mongodb/node-mongodb-native · error · MongoCryptAzureKMSRequestError

Malformed response body - missing field `access_token`.

Error message

Malformed response body - missing field `access_token`.

What it means

Raised when the Azure IMDS response parsed as JSON but contains no access_token field. The Azure access token is the credential libmongocrypt uses to unwrap the Customer Master Key in Azure Key Vault; its absence means the response is malformed for this provider. MongoCryptAzureKMSRequestError.

Solutions

  1. Inspect the error's attached body payload for the Azure error/error_description to find the real cause (often 'identity not found' or 'resource disabled').
  2. Verify the managed identity is enabled and assigned to the resource, and that the Key Vault is in the same tenant.
  3. Confirm the request reaches the standard resource https://vault.azure.net (the driver sets this; do not override the resource in tests).
  4. Retry after reassigning the managed identity; propagation can lag.
Defensive patterns

Strategy: try-catch

Try / catch

try {
  await clientEncryption.createEncryptedCollection(...);
} catch (e) {
  if (e instanceof MongoCryptAzureKMSRequestError && /access_token/.test(e.message)) {
    // inspect the attached body for Azure error_description, fix IAM, retry
  }
}

Prevention

When it happens

Trigger: IMDS returns JSON but with a different shape (e.g. an error envelope like { 'error': {...} } with no access_token); requesting a resource value Azure does not recognize; the managed identity has no permission to the target resource.

Common situations: Wrong 'resource' audience (should be https://vault.azure.net); Azure returning { error, error_description } for a denied token request; the response being a partial JSON object due to truncation; using a custom test URL that omits the token field.

Understand the failure class

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/1572906f81eb898d. Report an issue: GitHub.

Appendix: source

Thrown at src/client-side-encryption/providers/azure.ts:84

  body: string;
  status?: number;
}): Promise<AzureTokenCacheEntry> {
  const { status, body: rawBody } = response;

  const body: { expires_in?: number; access_token?: string } = (() => {
    try {
      return JSON.parse(rawBody);
    } catch {
      throw new MongoCryptAzureKMSRequestError('Malformed JSON body in GET request.');
    }
  })();

  if (status !== 200) {
    throw new MongoCryptAzureKMSRequestError('Unable to complete request.', body);
  }

  if (!body.access_token) {
    throw new MongoCryptAzureKMSRequestError(
      'Malformed response body - missing field `access_token`.'
    );
  }

  if (!body.expires_in) {
    throw new MongoCryptAzureKMSRequestError(
      'Malformed response body - missing field `expires_in`.'
    );
  }

  const expiresInMS = Number(body.expires_in) * 1000;
  if (Number.isNaN(expiresInMS)) {
    throw new MongoCryptAzureKMSRequestError(
      'Malformed response body - unable to parse int from `expires_in` field.'
    );
  }

  return {

View on GitHub (pinned to dce7939f86)