mongodb/node-mongodb-native · error · MongoCryptAzureKMSRequestError
Malformed response body - unable to parse int from…
Error message
Malformed response body - unable to parse int from `expires_in` field.
What it means
Raised when the Azure IMDS response has an expires_in field but Number(value) * 1000 yields NaN, i.e. expires_in is non-numeric (e.g. a string like 'never' or null). The driver multiplies expires_in (seconds) by 1000 to compute the cache expiry; a non-numeric value makes caching impossible. MongoCryptAzureKMSRequestError.
Solutions
- Ensure the IMDS (or test mock) returns expires_in as a number of seconds (e.g. 86400).
- Do not override the Azure KMS request URL/options in production; the real IMDS endpoint always returns a numeric expires_in.
- If genuinely from Azure, retry and escalate to Azure support if it persists.
Defensive patterns
Strategy: validation
Validate before calling
function assertExpiresInNumeric(body) {
if (Number.isNaN(Number(body.expires_in))) {
throw new Error('expires_in must be a number of seconds');
}
} Type guard
function isNumericExpiresIn(b: unknown): boolean {
return typeof b === 'object' && b !== null && !Number.isNaN(Number((b as any).expires_in));
} Prevention
- Mock IMDS must return expires_in as a number (seconds), not a duration string.
- Avoid overriding the Azure KMS request URL in production.
When it happens
Trigger: expires_in present but as a non-numeric string or an object; a malformed mock IMDS response such as { access_token: 'x', expires_in: 'abc' }.
Common situations: Test stub returning the wrong type for expires_in; a custom KMS proxy returning an ISO-8601 duration string instead of seconds; Azure returning an unexpected envelope during a platform incident.
Understand the failure class
- Parsing and encoding errors: unexpected token, malformed input — why parsers reject input and how to find the real culprit.
Related errors
- Malformed response body - missing field `expires_in`.
- [Azure KMS]
- Malformed JSON body in GET request.
- Malformed response body - missing field `access_token`.
- Unable to complete request.
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/700a80e06d42a3ee.
Report an issue: GitHub.
Appendix: source
Thrown at src/client-side-encryption/providers/azure.ts:97
if (status !== 200) {
throw new MongoCryptAzureKMSRequestError('Unable to complete request.', body);
}
if (!body.access_token) {
throw new MongoCryptAzureKMSRequestError(
'Malformed response body - missing field `access_token`.'
);
}
if (!body.expires_in) {
throw new MongoCryptAzureKMSRequestError(
'Malformed response body - missing field `expires_in`.'
);
}
const expiresInMS = Number(body.expires_in) * 1000;
if (Number.isNaN(expiresInMS)) {
throw new MongoCryptAzureKMSRequestError(
'Malformed response body - unable to parse int from `expires_in` field.'
);
}
return {
accessToken: body.access_token,
expiresOnTimestamp: Date.now() + expiresInMS
};
}
/**
* @internal
*
* exposed for CSFLE
* [prose test 18](https://github.com/mongodb/specifications/tree/master/source/client-side-encryption/tests#azure-imds-credentials)
*/
export interface AzureKMSRequestOptions {
headers?: Document;View on GitHub (pinned to dce7939f86)