mongodb/node-mongodb-native · error · MongoMissingCredentialsError
Reauthenticate failed due to no auth provider for
Error message
Reauthenticate failed due to no auth provider for ${credentials.mechanism} What it means
A MongoMissingCredentialsError thrown in ConnectionPool.reauthenticate when no auth provider is registered for the credential's mechanism. The driver looks up a provider (SCRAM, X.509, AWS, OIDC, Kerberos, PLAIN) in the auth provider registry; if the mechanism has no installed provider, reauth cannot proceed. This typically means an optional auth plugin (e.g., kerberos native module) is not installed.
Solutions
- Install the optional dependency for the mechanism: npm install kerberos (GSSAPI), ensure AWS SDK for MONGODB-AWS.
- Confirm the mechanism string matches a supported value (SCRAM-SHA-256, SCRAM-SHA-1, MONGODB-X509, MONGODB-AWS, MONGODB-OIDC, GSSAPI, PLAIN).
- Upgrade driver and optional deps together per the compatibility matrix.
- Pin the mechanism explicitly to avoid auto-negotiation landing on an unsupported one.
Example fix
// before — GSSAPI used without native kerberos
const client = new MongoClient('mongodb://host/?authMechanism=GSSAPI');
// after
// npm install kerberos
const client = new MongoClient('mongodb://host/?authMechanism=GSSAPI&authSource=$external'); Defensive patterns
Strategy: validation
Validate before calling
const SUPPORTED = ['SCRAM-SHA-1','SCRAM-SHA-256','MONGODB-X509','MONGODB-AWS','MONGODB-OIDC','GSSAPI','PLAIN'];
if (!SUPPORTED.includes(mechanism)) {
throw new Error(`Unsupported auth mechanism: ${mechanism}`);
}
if (mechanism === 'GSSAPI') {
require('kerberos'); // ensure native dep
} Try / catch
try {
await operation();
} catch (e) {
if (e instanceof MongoMissingCredentialsError && /no auth provider/.test(e.message)) {
// install the optional native dep for the mechanism, then reconnect
} else throw e;
} Prevention
- Install optional native deps for the chosen mechanism (kerberos, etc.).
- Pin the mechanism explicitly to a supported value.
- Match driver and optional-dep versions per the compatibility matrix.
When it happens
Trigger: Authenticating with a mechanism whose provider requires an optional native dependency that is not installed, then the server requests reauthentication. For example, GSSAPI (Kerberos) without the kerberos npm package, or MONGODB-AWS without the aws credentials provider available.
Common situations: Using GSSAPI/Kerberos auth without installing the kerberos package; MONGODB-OIDC without the provider configured; driver version where a mechanism provider was renamed/removed; production deploy missing optional native deps installed in dev.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- authMechanism requires an authSource of '$external
- Connection is missing credentials when asked to…
- Connection must have host and port and credentials defined.
- Credentials required for GSSAPI authentication
- No auth context found on connection.
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/694bf394722d498a.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/connection_pool.ts:542
const authContext = connection.authContext;
if (!authContext) {
throw new MongoRuntimeError('No auth context found on connection.');
}
const credentials = authContext.credentials;
if (!credentials) {
throw new MongoMissingCredentialsError(
'Connection is missing credentials when asked to reauthenticate'
);
}
const resolvedCredentials = credentials.resolveAuthMechanism(connection.hello);
const provider = this.server.topology.client.s.authProviders.getOrCreateProvider(
resolvedCredentials.mechanism,
resolvedCredentials.mechanismProperties
);
if (!provider) {
throw new MongoMissingCredentialsError(
`Reauthenticate failed due to no auth provider for ${credentials.mechanism}`
);
}
await provider.reauth(authContext);
return;
}
/** Clear the min pool size timer */
private clearMinPoolSizeTimer(): void {
const minPoolSizeTimer = this.minPoolSizeTimer;
if (minPoolSizeTimer) {
clearTimeout(minPoolSizeTimer);
}
}
private destroyConnection(View on GitHub (pinned to dce7939f86)