mongodb/node-mongodb-native · error · MongoMissingCredentialsError
Connection is missing credentials when asked to…
Error message
Connection is missing credentials when asked to reauthenticate
What it means
A MongoMissingCredentialsError thrown in ConnectionPool.reauthenticate when the authContext exists but its credentials property is missing. Reauthentication requires the original credentials to re-run the SASL exchange; without them the driver cannot produce a valid auth attempt. This points to credentials not being captured during MongoClient construction or being dropped from the context.
Solutions
- Provide credentials in the connection string or via authMechanismProperties consistently.
- For X.509/OIDC, ensure the credential callback/properties are set on MongoClient options.
- Verify authSource is correct so credentials are resolved.
- Upgrade the driver to a release with fixes for credential propagation on reauth.
Example fix
// before
const client = new MongoClient('mongodb://host/?authMechanism=MONGODB-X509');
// no tlsCertificateKeyFile / credentials retained
// after
const client = new MongoClient('mongodb://host/?authMechanism=MONGODB-X509&tls=true&tlsCertificateKeyFile=./cert.pem'); Defensive patterns
Strategy: validation
Validate before calling
// Ensure credentials are present before connecting
if (!uri.includes('@') && !options.credentials) {
throw new Error('Credentials required for authenticated deployments');
} Try / catch
try {
await operation();
} catch (e) {
if (e instanceof MongoMissingCredentialsError) {
// supply credentials and reconnect
} else throw e;
} Prevention
- Include credentials in the URI or options consistently.
- For X.509/OIDC, set authMechanismProperties on the client.
- Verify authSource resolves to a database with the user.
When it happens
Trigger: Connecting without credentials in the URI but the server later demands reauthentication (because an initial external token expired, or X.509/OIDC credentials were provided out-of-band and not retained). Also possible via an internal wiring bug that drops credentials from the auth context.
Common situations: Using X.509 or OIDC where credentials come from a callback that was not persisted; connecting with an authSource mismatch so credentials resolve to empty; driver version with a credentials-propagation regression; token-based auth (AWS, OIDC) where the refresh path lost the credential reference.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- Auth mechanism property ALLOWED_HOSTS is not allowed in the…
- AuthContext must provide credentials.
- AuthContext must provide credentials.
- authMechanism requires an authSource of '$external
- ${error.message}
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/742a11f707efc6a8.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/connection_pool.ts:530
);
conn.destroy();
}
this.connections.clear();
this.emitAndLog(ConnectionPool.CONNECTION_POOL_CLOSED, new ConnectionPoolClosedEvent(this));
}
/**
* @internal
* Reauthenticate a connection
*/
async reauthenticate(connection: Connection): Promise<void> {
const authContext = connection.authContext;
if (!authContext) {
throw new MongoRuntimeError('No auth context found on connection.');
}
const credentials = authContext.credentials;
if (!credentials) {
throw new MongoMissingCredentialsError(
'Connection is missing credentials when asked to reauthenticate'
);
}
const resolvedCredentials = credentials.resolveAuthMechanism(connection.hello);
const provider = this.server.topology.client.s.authProviders.getOrCreateProvider(
resolvedCredentials.mechanism,
resolvedCredentials.mechanismProperties
);
if (!provider) {
throw new MongoMissingCredentialsError(
`Reauthenticate failed due to no auth provider for ${credentials.mechanism}`
);
}
await provider.reauth(authContext);
View on GitHub (pinned to dce7939f86)