mongodb/node-mongodb-native · error · MongoOIDCError
OIDC callback timed out after
Error message
OIDC callback timed out after ${AUTOMATED_TIMEOUT_MS}ms. What it means
Thrown by the OIDC automated (machine) callback workflow when the user-supplied OIDC_CALLBACK does not resolve within AUTOMATED_TIMEOUT_MS (60000 ms / 1 minute). The automated workflow aborts the callback's AbortController and rejects with a MongoOIDCError so the connection does not hang indefinitely.
Solutions
- Make the callback fast and resilient: cache the token internally and only refresh near expiry.
- Add your own shorter timeout inside the callback so it rejects before 60s with a clear error.
- Verify network reachability and credentials for the token endpoint the callback calls.
Example fix
// before
const cb = async () => {
const r = await fetch(tokenUrl); // may hang forever
return { accessToken: (await r.json()).token };
};
// after
const cb = async (params) => {
const r = await fetch(tokenUrl, { signal: params.timeoutContext });
return { accessToken: (await r.json()).token };
}; Defensive patterns
Strategy: try-catch
Validate before calling
function makeCallback(inner) {
return async (params) => {
return await inner(params); // inner must respect params.timeoutContext
};
} Try / catch
try {
await client.connect();
} catch (e) {
if (e instanceof MongoOIDCError && /timed out/.test(e.message)) {
// inspect callback for blocking I/O; add internal caching/timeout
}
throw e;
} Prevention
- Cache tokens inside the callback; refresh only near expiry.
- Honor params.timeoutContext by passing it to fetch/AbortController.
- Add your own sub-60s timeout so failures surface quickly.
When it happens
Trigger: Registering OIDC_CALLBACK (machine flow) whose returned Promise takes longer than 60 seconds, or never resolves. Fires at automated_callback_workflow.ts:81 after the Promise.race with the Timeout resolves in favor of the timeout.
Common situations: Callback makes a slow HTTP request to a token endpoint behind a slow/unreachable network. Token endpoint is down and the callback has no timeout of its own. Deadlock or missed await inside the callback.
Understand the failure class
- Timeouts: ETIMEDOUT, deadlines, and hung requests — what actually expires when a request times out.
Related errors
- OIDC callback timed out after
- User provided OIDC callbacks must return a valid object…
- Auth mechanism property ALLOWED_HOSTS must be an array of…
- AuthContext must provide credentials.
- Azure endpoint did not return a value with only…
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/665986603799ccc3.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/mongodb_oidc/automated_callback_workflow.ts:81
protected async fetchAccessToken(credentials: MongoCredentials): Promise<OIDCResponse> {
const controller = new AbortController();
const params: OIDCCallbackParams = {
timeoutContext: controller.signal,
version: OIDC_VERSION
};
if (credentials.username) {
params.username = credentials.username;
}
if (credentials.mechanismProperties.TOKEN_RESOURCE) {
params.tokenAudience = credentials.mechanismProperties.TOKEN_RESOURCE;
}
const timeout = Timeout.expires(AUTOMATED_TIMEOUT_MS);
try {
return await Promise.race([this.executeAndValidateCallback(params), timeout]);
} catch (error) {
if (TimeoutError.is(error)) {
controller.abort();
throw new MongoOIDCError(`OIDC callback timed out after ${AUTOMATED_TIMEOUT_MS}ms.`);
}
throw error;
} finally {
timeout.clear();
}
}
}
View on GitHub (pinned to dce7939f86)