mongodb/node-mongodb-native · error · MongoInvalidArgumentError
Host ' ' is not valid for OIDC authentication with…
Error message
Host '${host}' is not valid for OIDC authentication with ALLOWED_HOSTS of '${allowedHosts.join(',')}' What it means
During connect (src/mongo_client.ts:655), when OIDC authentication is configured and the environment is NOT a service environment (no ENVIRONMENT set), the driver validates every host in the connection (including SRV-resolved hosts) against ALLOWED_HOSTS. If any host's hostname does not match the allowed list (or the default allowed hosts), it throws MongoInvalidArgumentError. This is a security control preventing OIDC token exchange with untrusted hosts.
Solutions
- Add the deployment's host(s) to ALLOWED_HOSTS in mechanismProperties, e.g. ALLOWED_HOSTS: ['cluster.example.com', '*.mongodb.net'].
- If using a trusted service environment, set ENVIRONMENT in mechanismProperties to bypass host validation (only for managed environments like Azure/GCP).
- Verify the connection string host and any SRV-resolved hosts against the ALLOWED_HOSTS list before connecting.
Example fix
// before
const client = new MongoClient(uri, {
authMechanismProperties: { ALLOWED_HOSTS: ['trusted.example.com'] },
auth: { mechanism: 'MONGODB-OIDC', ... }
});
// after
const client = new MongoClient(uri, {
authMechanismProperties: { ALLOWED_HOSTS: ['trusted.example.com', 'cluster.mongodb.net'] },
auth: { mechanism: 'MONGODB-OIDC', ... }
}); Defensive patterns
Strategy: validation
Validate before calling
function validateOidcHosts(hosts, allowedHosts) {
const { hostMatchesWildcards } = require('mongodb'); // or implement locally
for (const h of hosts) {
if (!hostMatchesWildcards(h, allowedHosts)) {
throw new Error(`Host ${h} not in ALLOWED_HOSTS`);
}
}
} Type guard
function isOidcMechanismProperties(v: unknown): v is { ALLOWED_HOSTS: string[]; ENVIRONMENT?: string } {
return v != null && Array.isArray((v as any).ALLOWED_HOSTS);
} Try / catch
try {
await client.connect();
} catch (e) {
if (e instanceof MongoInvalidArgumentError && /ALLOWED_HOSTS/.test(e.message)) {
// add the host to ALLOWED_HOSTS and retry
} else throw e;
} Prevention
- Pre-populate ALLOWED_HOSTS with all domains the deployment may resolve to (including SRV-expanded shards).
- Use a service ENVIRONMENT when running in a managed OIDC provider to bypass host checks safely.
- Validate connection-string hosts against ALLOWED_HOSTS during config bootstrap.
When it happens
Trigger: Connecting with mechanism 'MONGODB-OIDC' to a host whose domain is not in ALLOWED_HOSTS. Using mongodb+srv:// where SRV resolution yields a host outside the allowed set. Setting a custom ALLOWED_HOSTS that omits the deployment's domain.
Common situations: Misconfigured ALLOWED_HOSTS (typo, missing domain, overly restrictive wildcard). Connecting to a new cluster region/shard not added to the allowed list. SRV records expanding to hosts the caller did not anticipate.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- Auth mechanism property ALLOWED_HOSTS is not allowed in the…
- username and ENVIRONMENT
- Auth mechanism property ALLOWED_HOSTS must be an array of…
- AuthContext must provide credentials.
- collection not found
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/78f1d195b52a8640.
Report an issue: GitHub.
Appendix: source
Thrown at src/mongo_client.ts:662
}
if (typeof options.srvHost === 'string') {
const hosts = await resolveSRVRecord(options);
for (const [index, host] of hosts.entries()) {
options.hosts[index] = host;
}
}
// It is important to perform validation of hosts AFTER SRV resolution, to check the real hostname,
// but BEFORE we even attempt connecting with a potentially not allowed hostname
if (options.credentials?.mechanism === AuthMechanism.MONGODB_OIDC) {
const allowedHosts =
options.credentials?.mechanismProperties?.ALLOWED_HOSTS || DEFAULT_ALLOWED_HOSTS;
const isServiceAuth = !!options.credentials?.mechanismProperties?.ENVIRONMENT;
if (!isServiceAuth) {
for (const host of options.hosts) {
if (!hostMatchesWildcards(host.toHostPort().host, allowedHosts)) {
throw new MongoInvalidArgumentError(
`Host '${host}' is not valid for OIDC authentication with ALLOWED_HOSTS of '${allowedHosts.join(
','
)}'`
);
}
}
}
}
this.topology = new Topology(this, options.hosts, options);
// Events can be emitted before initialization is complete so we have to
// save the reference to the topology on the client ASAP if the event handlers need to access it
this.topology.once(Topology.OPEN, () => this.emit('open', this));
for (const event of MONGO_CLIENT_EVENTS) {
this.topology.on(event, (...args: any[]) => this.emit(event, ...(args as any)));
}View on GitHub (pinned to dce7939f86)