mongodb/node-mongodb-native · error · MongoAzureError

TOKEN_RESOURCE must be set in the auth mechanism properties…

Error message

TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure.

What it means

Thrown by the Azure machine workflow callback when tokenAudience (derived from TOKEN_RESOURCE) is missing at runtime. This is the in-flight equivalent of the validate() TOKEN_RESOURCE check, raised by azureCallback when params.tokenAudience is falsy. The Azure IMDS endpoint cannot mint a properly-scoped token without an audience.

Solutions

  1. Ensure authMechanismProperties includes TOKEN_RESOURCE (e.g. TOKEN_RESOURCE:'https://audience') for ENVIRONMENT:'azure'.
  2. In code, confirm the property name is exactly TOKEN_RESOURCE and the value is non-empty.
  3. Re-run with the latest driver patch; if it persists, log mechanismProperties right before connect to confirm propagation.

Example fix

// before
mechanismProperties: { ENVIRONMENT: 'azure' }
// after
mechanismProperties: { ENVIRONMENT: 'azure', TOKEN_RESOURCE: 'https://your-audience' }
Defensive patterns

Strategy: validation

Validate before calling

function assertAzureTokenResource(props) {
  if (props?.ENVIRONMENT === 'azure' && !props?.TOKEN_RESOURCE) {
    throw new Error('ENVIRONMENT azure requires TOKEN_RESOURCE.');
  }
}

Prevention

When it happens

Trigger: MONGODB-OIDC with ENVIRONMENT='azure' is selected but TOKEN_RESOURCE did not propagate to the callback (params.tokenAudience is undefined). Fires at azure_machine_workflow.ts:28.

Common situations: TOKEN_RESOURCE was set in a different options shape than the driver reads, or stripped during option merging. Constructing credentials manually and omitting the property. A connection string parsing issue dropping the property.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/700ec1ee2269d8ac. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/auth/mongodb_oidc/azure_machine_workflow.ts:28

const ENDPOINT_RESULT_ERROR =
  'Azure endpoint did not return a value with only access_token and expires_in properties';

/** Error for when the token audience is missing in the environment. */
const TOKEN_RESOURCE_MISSING_ERROR =
  'TOKEN_RESOURCE must be set in the auth mechanism properties when ENVIRONMENT is azure.';

/**
 * The callback function to be used in the automated callback workflow.
 * @param params - The OIDC callback parameters.
 * @returns The OIDC response.
 */
export const azureCallback: OIDCCallbackFunction = async (
  params: OIDCCallbackParams
): Promise<OIDCResponse> => {
  const tokenAudience = params.tokenAudience;
  const username = params.username;
  if (!tokenAudience) {
    throw new MongoAzureError(TOKEN_RESOURCE_MISSING_ERROR);
  }
  const response = await getAzureTokenData(tokenAudience, username);
  if (!isEndpointResultValid(response)) {
    throw new MongoAzureError(ENDPOINT_RESULT_ERROR);
  }
  return response;
};

/**
 * Hit the Azure endpoint to get the token data.
 */
async function getAzureTokenData(tokenAudience: string, username?: string): Promise<OIDCResponse> {
  const url = new URL(AZURE_BASE_URL);
  addAzureParams(url, tokenAudience, username);
  const response = await get(url, {
    headers: AZURE_HEADERS
  });
  if (response.status !== 200) {

View on GitHub (pinned to dce7939f86)