mongodb/node-mongodb-native · error · MongoAzureError
Status code returned from the Azure endpoint. Response body
Error message
Status code ${response.status} returned from the Azure endpoint. Response body: ${response.body} What it means
Thrown by the Azure machine workflow when the HTTP GET to the Azure IMDS endpoint returns a non-200 status code. The error includes the status and response body to help diagnose why Azure refused the token request (auth, identity, audience, or network issues).
Solutions
- Read the response body in the error message: 403/404 usually indicate missing/wrong managed identity or audience.
- Ensure a system-assigned identity is enabled on the compute resource, or pass the user-assigned clientId as the username.
- Confirm network access to the IMDS endpoint (169.254.169.254) and retry; if throttled (429), back off.
Defensive patterns
Strategy: try-catch
Try / catch
try {
await client.connect();
} catch (e) {
if (e instanceof MongoAzureError && /Status code/.test(e.message)) {
const code = Number(e.message.match(/(\d{3})/)?.[1]);
if (code === 403 || code === 404) {
// fix managed identity / clientId / audience
} else if (code === 429 || code >= 500) {
// transient: retry with backoff
}
}
throw e;
} Prevention
- Ensure a system-assigned identity is enabled or pass the user-assigned clientId as username.
- Confirm network access to 169.254.169.254 from the runtime.
- Implement retry with backoff for 429/5xx Azure responses.
When it happens
Trigger: getAzureTokenData() issues the metadata request and response.status !== 200. Fires at azure_machine_workflow.ts:47. Common non-200 causes: 403 (identity/permission), 404 (wrong resource path), 429 (throttle), 5xx (Azure outage).
Common situations: No system-assigned managed identity on the VM. User-assigned identity not specified (username/clientId param). TOKEN_RESOURCE/audience rejected by Azure. Azure IMDS temporarily unavailable or throttling. Network/firewall blocking 169.254.169.254.
Related errors
- Azure endpoint did not return a value with only…
- Status code returned from the GCP endpoint. Response body
- TOKEN_RESOURCE must be set in the auth mechanism properties…
- TOKEN_RESOURCE must be set in the auth mechanism properties…
- Auth mechanism property ALLOWED_HOSTS must be an array of…
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/4c6afc8c1b124488.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts:47
}
const response = await getAzureTokenData(tokenAudience, username);
if (!isEndpointResultValid(response)) {
throw new MongoAzureError(ENDPOINT_RESULT_ERROR);
}
return response;
};
/**
* Hit the Azure endpoint to get the token data.
*/
async function getAzureTokenData(tokenAudience: string, username?: string): Promise<OIDCResponse> {
const url = new URL(AZURE_BASE_URL);
addAzureParams(url, tokenAudience, username);
const response = await get(url, {
headers: AZURE_HEADERS
});
if (response.status !== 200) {
throw new MongoAzureError(
`Status code ${response.status} returned from the Azure endpoint. Response body: ${response.body}`
);
}
const result = JSON.parse(response.body);
return {
accessToken: result.access_token,
expiresInSeconds: Number(result.expires_in)
};
}
/**
* Determines if a result returned from the endpoint is valid.
* This means the result is not nullish, contains the access_token required field
* and the expires_in required field.
*/
function isEndpointResultValid(
token: unknown
): token is { access_token: unknown; expires_in: unknown } {View on GitHub (pinned to dce7939f86)