mongodb/node-mongodb-native · error · MongoAPIError
The ' ' option cannot be used with the ' ' option
Error message
The '${a}' option cannot be used with the '${b}' option What it means
TLS option conflict guard. tlsInsecure is a convenience flag that disables all certificate and hostname validation; using it alongside either tlsAllowInvalidCertificates or tlsAllowInvalidHostnames is redundant and confusing. checkTLSOptions throws to force the caller to choose one.
Solutions
- Remove tlsInsecure and keep the specific tlsAllowInvalid* flag you need.
- Or remove the tlsAllowInvalid* flags and keep only tlsInsecure.
Example fix
// before
new MongoClient('mongodb://h/db?tls=true&tlsInsecure=true&tlsAllowInvalidCertificates=true');
// after
new MongoClient('mongodb://h/db?tls=true&tlsAllowInvalidCertificates=true'); Defensive patterns
Strategy: validation
Validate before calling
function assertNoTlsConflict(opts: Record<string, unknown>) {
const has = (k: string) => opts[k] != null;
if (has('tlsInsecure') && (has('tlsAllowInvalidCertificates') || has('tlsAllowInvalidHostnames'))) {
throw new Error('tlsInsecure cannot be combined with tlsAllowInvalidCertificates/tlsAllowInvalidHostnames');
}
} Prevention
- Standardize on one TLS-loosening flag in your codebase.
- Avoid 'turn everything off' debugging stacks; commit to one flag before production.
When it happens
Trigger: Supplying tlsInsecure together with tlsAllowInvalidCertificates or tlsAllowInvalidHostnames in the URI query string or options object, parsed into the CaseInsensitiveMap of all provided options.
Common situations: A developer stacks every 'make TLS work' flag while fighting a self-signed cert, or migrates from older ssl config and forgets to remove redundant flags.
Related errors
- All values of tls/ssl must be the same.
- Auth mechanism property ALLOWED_HOSTS is not allowed in the…
- authMechanism requires an authSource of '$external
- Cannot combine replicaSet option with srvMaxHosts
- Cannot have empty URI params in DNS TXT Record
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/d1a00be3677bb49d.
Report an issue: GitHub.
Appendix: source
Thrown at src/connection_string.ts:170
throw new MongoParseError('Cannot combine replicaSet option with srvMaxHosts');
}
validateLoadBalancedOptions(hostAddresses, options, true);
return hostAddresses;
}
/**
* Checks if TLS options are valid
*
* @param allOptions - All options provided by user or included in default options map
* @throws MongoAPIError if TLS options are invalid
*/
function checkTLSOptions(allOptions: CaseInsensitiveMap): void {
if (!allOptions) return;
const check = (a: string, b: string) => {
if (allOptions.has(a) && allOptions.has(b)) {
throw new MongoAPIError(`The '${a}' option cannot be used with the '${b}' option`);
}
};
check('tlsInsecure', 'tlsAllowInvalidCertificates');
check('tlsInsecure', 'tlsAllowInvalidHostnames');
}
function getBoolean(name: string, value: unknown): boolean {
if (typeof value === 'boolean') return value;
switch (value) {
case 'true':
return true;
case 'false':
return false;
default:
throw new MongoParseError(`${name} must be either "true" or "false"`);
}
}
function getIntFromOptions(name: string, value: unknown): number {View on GitHub (pinned to dce7939f86)