
Solutions
- Choose one KMS connection mechanism: either proxyOptions or kmsConnectCallback
- For HTTP CONNECT proxies, use kmsConnectCallback and omit proxyOptions
- For SOCKS5 proxies, use proxyOptions and omit kmsConnectCallback
Example fix
// before
new ClientEncryption(client, {
keyVaultNamespace: 'encryption.__keyVault',
proxyOptions: { proxyHost: 'proxy.example.com', proxyPort: 1080 },
kmsConnectCallback: myCallback,
kmsProviders: { ... }
});
// after (choose one)
new ClientEncryption(client, {
keyVaultNamespace: 'encryption.__keyVault',
kmsConnectCallback: myCallback,
kmsProviders: { ... }
}); Defensive patterns
Strategy: validation
Validate before calling
// Before creating ClientEncryption
const { proxyOptions, kmsConnectCallback } = options;
if (proxyOptions?.proxyHost && kmsConnectCallback) {
throw new Error('Cannot set both proxyOptions and kmsConnectCallback; choose one');
} Prevention
- Review ClientEncryption options for conflicting KMS connection mechanisms
- Use kmsConnectCallback for HTTP CONNECT proxies; use proxyOptions for SOCKS5
- Validate configuration objects before passing them to the constructor
When it happens
Trigger: Creating a new ClientEncryption instance with options that include both proxyOptions: { proxyHost: '...' } and kmsConnectCallback: fn.
Common situations: Configuring explicit encryption (not auto-encryption) with both proxy mechanisms specified; merging configuration presets that each set one of these options; corporate proxy environments where multiple proxy approaches were attempted.
Related errors
- Can only provide a custom AWS credential provider when the…
- Cannot set both proxyOptions and kmsConnectCallback
- Can only provide a custom AWS credential provider when the…
- Missing required option `keyVaultNamespace`
- Unable to complete creating data keys
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/54cecab32e49582d.
Report an issue: GitHub.
Appendix: source
Thrown at src/client-side-encryption/client_encryption.ts:132
*
* @example
* ```ts
* new ClientEncryption(mongoClient, {
* keyVaultNamespace: 'client.encryption',
* kmsProviders: {
* aws: {
* accessKeyId: AWS_ACCESS_KEY,
* secretAccessKey: AWS_SECRET_KEY
* }
* }
* });
* ```
*/
constructor(client: MongoClient, options: ClientEncryptionOptions) {
this._client = client;
this._proxyOptions = options.proxyOptions ?? {};
if (this._proxyOptions.proxyHost && options.kmsConnectCallback) {
throw new MongoCryptInvalidArgumentError(
'Cannot set both proxyOptions and kmsConnectCallback'
);
}
this._tlsOptions = options.tlsOptions ?? {};
this._kmsConnectCallback = options.kmsConnectCallback;
this._kmsProviders = options.kmsProviders || {};
const { timeoutMS } = resolveTimeoutOptions(client, options);
this._timeoutMS = timeoutMS;
this._credentialProviders = options.credentialProviders;
if (options.credentialProviders?.aws && !isEmptyCredentials('aws', this._kmsProviders)) {
throw new MongoCryptInvalidArgumentError(
'Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching'
);
}
if (options.keyVaultNamespace == null) {
throw new MongoCryptInvalidArgumentError('Missing required option `keyVaultNamespace`');View on GitHub (pinned to dce7939f86)