mongodb/node-mongodb-native · error · MongoRuntimeError
No AutoEncrypter available for encryption
Error message
No AutoEncrypter available for encryption
What it means
A MongoRuntimeError thrown in CryptoConnection.command when autoEncrypter is not set. CryptoConnection is the connection subclass used for Client-Side Field Level Encryption (CSFLE) / Queryable Encryption; its command override expects an AutoEncrypter instance to encrypt outbound commands. Reaching this throw means the connection is a CryptoConnection but was constructed without the autoEncrypter option — an internal misconfiguration.
Solutions
- Install mongodb-client-encryption at the correct version: npm install mongodb-client-encryption.
- Ensure libmongocrypt is installed and on the library path.
- Match the mongodb-client-encryption version to the driver version per the compatibility matrix.
- Verify autoEncryption settings (keyVaultNS, kmsProviders) are complete; incomplete config can prevent AutoEncrypter init.
Example fix
// before — autoEncryption enabled but native dep missing
const client = new MongoClient(uri, {
autoEncryption: { keyVaultNamespace: 'encryption.__keyVault', kmsProviders: { local: { key } } }
});
// after — install dep then construct
// npm install mongodb-client-encryption
const client = new MongoClient(uri, {
autoEncryption: { keyVaultNamespace: 'encryption.__keyVault', kmsProviders: { local: { key } } }
}); Defensive patterns
Strategy: validation
Validate before calling
// Verify the native CSFLE module loads before constructing the client
try {
require('mongodb-client-encryption');
} catch {
throw new Error('mongodb-client-encryption is required for autoEncryption');
} Prevention
- Install mongodb-client-encryption at the version matching the driver.
- Ensure libmongocrypt is on the system library path.
- Smoke-test the native module load at deploy time.
When it happens
Trigger: The driver instantiated a CryptoConnection (because autoEncryption was configured on the client) but the autoEncrypter was not attached — typically due to the mongodb-client-encryption native module failing to load or an internal wiring bug. The user-facing trigger is performing any CRUD/command after enabling autoEncryption when the native crypto dependency is missing or broken.
Common situations: Installing mongodb without the required mongodb-client-encryption native dependency; a broken/missing libmongocrypt on the system; version mismatch between driver and mongodb-client-encryption; enabling autoEncryption in config but not installing the shared library.
Related errors
- Cursor document did not contain a batch
- Expected result of decryption to be deserialized BSON object
- Auto-encryption requested, but the module is not installed…
- [Azure KMS]
- Can only provide a custom AWS credential provider when the…
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/926242488f689341.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/connection.ts:882
options: CommandOptions | undefined,
responseType: T
): Promise<InstanceType<T>>;
public override async command(
ns: MongoDBNamespace,
command: Document,
options?: CommandOptions
): Promise<Document>;
override async command<T extends MongoDBResponseConstructor>(
ns: MongoDBNamespace,
cmd: Document,
options?: CommandOptions,
responseType?: T
): Promise<Document> {
const { autoEncrypter } = this;
if (!autoEncrypter) {
throw new MongoRuntimeError('No AutoEncrypter available for encryption');
}
const serverWireVersion = maxWireVersion(this);
if (serverWireVersion === 0) {
// This means the initial handshake hasn't happened yet
return await super.command<T>(ns, cmd, options, responseType);
}
// Save sort or indexKeys based on the command being run
// the encrypt API serializes our JS objects to BSON to pass to the native code layer
// and then deserializes the encrypted result, the protocol level components
// of the command (ex. sort) are then converted to JS objects potentially losing
// import key order information. These fields are never encrypted so we can save the values
// from before the encryption and replace them after encryption has been performed
const sort: Map<string, number> | null = cmd.find || cmd.findAndModify ? cmd.sort : null;
const indexKeys: Map<string, number>[] | null = cmd.createIndexes
? cmd.indexes.map((index: { key: Map<string, number> }) => index.key)
: null;View on GitHub (pinned to dce7939f86)