mongodb/node-mongodb-native · critical · MongoInvalidArgumentError

No AuthProvider for defined.

Error message

No AuthProvider for ${AuthMechanism.MONGODB_SCRAM_SHA256} defined.

What it means

Thrown as a MongoInvalidArgumentError in prepareHandshakeDocument() when credentials use MONGODB_DEFAULT with a username, the driver tries to use SCRAM-SHA-256 for speculative auth, and getOrCreateProvider(MONGODB_SCRAM_SHA256) returns null. The adjacent comment ('This auth mechanism is always present') makes clear this is a defensive invariant — SCRAM-SHA-256 is a built-in provider and should never be absent.

Solutions

  1. Do not remove or override the default AuthProvider registry
  2. If you construct a custom MongoClient options object with authProviders, ensure SCRAM-SHA-256 remains registered
  3. Report as a driver bug if hit with an unmodified driver
Defensive patterns

Strategy: try-catch

Try / catch

try { await client.connect(); } catch (e) {
  if (e instanceof MongoInvalidArgumentError && /No AuthProvider for.*SCRAM-SHA-256/.test(e.message)) {
    // do not strip the default auth provider registry; report as a bug
  }
  throw e;
}

Prevention

When it happens

Trigger: Effectively unreachable in normal operation: SCRAM-SHA-256 is a core built-in provider. Would only fire if a custom AuthProvider registry was constructed that explicitly omitted ScramSHA256, or if internal provider registration was broken (e.g. a bad monkey-patch or a driver bug).

Common situations: Custom code that reconfigures the authProviders registry and removes SCRAM-SHA-256; a corrupted/modified driver build; extremely unlikely in stock usage.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/56f2ddd91a1d9e3f. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/connect.ts:266

    compression: compressors
  };

  if (options.loadBalanced === true) {
    handshakeDoc.loadBalanced = true;
  }

  const credentials = authContext.credentials;
  if (credentials) {
    if (credentials.mechanism === AuthMechanism.MONGODB_DEFAULT && credentials.username) {
      handshakeDoc.saslSupportedMechs = `${credentials.source}.${credentials.username}`;

      const provider = authContext.options.authProviders.getOrCreateProvider(
        AuthMechanism.MONGODB_SCRAM_SHA256,
        credentials.mechanismProperties
      );
      if (!provider) {
        // This auth mechanism is always present.
        throw new MongoInvalidArgumentError(
          `No AuthProvider for ${AuthMechanism.MONGODB_SCRAM_SHA256} defined.`
        );
      }
      return await provider.prepare(handshakeDoc, authContext);
    }
    const provider = authContext.options.authProviders.getOrCreateProvider(
      credentials.mechanism,
      credentials.mechanismProperties
    );
    if (!provider) {
      throw new MongoInvalidArgumentError(`No AuthProvider for ${credentials.mechanism} defined.`);
    }
    return await provider.prepare(handshakeDoc, authContext);
  }
  return handshakeDoc;
}

/**

View on GitHub (pinned to dce7939f86)