mongodb/node-mongodb-native · error · MongoMissingCredentialsError
Could not obtain temporary MONGODB-AWS credentials
Error message
Could not obtain temporary MONGODB-AWS credentials
What it means
Thrown inside makeTempCredentials() when the AWS credential provider returned temporary credentials that lack AccessKeyId or SecretAccessKey. After attempting to fetch credentials from the environment/IMDS/IAM role, the result was incomplete, so the driver cannot construct a valid MongoCredentials for MONGODB-AWS.
Solutions
- If using an IAM role, verify the role is attached and IMDS connectivity works (curl http://169.254.169.254/latest/meta-data/iam/security-credentials/).
- Provide static credentials explicitly (AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY env vars or username/password) to bypass the metadata path.
- Check for AWS_SESSION_TOKEN requirements when using temporary STS credentials.
Example fix
// before: relying on IMDS that returns nothing
new MongoClient('mongodb://host/?authMechanism=MONGODB-AWS');
// after: explicit static credentials
process.env.AWS_ACCESS_KEY_ID='AKIA...';
process.env.AWS_SECRET_ACCESS_KEY='secret';
new MongoClient('mongodb://host/?authMechanism=MONGODB-AWS'); Defensive patterns
Strategy: validation
Validate before calling
async function assertAwsCredsResolvable(fetcher) {
const c = await fetcher.getCredentials();
if (!c.AccessKeyId || !c.SecretAccessKey) {
throw new Error('AWS credential provider returned incomplete credentials.');
}
} Try / catch
try {
await client.connect();
} catch (e) {
if (e instanceof MongoMissingCredentialsError && /temporary MONGODB-AWS/.test(e.message)) {
// fall back to explicit AWS env vars or static keys
}
throw e;
} Prevention
- Set AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY explicitly in dev.
- Verify the IAM role/IMDS path works before relying on it in prod.
- Add a pre-connect credential probe in startup scripts.
When it happens
Trigger: AWSSDKCredentialProvider.getCredentials() resolves but the returned object has no AccessKeyId and/or no SecretAccessKey. Fires at mongodb_aws.ts:144.
Common situations: Running on an EC2/ECS/EKS instance whose IAM role has no permission, or IMDS is unreachable returning empty data. AWS env vars set to empty strings. A misconfigured credential provider. Instance metadata service throttled/denied.
Related errors
- ${error.message}
- AuthContext must provide credentials.
- AuthContext must provide credentials.
- AuthContext must provide credentials.
- AuthContext must provide credentials.
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/660d60282aeb9050.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/mongodb_aws.ts:144
const saslContinue = {
saslContinue: 1,
conversationId: saslStartResponse.conversationId,
payload: BSON.serialize(payload, bsonOptions)
};
await connection.command(ns(`${db}.$cmd`), saslContinue, undefined);
}
}
async function makeTempCredentials(
credentials: MongoCredentials,
awsCredentialFetcher: AWSSDKCredentialProvider
): Promise<MongoCredentials> {
function makeMongoCredentialsFromAWSTemp(creds: AWSTempCredentials) {
// The AWS session token (creds.Token) may or may not be set.
if (!creds.AccessKeyId || !creds.SecretAccessKey) {
throw new MongoMissingCredentialsError('Could not obtain temporary MONGODB-AWS credentials');
}
return new MongoCredentials({
username: creds.AccessKeyId,
password: creds.SecretAccessKey,
source: credentials.source,
mechanism: AuthMechanism.MONGODB_AWS,
mechanismProperties: {
AWS_SESSION_TOKEN: creds.Token
}
});
}
const temporaryCredentials = await awsCredentialFetcher.getCredentials();
return makeMongoCredentialsFromAWSTemp(temporaryCredentials);
}
function deriveRegion(host: string) {View on GitHub (pinned to dce7939f86)