mongodb/node-mongodb-native · error · MongoAzureError
TOKEN_RESOURCE must be set in the auth mechanism properties…
Error message
TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure.
What it means
Thrown by the Azure machine workflow callback when tokenAudience (derived from TOKEN_RESOURCE) is missing at runtime. This is the in-flight equivalent of the validate() TOKEN_RESOURCE check, raised by azureCallback when params.tokenAudience is falsy. The Azure IMDS endpoint cannot mint a properly-scoped token without an audience.
Solutions
- Ensure authMechanismProperties includes TOKEN_RESOURCE (e.g. TOKEN_RESOURCE:'https://audience') for ENVIRONMENT:'azure'.
- In code, confirm the property name is exactly TOKEN_RESOURCE and the value is non-empty.
- Re-run with the latest driver patch; if it persists, log mechanismProperties right before connect to confirm propagation.
Example fix
// before
mechanismProperties: { ENVIRONMENT: 'azure' }
// after
mechanismProperties: { ENVIRONMENT: 'azure', TOKEN_RESOURCE: 'https://your-audience' } Defensive patterns
Strategy: validation
Validate before calling
function assertAzureTokenResource(props) {
if (props?.ENVIRONMENT === 'azure' && !props?.TOKEN_RESOURCE) {
throw new Error('ENVIRONMENT azure requires TOKEN_RESOURCE.');
}
} Prevention
- Always set TOKEN_RESOURCE alongside ENVIRONMENT:'azure'.
- Validate mechanismProperties in a config layer before connect.
- Log the resolved mechanismProperties in dev to confirm propagation.
When it happens
Trigger: MONGODB-OIDC with ENVIRONMENT='azure' is selected but TOKEN_RESOURCE did not propagate to the callback (params.tokenAudience is undefined). Fires at azure_machine_workflow.ts:28.
Common situations: TOKEN_RESOURCE was set in a different options shape than the driver reads, or stripped during option merging. Constructing credentials manually and omitting the property. A connection string parsing issue dropping the property.
Related errors
- TOKEN_RESOURCE must be set in the auth mechanism properties…
- Auth mechanism property ALLOWED_HOSTS must be an array of…
- AuthContext must provide credentials.
- Azure endpoint did not return a value with only…
- Currently only a ENVIRONMENT in
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/700ec1ee2269d8ac.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts:28
const ENDPOINT_RESULT_ERROR =
'Azure endpoint did not return a value with only access_token and expires_in properties';
/** Error for when the token audience is missing in the environment. */
const TOKEN_RESOURCE_MISSING_ERROR =
'TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure.';
/**
* The callback function to be used in the automated callback workflow.
* @param params - The OIDC callback parameters.
* @returns The OIDC response.
*/
export const azureCallback: OIDCCallbackFunction = async (
params: OIDCCallbackParams
): Promise<OIDCResponse> => {
const tokenAudience = params.tokenAudience;
const username = params.username;
if (!tokenAudience) {
throw new MongoAzureError(TOKEN_RESOURCE_MISSING_ERROR);
}
const response = await getAzureTokenData(tokenAudience, username);
if (!isEndpointResultValid(response)) {
throw new MongoAzureError(ENDPOINT_RESULT_ERROR);
}
return response;
};
/**
* Hit the Azure endpoint to get the token data.
*/
async function getAzureTokenData(tokenAudience: string, username?: string): Promise<OIDCResponse> {
const url = new URL(AZURE_BASE_URL);
addAzureParams(url, tokenAudience, username);
const response = await get(url, {
headers: AZURE_HEADERS
});
if (response.status !== 200) {View on GitHub (pinned to dce7939f86)