mongodb/node-mongodb-native · error · MongoAPIError

The ' ' option cannot be used with the ' ' option

Error message

The '${a}' option cannot be used with the '${b}' option

What it means

TLS option conflict guard. tlsInsecure is a convenience flag that disables all certificate and hostname validation; using it alongside either tlsAllowInvalidCertificates or tlsAllowInvalidHostnames is redundant and confusing. checkTLSOptions throws to force the caller to choose one.

Solutions

  1. Remove tlsInsecure and keep the specific tlsAllowInvalid* flag you need.
  2. Or remove the tlsAllowInvalid* flags and keep only tlsInsecure.

Example fix

// before
new MongoClient('mongodb://h/db?tls=true&tlsInsecure=true&tlsAllowInvalidCertificates=true');
// after
new MongoClient('mongodb://h/db?tls=true&tlsAllowInvalidCertificates=true');
Defensive patterns

Strategy: validation

Validate before calling

function assertNoTlsConflict(opts: Record<string, unknown>) {
  const has = (k: string) => opts[k] != null;
  if (has('tlsInsecure') && (has('tlsAllowInvalidCertificates') || has('tlsAllowInvalidHostnames'))) {
    throw new Error('tlsInsecure cannot be combined with tlsAllowInvalidCertificates/tlsAllowInvalidHostnames');
  }
}

Prevention

When it happens

Trigger: Supplying tlsInsecure together with tlsAllowInvalidCertificates or tlsAllowInvalidHostnames in the URI query string or options object, parsed into the CaseInsensitiveMap of all provided options.

Common situations: A developer stacks every 'make TLS work' flag while fighting a self-signed cert, or migrates from older ssl config and forgets to remove redundant flags.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/d1a00be3677bb49d. Report an issue: GitHub.

Appendix: source

Thrown at src/connection_string.ts:170

    throw new MongoParseError('Cannot combine replicaSet option with srvMaxHosts');
  }

  validateLoadBalancedOptions(hostAddresses, options, true);

  return hostAddresses;
}

/**
 * Checks if TLS options are valid
 *
 * @param allOptions - All options provided by user or included in default options map
 * @throws MongoAPIError if TLS options are invalid
 */
function checkTLSOptions(allOptions: CaseInsensitiveMap): void {
  if (!allOptions) return;
  const check = (a: string, b: string) => {
    if (allOptions.has(a) && allOptions.has(b)) {
      throw new MongoAPIError(`The '${a}' option cannot be used with the '${b}' option`);
    }
  };
  check('tlsInsecure', 'tlsAllowInvalidCertificates');
  check('tlsInsecure', 'tlsAllowInvalidHostnames');
}
function getBoolean(name: string, value: unknown): boolean {
  if (typeof value === 'boolean') return value;
  switch (value) {
    case 'true':
      return true;
    case 'false':
      return false;
    default:
      throw new MongoParseError(`${name} must be either "true" or "false"`);
  }
}

function getIntFromOptions(name: string, value: unknown): number {

View on GitHub (pinned to dce7939f86)