mongodb/node-mongodb-native · error · MongoCryptInvalidArgumentError

Cannot set both proxyOptions and kmsConnectCallback

Error message

Cannot set both proxyOptions and kmsConnectCallback

What it means

Thrown by the AutoEncrypter constructor when both proxyOptions (with a proxyHost) and kmsConnectCallback are provided in the autoEncryption configuration. These are two mutually exclusive mechanisms for controlling how the driver connects to KMS providers: proxyOptions configures a SOCKS5 proxy, while kmsConnectCallback provides a custom socket factory. This is a MongoCryptInvalidArgumentError.

Solutions

  1. Use only one KMS connection mechanism: either proxyOptions or kmsConnectCallback, not both
  2. If you need an HTTP CONNECT proxy, use kmsConnectCallback and remove proxyOptions
  3. If you need a SOCKS5 proxy, use proxyOptions and remove kmsConnectCallback

Example fix

// before
new MongoClient(uri, {
  autoEncryption: {
    proxyOptions: { proxyHost: 'proxy.example.com', proxyPort: 1080 },
    kmsConnectCallback: myCallback,
    kmsProviders: { ... }
  }
});

// after (choose one)
new MongoClient(uri, {
  autoEncryption: {
    kmsConnectCallback: myCallback,
    kmsProviders: { ... }
  }
});
Defensive patterns

Strategy: validation

Validate before calling

// Before creating the MongoClient
const { proxyOptions, kmsConnectCallback } = autoEncryptionConfig;
if (proxyOptions?.proxyHost && kmsConnectCallback) {
  throw new Error('Cannot set both proxyOptions and kmsConnectCallback; choose one');
}

Prevention

When it happens

Trigger: Creating a MongoClient with autoEncryption options that include both proxyOptions: { proxyHost: '...' } and kmsConnectCallback: fn. The constructor validates this before any connection is attempted.

Common situations: Configuring CSFLE behind a corporate proxy and mistakenly providing both SOCKS5 proxy settings and a custom HTTP CONNECT callback; merging configuration objects from different sources without removing the conflicting key.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/ef3be7128e9dd93e. Report an issue: GitHub.

Appendix: source

Thrown at src/client-side-encryption/auto_encrypter.ts:254

   *       cryptSharedLibRequired: true
   *     }
   *   }
   * });
   * ```
   *
   * await client.connect();
   * // From here on, the client will be encrypting / decrypting automatically
   */
  constructor(client: MongoClient, options: AutoEncryptionOptions) {
    this._client = client;
    this._bypassEncryption = options.bypassAutoEncryption === true;

    this._keyVaultNamespace = options.keyVaultNamespace || 'admin.datakeys';
    this._keyVaultClient = options.keyVaultClient || client;
    this._metaDataClient = options.metadataClient || client;
    this._proxyOptions = options.proxyOptions || {};
    if (this._proxyOptions.proxyHost && options.kmsConnectCallback) {
      throw new MongoCryptInvalidArgumentError(
        'Cannot set both proxyOptions and kmsConnectCallback'
      );
    }
    this._tlsOptions = options.tlsOptions || {};
    this._kmsConnectCallback = options.kmsConnectCallback;
    this._kmsProviders = options.kmsProviders || {};
    this._credentialProviders = options.credentialProviders;

    if (options.credentialProviders?.aws && !isEmptyCredentials('aws', this._kmsProviders)) {
      throw new MongoCryptInvalidArgumentError(
        'Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching'
      );
    }

    const mongoCryptOptions: MongoCryptOptions = {
      errorWrapper: defaultErrorWrapper
    };
    if (options.schemaMap) {

View on GitHub (pinned to dce7939f86)