mongodb/node-mongodb-native · error · MongoCryptAzureKMSRequestError
Malformed response body - missing field `access_token`.
Error message
Malformed response body - missing field `access_token`.
What it means
Raised when the Azure IMDS response parsed as JSON but contains no access_token field. The Azure access token is the credential libmongocrypt uses to unwrap the Customer Master Key in Azure Key Vault; its absence means the response is malformed for this provider. MongoCryptAzureKMSRequestError.
Solutions
- Inspect the error's attached body payload for the Azure error/error_description to find the real cause (often 'identity not found' or 'resource disabled').
- Verify the managed identity is enabled and assigned to the resource, and that the Key Vault is in the same tenant.
- Confirm the request reaches the standard resource https://vault.azure.net (the driver sets this; do not override the resource in tests).
- Retry after reassigning the managed identity; propagation can lag.
Defensive patterns
Strategy: try-catch
Try / catch
try {
await clientEncryption.createEncryptedCollection(...);
} catch (e) {
if (e instanceof MongoCryptAzureKMSRequestError && /access_token/.test(e.message)) {
// inspect the attached body for Azure error_description, fix IAM, retry
}
} Prevention
- Ensure the managed identity has permission to request tokens for https://vault.azure.net.
- Log the error's payload field to capture Azure's error_description.
When it happens
Trigger: IMDS returns JSON but with a different shape (e.g. an error envelope like { 'error': {...} } with no access_token); requesting a resource value Azure does not recognize; the managed identity has no permission to the target resource.
Common situations: Wrong 'resource' audience (should be https://vault.azure.net); Azure returning { error, error_description } for a denied token request; the response being a partial JSON object due to truncation; using a custom test URL that omits the token field.
Understand the failure class
- Parsing and encoding errors: unexpected token, malformed input — why parsers reject input and how to find the real culprit.
Related errors
- Unable to complete request.
- [Azure KMS]
- Malformed JSON body in GET request.
- Malformed response body - missing field `expires_in`.
- Malformed response body - unable to parse int from…
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/1572906f81eb898d.
Report an issue: GitHub.
Appendix: source
Thrown at src/client-side-encryption/providers/azure.ts:84
body: string;
status?: number;
}): Promise<AzureTokenCacheEntry> {
const { status, body: rawBody } = response;
const body: { expires_in?: number; access_token?: string } = (() => {
try {
return JSON.parse(rawBody);
} catch {
throw new MongoCryptAzureKMSRequestError('Malformed JSON body in GET request.');
}
})();
if (status !== 200) {
throw new MongoCryptAzureKMSRequestError('Unable to complete request.', body);
}
if (!body.access_token) {
throw new MongoCryptAzureKMSRequestError(
'Malformed response body - missing field `access_token`.'
);
}
if (!body.expires_in) {
throw new MongoCryptAzureKMSRequestError(
'Malformed response body - missing field `expires_in`.'
);
}
const expiresInMS = Number(body.expires_in) * 1000;
if (Number.isNaN(expiresInMS)) {
throw new MongoCryptAzureKMSRequestError(
'Malformed response body - unable to parse int from `expires_in` field.'
);
}
return {View on GitHub (pinned to dce7939f86)