mongodb/node-mongodb-native · error · MongoCryptAzureKMSRequestError

Malformed response body - unable to parse int from…

Error message

Malformed response body - unable to parse int from `expires_in` field.

What it means

Raised when the Azure IMDS response has an expires_in field but Number(value) * 1000 yields NaN, i.e. expires_in is non-numeric (e.g. a string like 'never' or null). The driver multiplies expires_in (seconds) by 1000 to compute the cache expiry; a non-numeric value makes caching impossible. MongoCryptAzureKMSRequestError.

Solutions

  1. Ensure the IMDS (or test mock) returns expires_in as a number of seconds (e.g. 86400).
  2. Do not override the Azure KMS request URL/options in production; the real IMDS endpoint always returns a numeric expires_in.
  3. If genuinely from Azure, retry and escalate to Azure support if it persists.
Defensive patterns

Strategy: validation

Validate before calling

function assertExpiresInNumeric(body) {
  if (Number.isNaN(Number(body.expires_in))) {
    throw new Error('expires_in must be a number of seconds');
  }
}

Type guard

function isNumericExpiresIn(b: unknown): boolean {
  return typeof b === 'object' && b !== null && !Number.isNaN(Number((b as any).expires_in));
}

Prevention

When it happens

Trigger: expires_in present but as a non-numeric string or an object; a malformed mock IMDS response such as { access_token: 'x', expires_in: 'abc' }.

Common situations: Test stub returning the wrong type for expires_in; a custom KMS proxy returning an ISO-8601 duration string instead of seconds; Azure returning an unexpected envelope during a platform incident.

Understand the failure class

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/700a80e06d42a3ee. Report an issue: GitHub.

Appendix: source

Thrown at src/client-side-encryption/providers/azure.ts:97

  if (status !== 200) {
    throw new MongoCryptAzureKMSRequestError('Unable to complete request.', body);
  }

  if (!body.access_token) {
    throw new MongoCryptAzureKMSRequestError(
      'Malformed response body - missing field `access_token`.'
    );
  }

  if (!body.expires_in) {
    throw new MongoCryptAzureKMSRequestError(
      'Malformed response body - missing field `expires_in`.'
    );
  }

  const expiresInMS = Number(body.expires_in) * 1000;
  if (Number.isNaN(expiresInMS)) {
    throw new MongoCryptAzureKMSRequestError(
      'Malformed response body - unable to parse int from `expires_in` field.'
    );
  }

  return {
    accessToken: body.access_token,
    expiresOnTimestamp: Date.now() + expiresInMS
  };
}

/**
 * @internal
 *
 * exposed for CSFLE
 * [prose test 18](https://github.com/mongodb/specifications/tree/master/source/client-side-encryption/tests#azure-imds-credentials)
 */
export interface AzureKMSRequestOptions {
  headers?: Document;

View on GitHub (pinned to dce7939f86)