mongodb/node-mongodb-native · critical · MongoInvalidArgumentError
No workflow provided to the OIDC auth provider.
Error message
No workflow provided to the OIDC auth provider.
What it means
Thrown by the MongoDBOIDC auth provider constructor (mongodb_oidc.ts:141) when no workflow argument is supplied. The driver normally selects an OIDC workflow from OIDC_WORKFLOWS keyed by ENVIRONMENT (test/azure/gcp/k8s); a missing workflow means the environment was unrecognized or the provider was instantiated directly without one. Raised as MongoInvalidArgumentError.
Solutions
- Use one of the supported ENVIRONMENT values exactly: test, azure, gcp, or k8s
- For custom OIDC, supply your own workflow/callback via code rather than a named environment
- Upgrade the driver to a version that supports your target environment
- Check the ENVIRONMENT value for typos and case sensitivity
Example fix
// before const uri = 'mongodb://host/?authMechanism=MONGODB-OIDC&authMechanismProperties=ENVIRONMENT:GCP'; // after const uri = 'mongodb://host/?authMechanism=MONGODB-OIDC&authMechanismProperties=ENVIRONMENT:gcp,TOKEN_RESOURCE:<audience>';
Defensive patterns
Strategy: validation
Validate before calling
const SUPPORTED = new Set(['test', 'azure', 'gcp', 'k8s']);
const env = clientOptions.auth?.mechanismProperties?.ENVIRONMENT;
if (env !== undefined && !SUPPORTED.has(env)) {
throw new Error(`Unsupported OIDC ENVIRONMENT '${env}'. Supported: ${[...SUPPORTED].join(', ')}`);
} Type guard
function isSupportedOidcEnv(env: unknown): env is 'test' | 'azure' | 'gcp' | 'k8s' {
return typeof env === 'string' && ['test', 'azure', 'gcp', 'k8s'].includes(env);
} Prevention
- Validate the ENVIRONMENT value against the supported set at config-load time
- Treat ENVIRONMENT case-sensitively (lowercase only)
- Upgrade the driver when adopting a new OIDC environment
When it happens
Trigger: Specifying authMechanismProperties.ENVIRONMENT with a value outside {test, azure, gcp, k8s}, or programmatically constructing new MongoDBOIDC() without passing a workflow. Also possible if a driver version predates the environment you specified.
Common situations: Typo or wrong case in ENVIRONMENT (e.g., 'GCP', 'gcps', 'aws'). Using an older driver that does not yet register the environment you need. Forking the driver and forgetting to register a custom workflow in OIDC_WORKFLOWS.
Related errors
- Auth mechanism property ALLOWED_HOSTS must be an array of…
- AuthContext must provide credentials.
- Currently only a ENVIRONMENT in
- Either a ENVIRONMENT, OIDC_CALLBACK, or OIDC_HUMAN_CALLBACK…
- No password is allowed in ENVIRONMENT
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/25287c78df073729.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/mongodb_oidc.ts:141
export const OIDC_WORKFLOWS: Map<EnvironmentName, () => Workflow> = new Map();
OIDC_WORKFLOWS.set('test', () => new AutomatedCallbackWorkflow(new TokenCache(), testCallback));
OIDC_WORKFLOWS.set('azure', () => new AutomatedCallbackWorkflow(new TokenCache(), azureCallback));
OIDC_WORKFLOWS.set('gcp', () => new AutomatedCallbackWorkflow(new TokenCache(), gcpCallback));
OIDC_WORKFLOWS.set('k8s', () => new AutomatedCallbackWorkflow(new TokenCache(), k8sCallback));
/**
* OIDC auth provider.
*/
export class MongoDBOIDC extends AuthProvider {
workflow: Workflow;
/**
* Instantiate the auth provider.
*/
constructor(workflow?: Workflow) {
super();
if (!workflow) {
throw new MongoInvalidArgumentError('No workflow provided to the OIDC auth provider.');
}
this.workflow = workflow;
}
/**
* Authenticate using OIDC
*/
override async auth(authContext: AuthContext): Promise<void> {
const { connection, reauthenticating, response } = authContext;
if (response?.speculativeAuthenticate?.done && !reauthenticating) {
return;
}
const credentials = getCredentials(authContext);
if (reauthenticating) {
await this.workflow.reauthenticate(connection, credentials);
} else {
await this.workflow.execute(connection, credentials, response);
}View on GitHub (pinned to dce7939f86)