mongodb/node-mongodb-native · error · MongoInvalidArgumentError
No password is allowed in ENVIRONMENT
Error message
No password is allowed in ENVIRONMENT '${this.mechanismProperties.ENVIRONMENT}' for '${this.mechanism}'. What it means
Thrown by MongoCredentials.validate() when the MONGODB-OIDC mechanism is configured with both a username and a password. OIDC authentication issues tokens from an identity provider, so a static password is never valid alongside a principal username. The driver rejects this combination up front because the OIDC workflow has no way to consume a password.
Solutions
- Remove the password from your connection string or credentials object; OIDC tokens are obtained via ENVIRONMENT or a callback, not a password.
- If you supplied the password inadvertently via code, delete the password property from the options passed to new MongoClient.
- Confirm that username-only is intentional (only allowed for the 'azure' ENVIRONMENT); otherwise remove the username too.
Example fix
// before
new MongoClient('mongodb://host/?authMechanism=MONGODB-OIDC&username=app&password=secret');
// after
new MongoClient('mongodb://host/?authMechanism=MONGODB-OIDC&username=app'); Defensive patterns
Strategy: validation
Validate before calling
function assertNoOidcPassword(opts) {
if (opts.auth?.mechanism === 'MONGODB-OIDC' && opts.auth?.username && opts.auth?.password != null) {
throw new Error('MONGODB-OIDC does not accept a password when a username is set.');
}
} Prevention
- Centralize connection-string building in one helper that forbids password for OIDC.
- Run a unit test asserting OIDC credentials never include a password.
- Treat username-only OIDC as valid only for the azure ENVIRONMENT.
When it happens
Trigger: Constructing a MongoClient with authMechanism='MONGODB-OIDC' (or passing credentials that resolve to OIDC) while simultaneously supplying both username and password in the credentials/connection string. The error fires during the first authentication attempt when validate() runs.
Common situations: Copy-pasting a SCRAM username/password connection string and only swapping the authMechanism value to MONGODB-OIDC. Configuring an Azure/service-account OIDC principal (which legitimately takes a username) and accidentally leaving an old password field populated.
Related errors
- AuthContext must provide credentials.
- Auth mechanism property ALLOWED_HOSTS must be an array of…
- AuthContext must provide credentials.
- AuthContext must provide credentials.
- AuthContext must provide credentials.
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/e42842f61cd6c690.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/mongo_credentials.ts:203
this.mechanism === AuthMechanism.MONGODB_SCRAM_SHA256) &&
!this.username
) {
throw new MongoMissingCredentialsError(`Username required for mechanism '${this.mechanism}'`);
}
if (this.mechanism === AuthMechanism.MONGODB_OIDC) {
if (
this.username &&
this.mechanismProperties.ENVIRONMENT &&
this.mechanismProperties.ENVIRONMENT !== 'azure'
) {
throw new MongoInvalidArgumentError(
`username and ENVIRONMENT '${this.mechanismProperties.ENVIRONMENT}' may not be used together for mechanism '${this.mechanism}'.`
);
}
if (this.username && this.password) {
throw new MongoInvalidArgumentError(
`No password is allowed in ENVIRONMENT '${this.mechanismProperties.ENVIRONMENT}' for '${this.mechanism}'.`
);
}
if (
(this.mechanismProperties.ENVIRONMENT === 'azure' ||
this.mechanismProperties.ENVIRONMENT === 'gcp') &&
!this.mechanismProperties.TOKEN_RESOURCE
) {
throw new MongoInvalidArgumentError(TOKEN_RESOURCE_MISSING_ERROR);
}
if (
this.mechanismProperties.ENVIRONMENT &&
!ALLOWED_ENVIRONMENT_NAMES.includes(this.mechanismProperties.ENVIRONMENT)
) {
throw new MongoInvalidArgumentError(
`Currently only a ENVIRONMENT in ${ALLOWED_ENVIRONMENT_NAMES.join(View on GitHub (pinned to dce7939f86)