mongodb/node-mongodb-native · error · MongoMissingCredentialsError

Could not obtain temporary MONGODB-AWS credentials

Error message

Could not obtain temporary MONGODB-AWS credentials

What it means

Thrown inside makeTempCredentials() when the AWS credential provider returned temporary credentials that lack AccessKeyId or SecretAccessKey. After attempting to fetch credentials from the environment/IMDS/IAM role, the result was incomplete, so the driver cannot construct a valid MongoCredentials for MONGODB-AWS.

Solutions

  1. If using an IAM role, verify the role is attached and IMDS connectivity works (curl http://169.254.169.254/latest/meta-data/iam/security-credentials/).
  2. Provide static credentials explicitly (AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY env vars or username/password) to bypass the metadata path.
  3. Check for AWS_SESSION_TOKEN requirements when using temporary STS credentials.

Example fix

// before: relying on IMDS that returns nothing
new MongoClient('mongodb://host/?authMechanism=MONGODB-AWS');
// after: explicit static credentials
process.env.AWS_ACCESS_KEY_ID='AKIA...';
process.env.AWS_SECRET_ACCESS_KEY='secret';
new MongoClient('mongodb://host/?authMechanism=MONGODB-AWS');
Defensive patterns

Strategy: validation

Validate before calling

async function assertAwsCredsResolvable(fetcher) {
  const c = await fetcher.getCredentials();
  if (!c.AccessKeyId || !c.SecretAccessKey) {
    throw new Error('AWS credential provider returned incomplete credentials.');
  }
}

Try / catch

try {
  await client.connect();
} catch (e) {
  if (e instanceof MongoMissingCredentialsError && /temporary MONGODB-AWS/.test(e.message)) {
    // fall back to explicit AWS env vars or static keys
  }
  throw e;
}

Prevention

When it happens

Trigger: AWSSDKCredentialProvider.getCredentials() resolves but the returned object has no AccessKeyId and/or no SecretAccessKey. Fires at mongodb_aws.ts:144.

Common situations: Running on an EC2/ECS/EKS instance whose IAM role has no permission, or IMDS is unreachable returning empty data. AWS env vars set to empty strings. A misconfigured credential provider. Instance metadata service throttled/denied.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/660d60282aeb9050. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/auth/mongodb_aws.ts:144

    const saslContinue = {
      saslContinue: 1,
      conversationId: saslStartResponse.conversationId,
      payload: BSON.serialize(payload, bsonOptions)
    };

    await connection.command(ns(`${db}.$cmd`), saslContinue, undefined);
  }
}

async function makeTempCredentials(
  credentials: MongoCredentials,
  awsCredentialFetcher: AWSSDKCredentialProvider
): Promise<MongoCredentials> {
  function makeMongoCredentialsFromAWSTemp(creds: AWSTempCredentials) {
    // The AWS session token (creds.Token) may or may not be set.
    if (!creds.AccessKeyId || !creds.SecretAccessKey) {
      throw new MongoMissingCredentialsError('Could not obtain temporary MONGODB-AWS credentials');
    }

    return new MongoCredentials({
      username: creds.AccessKeyId,
      password: creds.SecretAccessKey,
      source: credentials.source,
      mechanism: AuthMechanism.MONGODB_AWS,
      mechanismProperties: {
        AWS_SESSION_TOKEN: creds.Token
      }
    });
  }
  const temporaryCredentials = await awsCredentialFetcher.getCredentials();

  return makeMongoCredentialsFromAWSTemp(temporaryCredentials);
}

function deriveRegion(host: string) {

View on GitHub (pinned to dce7939f86)