mongodb/node-mongodb-native · error · MongoMissingCredentialsError

Reauthenticate failed due to no auth provider for

Error message

Reauthenticate failed due to no auth provider for ${credentials.mechanism}

What it means

A MongoMissingCredentialsError thrown in ConnectionPool.reauthenticate when no auth provider is registered for the credential's mechanism. The driver looks up a provider (SCRAM, X.509, AWS, OIDC, Kerberos, PLAIN) in the auth provider registry; if the mechanism has no installed provider, reauth cannot proceed. This typically means an optional auth plugin (e.g., kerberos native module) is not installed.

Solutions

  1. Install the optional dependency for the mechanism: npm install kerberos (GSSAPI), ensure AWS SDK for MONGODB-AWS.
  2. Confirm the mechanism string matches a supported value (SCRAM-SHA-256, SCRAM-SHA-1, MONGODB-X509, MONGODB-AWS, MONGODB-OIDC, GSSAPI, PLAIN).
  3. Upgrade driver and optional deps together per the compatibility matrix.
  4. Pin the mechanism explicitly to avoid auto-negotiation landing on an unsupported one.

Example fix

// before — GSSAPI used without native kerberos
const client = new MongoClient('mongodb://host/?authMechanism=GSSAPI');

// after
// npm install kerberos
const client = new MongoClient('mongodb://host/?authMechanism=GSSAPI&authSource=$external');
Defensive patterns

Strategy: validation

Validate before calling

const SUPPORTED = ['SCRAM-SHA-1','SCRAM-SHA-256','MONGODB-X509','MONGODB-AWS','MONGODB-OIDC','GSSAPI','PLAIN'];
if (!SUPPORTED.includes(mechanism)) {
  throw new Error(`Unsupported auth mechanism: ${mechanism}`);
}
if (mechanism === 'GSSAPI') {
  require('kerberos'); // ensure native dep
}

Try / catch

try {
  await operation();
} catch (e) {
  if (e instanceof MongoMissingCredentialsError && /no auth provider/.test(e.message)) {
    // install the optional native dep for the mechanism, then reconnect
  } else throw e;
}

Prevention

When it happens

Trigger: Authenticating with a mechanism whose provider requires an optional native dependency that is not installed, then the server requests reauthentication. For example, GSSAPI (Kerberos) without the kerberos npm package, or MONGODB-AWS without the aws credentials provider available.

Common situations: Using GSSAPI/Kerberos auth without installing the kerberos package; MONGODB-OIDC without the provider configured; driver version where a mechanism provider was renamed/removed; production deploy missing optional native deps installed in dev.

Understand the failure class

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/694bf394722d498a. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/connection_pool.ts:542

    const authContext = connection.authContext;
    if (!authContext) {
      throw new MongoRuntimeError('No auth context found on connection.');
    }
    const credentials = authContext.credentials;
    if (!credentials) {
      throw new MongoMissingCredentialsError(
        'Connection is missing credentials when asked to reauthenticate'
      );
    }

    const resolvedCredentials = credentials.resolveAuthMechanism(connection.hello);
    const provider = this.server.topology.client.s.authProviders.getOrCreateProvider(
      resolvedCredentials.mechanism,
      resolvedCredentials.mechanismProperties
    );

    if (!provider) {
      throw new MongoMissingCredentialsError(
        `Reauthenticate failed due to no auth provider for ${credentials.mechanism}`
      );
    }

    await provider.reauth(authContext);

    return;
  }

  /** Clear the min pool size timer */
  private clearMinPoolSizeTimer(): void {
    const minPoolSizeTimer = this.minPoolSizeTimer;
    if (minPoolSizeTimer) {
      clearTimeout(minPoolSizeTimer);
    }
  }

  private destroyConnection(

View on GitHub (pinned to dce7939f86)