mongodb/node-mongodb-native · error · MongoCryptInvalidArgumentError
Cannot set both proxyOptions and kmsConnectCallback
Error message
Cannot set both proxyOptions and kmsConnectCallback
What it means
Thrown by the AutoEncrypter constructor when both proxyOptions (with a proxyHost) and kmsConnectCallback are provided in the autoEncryption configuration. These are two mutually exclusive mechanisms for controlling how the driver connects to KMS providers: proxyOptions configures a SOCKS5 proxy, while kmsConnectCallback provides a custom socket factory. This is a MongoCryptInvalidArgumentError.
Solutions
- Use only one KMS connection mechanism: either proxyOptions or kmsConnectCallback, not both
- If you need an HTTP CONNECT proxy, use kmsConnectCallback and remove proxyOptions
- If you need a SOCKS5 proxy, use proxyOptions and remove kmsConnectCallback
Example fix
// before
new MongoClient(uri, {
autoEncryption: {
proxyOptions: { proxyHost: 'proxy.example.com', proxyPort: 1080 },
kmsConnectCallback: myCallback,
kmsProviders: { ... }
}
});
// after (choose one)
new MongoClient(uri, {
autoEncryption: {
kmsConnectCallback: myCallback,
kmsProviders: { ... }
}
}); Defensive patterns
Strategy: validation
Validate before calling
// Before creating the MongoClient
const { proxyOptions, kmsConnectCallback } = autoEncryptionConfig;
if (proxyOptions?.proxyHost && kmsConnectCallback) {
throw new Error('Cannot set both proxyOptions and kmsConnectCallback; choose one');
} Prevention
- Review autoEncryption options before constructing MongoClient
- Understand that proxyOptions (SOCKS5) and kmsConnectCallback (custom socket) are mutually exclusive
- When merging config objects, check for conflicting KMS connection keys
When it happens
Trigger: Creating a MongoClient with autoEncryption options that include both proxyOptions: { proxyHost: '...' } and kmsConnectCallback: fn. The constructor validates this before any connection is attempted.
Common situations: Configuring CSFLE behind a corporate proxy and mistakenly providing both SOCKS5 proxy settings and a custom HTTP CONNECT callback; merging configuration objects from different sources without removing the conflicting key.
Related errors
- Cannot set both proxyOptions and kmsConnectCallback
- Can only provide a custom AWS credential provider when the…
- Can only provide a custom AWS credential provider when the…
- Auto-encryption requested, but the module is not installed…
- [Azure KMS]
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/ef3be7128e9dd93e.
Report an issue: GitHub.
Appendix: source
Thrown at src/client-side-encryption/auto_encrypter.ts:254
* cryptSharedLibRequired: true
* }
* }
* });
* ```
*
* await client.connect();
* // From here on, the client will be encrypting / decrypting automatically
*/
constructor(client: MongoClient, options: AutoEncryptionOptions) {
this._client = client;
this._bypassEncryption = options.bypassAutoEncryption === true;
this._keyVaultNamespace = options.keyVaultNamespace || 'admin.datakeys';
this._keyVaultClient = options.keyVaultClient || client;
this._metaDataClient = options.metadataClient || client;
this._proxyOptions = options.proxyOptions || {};
if (this._proxyOptions.proxyHost && options.kmsConnectCallback) {
throw new MongoCryptInvalidArgumentError(
'Cannot set both proxyOptions and kmsConnectCallback'
);
}
this._tlsOptions = options.tlsOptions || {};
this._kmsConnectCallback = options.kmsConnectCallback;
this._kmsProviders = options.kmsProviders || {};
this._credentialProviders = options.credentialProviders;
if (options.credentialProviders?.aws && !isEmptyCredentials('aws', this._kmsProviders)) {
throw new MongoCryptInvalidArgumentError(
'Can only provide a custom AWS credential provider when the state machine is configured for automatic AWS credential fetching'
);
}
const mongoCryptOptions: MongoCryptOptions = {
errorWrapper: defaultErrorWrapper
};
if (options.schemaMap) {View on GitHub (pinned to dce7939f86)