mongodb/node-mongodb-native · error · MongoInvalidArgumentError

Currently only a ENVIRONMENT in

Error message

Currently only a ENVIRONMENT in ${ALLOWED_ENVIRONMENT_NAMES.join(',')} is supported for mechanism '${this.mechanism}'.

What it means

Thrown by MongoCredentials.validate() when MONGODB-OIDC is configured with an ENVIRONMENT value not in the allowed set (test, azure, gcp, k8s). The driver only ships machine-workflow implementations for those environments; any other string is rejected at validation time.

Solutions

  1. Use one of the supported ENVIRONMENT values: 'test', 'azure', 'gcp', or 'k8s' (lowercase, exact).
  2. If you need a custom/token-source flow, omit ENVIRONMENT and provide OIDC_CALLBACK or OIDC_HUMAN_CALLBACK instead.
  3. For AWS authentication, switch the mechanism to MONGODB-AWS rather than MONGODB-OIDC with ENVIRONMENT:'aws'.

Example fix

// before
mechanismProperties: { ENVIRONMENT: 'aws' }
// after (custom flow)
mechanismProperties: { OIDC_CALLBACK: myCallback }
Defensive patterns

Strategy: type-guard

Validate before calling

const ALLOWED = ['test','azure','gcp','k8s'];
function isValidEnv(e) { return e == null || ALLOWED.includes(e); }

Type guard

function isOidcEnvironment(v): v is 'test'|'azure'|'gcp'|'k8s' {
  return ['test','azure','gcp','k8s'].includes(v);
}

Prevention

When it happens

Trigger: Providing authMechanismProperties={ ENVIRONMENT: '<anything-not-test/azure/gcp/k8s>' } with mechanism MONGODB-OIDC. Fires during validate() on the first auth attempt.

Common situations: Typos like ENVIRONMENT:'aws' (AWS is not an OIDC machine environment; use MONGODB-AWS mechanism instead). Using 'local' or 'development' expecting a built-in workflow. Case-sensitivity mistakes ('Azure' vs 'azure').

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/b6efba8df15dc4c1. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/auth/mongo_credentials.ts:220

      if (this.username && this.password) {
        throw new MongoInvalidArgumentError(
          `No password is allowed in ENVIRONMENT '${this.mechanismProperties.ENVIRONMENT}' for '${this.mechanism}'.`
        );
      }

      if (
        (this.mechanismProperties.ENVIRONMENT === 'azure' ||
          this.mechanismProperties.ENVIRONMENT === 'gcp') &&
        !this.mechanismProperties.TOKEN_RESOURCE
      ) {
        throw new MongoInvalidArgumentError(TOKEN_RESOURCE_MISSING_ERROR);
      }

      if (
        this.mechanismProperties.ENVIRONMENT &&
        !ALLOWED_ENVIRONMENT_NAMES.includes(this.mechanismProperties.ENVIRONMENT)
      ) {
        throw new MongoInvalidArgumentError(
          `Currently only a ENVIRONMENT in ${ALLOWED_ENVIRONMENT_NAMES.join(
            ','
          )} is supported for mechanism '${this.mechanism}'.`
        );
      }

      if (
        !this.mechanismProperties.ENVIRONMENT &&
        !this.mechanismProperties.OIDC_CALLBACK &&
        !this.mechanismProperties.OIDC_HUMAN_CALLBACK
      ) {
        throw new MongoInvalidArgumentError(
          `Either a ENVIRONMENT, OIDC_CALLBACK, or OIDC_HUMAN_CALLBACK must be specified for mechanism '${this.mechanism}'.`
        );
      }

      if (this.mechanismProperties.ALLOWED_HOSTS) {
        const hosts = this.mechanismProperties.ALLOWED_HOSTS;

View on GitHub (pinned to dce7939f86)