mongodb/node-mongodb-native · critical · MongoInvalidArgumentError

No workflow provided to the OIDC auth provider.

Error message

No workflow provided to the OIDC auth provider.

What it means

Thrown by the MongoDBOIDC auth provider constructor (mongodb_oidc.ts:141) when no workflow argument is supplied. The driver normally selects an OIDC workflow from OIDC_WORKFLOWS keyed by ENVIRONMENT (test/azure/gcp/k8s); a missing workflow means the environment was unrecognized or the provider was instantiated directly without one. Raised as MongoInvalidArgumentError.

Solutions

  1. Use one of the supported ENVIRONMENT values exactly: test, azure, gcp, or k8s
  2. For custom OIDC, supply your own workflow/callback via code rather than a named environment
  3. Upgrade the driver to a version that supports your target environment
  4. Check the ENVIRONMENT value for typos and case sensitivity

Example fix

// before
const uri =
  'mongodb://host/?authMechanism=MONGODB-OIDC&authMechanismProperties=ENVIRONMENT:GCP';

// after
const uri =
  'mongodb://host/?authMechanism=MONGODB-OIDC&authMechanismProperties=ENVIRONMENT:gcp,TOKEN_RESOURCE:<audience>';
Defensive patterns

Strategy: validation

Validate before calling

const SUPPORTED = new Set(['test', 'azure', 'gcp', 'k8s']);
const env = clientOptions.auth?.mechanismProperties?.ENVIRONMENT;
if (env !== undefined && !SUPPORTED.has(env)) {
  throw new Error(`Unsupported OIDC ENVIRONMENT '${env}'. Supported: ${[...SUPPORTED].join(', ')}`);
}

Type guard

function isSupportedOidcEnv(env: unknown): env is 'test' | 'azure' | 'gcp' | 'k8s' {
  return typeof env === 'string' && ['test', 'azure', 'gcp', 'k8s'].includes(env);
}

Prevention

When it happens

Trigger: Specifying authMechanismProperties.ENVIRONMENT with a value outside {test, azure, gcp, k8s}, or programmatically constructing new MongoDBOIDC() without passing a workflow. Also possible if a driver version predates the environment you specified.

Common situations: Typo or wrong case in ENVIRONMENT (e.g., 'GCP', 'gcps', 'aws'). Using an older driver that does not yet register the environment you need. Forking the driver and forgetting to register a custom workflow in OIDC_WORKFLOWS.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/25287c78df073729. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/auth/mongodb_oidc.ts:141

export const OIDC_WORKFLOWS: Map<EnvironmentName, () => Workflow> = new Map();
OIDC_WORKFLOWS.set('test', () => new AutomatedCallbackWorkflow(new TokenCache(), testCallback));
OIDC_WORKFLOWS.set('azure', () => new AutomatedCallbackWorkflow(new TokenCache(), azureCallback));
OIDC_WORKFLOWS.set('gcp', () => new AutomatedCallbackWorkflow(new TokenCache(), gcpCallback));
OIDC_WORKFLOWS.set('k8s', () => new AutomatedCallbackWorkflow(new TokenCache(), k8sCallback));

/**
 * OIDC auth provider.
 */
export class MongoDBOIDC extends AuthProvider {
  workflow: Workflow;

  /**
   * Instantiate the auth provider.
   */
  constructor(workflow?: Workflow) {
    super();
    if (!workflow) {
      throw new MongoInvalidArgumentError('No workflow provided to the OIDC auth provider.');
    }
    this.workflow = workflow;
  }

  /**
   * Authenticate using OIDC
   */
  override async auth(authContext: AuthContext): Promise<void> {
    const { connection, reauthenticating, response } = authContext;
    if (response?.speculativeAuthenticate?.done && !reauthenticating) {
      return;
    }
    const credentials = getCredentials(authContext);
    if (reauthenticating) {
      await this.workflow.reauthenticate(connection, credentials);
    } else {
      await this.workflow.execute(connection, credentials, response);
    }

View on GitHub (pinned to dce7939f86)