mongodb/node-mongodb-native · error · MongoRuntimeError

No AutoEncrypter available for encryption

Error message

No AutoEncrypter available for encryption

What it means

A MongoRuntimeError thrown in CryptoConnection.command when autoEncrypter is not set. CryptoConnection is the connection subclass used for Client-Side Field Level Encryption (CSFLE) / Queryable Encryption; its command override expects an AutoEncrypter instance to encrypt outbound commands. Reaching this throw means the connection is a CryptoConnection but was constructed without the autoEncrypter option — an internal misconfiguration.

Solutions

  1. Install mongodb-client-encryption at the correct version: npm install mongodb-client-encryption.
  2. Ensure libmongocrypt is installed and on the library path.
  3. Match the mongodb-client-encryption version to the driver version per the compatibility matrix.
  4. Verify autoEncryption settings (keyVaultNS, kmsProviders) are complete; incomplete config can prevent AutoEncrypter init.

Example fix

// before — autoEncryption enabled but native dep missing
const client = new MongoClient(uri, {
  autoEncryption: { keyVaultNamespace: 'encryption.__keyVault', kmsProviders: { local: { key } } }
});

// after — install dep then construct
// npm install mongodb-client-encryption
const client = new MongoClient(uri, {
  autoEncryption: { keyVaultNamespace: 'encryption.__keyVault', kmsProviders: { local: { key } } }
});
Defensive patterns

Strategy: validation

Validate before calling

// Verify the native CSFLE module loads before constructing the client
try {
  require('mongodb-client-encryption');
} catch {
  throw new Error('mongodb-client-encryption is required for autoEncryption');
}

Prevention

When it happens

Trigger: The driver instantiated a CryptoConnection (because autoEncryption was configured on the client) but the autoEncrypter was not attached — typically due to the mongodb-client-encryption native module failing to load or an internal wiring bug. The user-facing trigger is performing any CRUD/command after enabling autoEncryption when the native crypto dependency is missing or broken.

Common situations: Installing mongodb without the required mongodb-client-encryption native dependency; a broken/missing libmongocrypt on the system; version mismatch between driver and mongodb-client-encryption; enabling autoEncryption in config but not installing the shared library.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/926242488f689341. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/connection.ts:882

    options: CommandOptions | undefined,
    responseType: T
  ): Promise<InstanceType<T>>;

  public override async command(
    ns: MongoDBNamespace,
    command: Document,
    options?: CommandOptions
  ): Promise<Document>;

  override async command<T extends MongoDBResponseConstructor>(
    ns: MongoDBNamespace,
    cmd: Document,
    options?: CommandOptions,
    responseType?: T
  ): Promise<Document> {
    const { autoEncrypter } = this;
    if (!autoEncrypter) {
      throw new MongoRuntimeError('No AutoEncrypter available for encryption');
    }

    const serverWireVersion = maxWireVersion(this);
    if (serverWireVersion === 0) {
      // This means the initial handshake hasn't happened yet
      return await super.command<T>(ns, cmd, options, responseType);
    }

    // Save sort or indexKeys based on the command being run
    // the encrypt API serializes our JS objects to BSON to pass to the native code layer
    // and then deserializes the encrypted result, the protocol level components
    // of the command (ex. sort) are then converted to JS objects potentially losing
    // import key order information. These fields are never encrypted so we can save the values
    // from before the encryption and replace them after encryption has been performed
    const sort: Map<string, number> | null = cmd.find || cmd.findAndModify ? cmd.sort : null;
    const indexKeys: Map<string, number>[] | null = cmd.createIndexes
      ? cmd.indexes.map((index: { key: Map<string, number> }) => index.key)
      : null;

View on GitHub (pinned to dce7939f86)