mongodb/node-mongodb-native · error · MongoRuntimeError
Server nonce does not begin with client nonce
Error message
Server nonce does not begin with client nonce
What it means
Thrown during MONGODB-AWS SASL exchange when the first 32 bytes of the server's nonce do not equal the 32-byte client nonce the driver sent. Per the cross-driver auth spec, the server nonce must begin with the client nonce; a mismatch signals a protocol violation or potential attack, so the driver aborts.
Solutions
- Connect directly to the MongoDB host, bypassing any proxy/VPN that could alter payloads.
- Confirm the target is an authentic MongoDB deployment supporting MONGODB-AWS.
- Gather driver version + server hello and file a bug if reproducible against real MongoDB.
Defensive patterns
Strategy: try-catch
Try / catch
try {
await client.connect();
} catch (e) {
if (e instanceof MongoRuntimeError && /Server nonce does not begin/.test(e.message)) {
// protocol/security violation; do not retry against same endpoint blindly
}
throw e;
} Prevention
- Ensure a direct, unmodified path to the MongoDB server.
- Treat nonce mismatches as security-sensitive; investigate the endpoint.
- Do not retry-loop without diagnostics; the cause is server/proxy-side.
When it happens
Trigger: ByteUtils.equals(serverNonce.subarray(0,32), clientNonce) returns false. Fires at mongodb_aws.ts:90. A server-side response-construction bug or payload corruption is the usual cause.
Common situations: Intermediate proxy rewriting the conversation. A misbehaving MongoDB-compatible service. Extremely rare in normal operation against real MongoDB.
Related errors
- Server returned an invalid host
- Invalid server nonce length
- AuthContext must provide credentials.
- AWS_SESSION_TOKEN cannot be provided when using…
- Azure endpoint did not return a value with only…
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/2692174a3104ac8e.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/mongodb_aws.ts:90
const saslStartResponse = await connection.command(ns(`${db}.$cmd`), saslStart, undefined);
const serverResponse = BSON.deserialize(saslStartResponse.payload.buffer, bsonOptions) as {
s: Binary;
h: string;
};
const host = serverResponse.h;
const serverNonce = serverResponse.s.buffer;
if (serverNonce.length !== 64) {
// TODO(NODE-3483)
throw new MongoRuntimeError(`Invalid server nonce length ${serverNonce.length}, expected 64`);
}
if (!ByteUtils.equals(serverNonce.subarray(0, nonce.byteLength), nonce)) {
// throw because the serverNonce's leading 32 bytes must equal the client nonce's 32 bytes
// https://github.com/mongodb/specifications/blob/master/source/auth/auth.md#conversation-5
// TODO(NODE-3483)
throw new MongoRuntimeError('Server nonce does not begin with client nonce');
}
if (host.length < 1 || host.length > 255 || host.indexOf('..') !== -1) {
// TODO(NODE-3483)
throw new MongoRuntimeError(`Server returned an invalid host: "${host}"`);
}
const body = 'Action=GetCallerIdentity&Version=2011-06-15';
const headers = await aws4Sign(
{
method: 'POST',
host,
region: deriveRegion(serverResponse.h),
service: 'sts',
headers: {
'Content-Type': 'application/x-www-form-urlencoded',
'Content-Length': body.length,
'X-MongoDB-Server-Nonce': ByteUtils.toBase64(serverNonce),View on GitHub (pinned to dce7939f86)