mongodb/node-mongodb-native · error · MongoRuntimeError
Reauthentication already in progress.
Error message
Reauthentication already in progress.
What it means
Thrown by AuthProvider.reauth when context.reauthenticating is already true — i.e. a re-authentication flow was started and a second one was triggered before the first finished. The driver re-authenticates (e.g. for OIDC token refresh, AWS session expiry, or after a 391 'Reauthenticate' server error) and this guard prevents overlapping flows on the same connection. It is a MongoRuntimeError.
Solutions
- Let the driver manage re-authentication automatically (do not call internal auth APIs); ensure only one reauth is in flight per connection.
- For OIDC, implement the token callback to be fast and cached so concurrent reauth attempts resolve quickly and don't pile up.
- If using short-lived credentials, give them a TTL comfortably longer than operation latency to avoid frequent reauth.
- Upgrade the driver — reauth concurrency has been refined across releases; a double-dispatch may be a fixed bug.
Defensive patterns
Strategy: try-catch
Prevention
- Let the driver handle re-authentication; do not invoke internal auth methods concurrently.
- Make OIDC token callbacks fast and cached to avoid reauth pile-ups.
- Use credentials with TTL comfortably longer than your longest operation.
When it happens
Trigger: Two concurrent operations on a connection both receive a re-authenticate signal and attempt reauth simultaneously; an auth provider's reauth recursively calls reauth; manual invocation of reauth while the SDAM monitor is also re-authenticating.
Common situations: OIDC tokens expiring under high concurrency where multiple connections reauth at once; AWS temporary credentials expiring mid-operation; a server 391 response arriving during an in-flight reauth; driver bug causing double reauth dispatch.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- No workflow provided to the OIDC auth provider.
- username and ENVIRONMENT
- Attempted to get a refresh token when none exists.
- Attempted to get an access token when none exists.
- Attempted to get IDP information when none exists.
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/1fc6dcc0561ae231.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/auth_provider.ts:68
_authContext: AuthContext
): Promise<HandshakeDocument> {
return handshakeDoc;
}
/**
* Authenticate
*
* @param context - A shared context for authentication flow
*/
abstract auth(context: AuthContext): Promise<void>;
/**
* Reauthenticate.
* @param context - The shared auth context.
*/
async reauth(context: AuthContext): Promise<void> {
if (context.reauthenticating) {
throw new MongoRuntimeError('Reauthentication already in progress.');
}
try {
context.reauthenticating = true;
await this.auth(context);
} finally {
context.reauthenticating = false;
}
}
}
View on GitHub (pinned to dce7939f86)