mongodb/node-mongodb-native · error · MongoInvalidArgumentError

Host ' ' is not valid for OIDC authentication with…

Error message

Host '${host}' is not valid for OIDC authentication with ALLOWED_HOSTS of '${allowedHosts.join(',')}'

What it means

During connect (src/mongo_client.ts:655), when OIDC authentication is configured and the environment is NOT a service environment (no ENVIRONMENT set), the driver validates every host in the connection (including SRV-resolved hosts) against ALLOWED_HOSTS. If any host's hostname does not match the allowed list (or the default allowed hosts), it throws MongoInvalidArgumentError. This is a security control preventing OIDC token exchange with untrusted hosts.

Solutions

  1. Add the deployment's host(s) to ALLOWED_HOSTS in mechanismProperties, e.g. ALLOWED_HOSTS: ['cluster.example.com', '*.mongodb.net'].
  2. If using a trusted service environment, set ENVIRONMENT in mechanismProperties to bypass host validation (only for managed environments like Azure/GCP).
  3. Verify the connection string host and any SRV-resolved hosts against the ALLOWED_HOSTS list before connecting.

Example fix

// before
const client = new MongoClient(uri, {
  authMechanismProperties: { ALLOWED_HOSTS: ['trusted.example.com'] },
  auth: { mechanism: 'MONGODB-OIDC', ... }
});
// after
const client = new MongoClient(uri, {
  authMechanismProperties: { ALLOWED_HOSTS: ['trusted.example.com', 'cluster.mongodb.net'] },
  auth: { mechanism: 'MONGODB-OIDC', ... }
});
Defensive patterns

Strategy: validation

Validate before calling

function validateOidcHosts(hosts, allowedHosts) {
  const { hostMatchesWildcards } = require('mongodb'); // or implement locally
  for (const h of hosts) {
    if (!hostMatchesWildcards(h, allowedHosts)) {
      throw new Error(`Host ${h} not in ALLOWED_HOSTS`);
    }
  }
}

Type guard

function isOidcMechanismProperties(v: unknown): v is { ALLOWED_HOSTS: string[]; ENVIRONMENT?: string } {
  return v != null && Array.isArray((v as any).ALLOWED_HOSTS);
}

Try / catch

try {
  await client.connect();
} catch (e) {
  if (e instanceof MongoInvalidArgumentError && /ALLOWED_HOSTS/.test(e.message)) {
    // add the host to ALLOWED_HOSTS and retry
  } else throw e;
}

Prevention

When it happens

Trigger: Connecting with mechanism 'MONGODB-OIDC' to a host whose domain is not in ALLOWED_HOSTS. Using mongodb+srv:// where SRV resolution yields a host outside the allowed set. Setting a custom ALLOWED_HOSTS that omits the deployment's domain.

Common situations: Misconfigured ALLOWED_HOSTS (typo, missing domain, overly restrictive wildcard). Connecting to a new cluster region/shard not added to the allowed list. SRV records expanding to hosts the caller did not anticipate.

Understand the failure class

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/78f1d195b52a8640. Report an issue: GitHub.

Appendix: source

Thrown at src/mongo_client.ts:662

    }
    if (typeof options.srvHost === 'string') {
      const hosts = await resolveSRVRecord(options);

      for (const [index, host] of hosts.entries()) {
        options.hosts[index] = host;
      }
    }

    // It is important to perform validation of hosts AFTER SRV resolution, to check the real hostname,
    // but BEFORE we even attempt connecting with a potentially not allowed hostname
    if (options.credentials?.mechanism === AuthMechanism.MONGODB_OIDC) {
      const allowedHosts =
        options.credentials?.mechanismProperties?.ALLOWED_HOSTS || DEFAULT_ALLOWED_HOSTS;
      const isServiceAuth = !!options.credentials?.mechanismProperties?.ENVIRONMENT;
      if (!isServiceAuth) {
        for (const host of options.hosts) {
          if (!hostMatchesWildcards(host.toHostPort().host, allowedHosts)) {
            throw new MongoInvalidArgumentError(
              `Host '${host}' is not valid for OIDC authentication with ALLOWED_HOSTS of '${allowedHosts.join(
                ','
              )}'`
            );
          }
        }
      }
    }

    this.topology = new Topology(this, options.hosts, options);
    // Events can be emitted before initialization is complete so we have to
    // save the reference to the topology on the client ASAP if the event handlers need to access it

    this.topology.once(Topology.OPEN, () => this.emit('open', this));

    for (const event of MONGO_CLIENT_EVENTS) {
      this.topology.on(event, (...args: any[]) => this.emit(event, ...(args as any)));
    }

View on GitHub (pinned to dce7939f86)