mongodb/node-mongodb-native · error · MongoCryptAzureKMSRequestError
Unable to complete request.
Error message
Unable to complete request.
What it means
Thrown by the Azure KMS credential provider when the IMDS HTTP response status is not 200. parseResponse attaches the parsed body as the error's payload so the caller can see the Azure error details. It is a MongoCryptAzureKMSRequestError surfaced while fetching the Azure access token for CSFLE/Queryable Encryption.
Solutions
- Confirm a managed identity is assigned to the Azure resource (System assigned or User assigned) and has propagated (can take a few minutes).
- Grant the identity the required Key Vault access roles: Key Vault Reader plus Key Vault Crypto Service Encryption User (for CMK wrap/unwrap).
- For transient 5xx, retry the operation after a short backoff; IMDS can be briefly unavailable during boot.
- If no managed identity is available, configure the azure kmsProvider with explicit tenantId/clientId/clientSecret instead of {}.
Example fix
// before: resource has no managed identity -> IMDS 400
const client = new MongoClient(uri, {
autoEncryption: { kmsProviders: { azure: {} } }
});
// after: assign identity in Azure, or use explicit SP credentials
const client = new MongoClient(uri, {
autoEncryption: {
kmsProviders: {
azure: { tenantId, clientId, clientSecret }
}
}
}); Defensive patterns
Strategy: retry
Try / catch
try {
await loadAzureCredentials(kmsProviders);
} catch (e) {
if (e instanceof MongoCryptAzureKMSRequestError && e.message === 'Unable to complete request.') {
// inspect e payload, then retry with backoff for transient 5xx
}
throw e;
} Prevention
- Confirm a managed identity is attached and has the Key Vault wrap/unwrap roles.
- For transient 5xx from IMDS, implement bounded retry with backoff.
When it happens
Trigger: IMDS returning 400/401/403/404/500 (e.g. no managed identity assigned: 400 with 'Identity not found'); the resource/audience mismatch; Azure throttling; transient 5xx during IMDS startup.
Common situations: Azure VM/App Service has no system- or user-assigned managed identity attached (IMDS returns 400); the managed identity lacks 'Key Vault Reader' + 'Key Vault Crypto Service Encryption User' roles; Azure platform incident causing 5xx from IMDS; recently attached identity not yet propagated.
Related errors
- [Azure KMS]
- Malformed JSON body in GET request.
- Malformed response body - missing field `access_token`.
- KMS request timed out
- Malformed response body - missing field `expires_in`.
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/12fc5d1f45d62f4d.
Report an issue: GitHub.
Appendix: source
Thrown at src/client-side-encryption/providers/azure.ts:80
export const tokenCache = new AzureCredentialCache();
/** @internal */
async function parseResponse(response: {
body: string;
status?: number;
}): Promise<AzureTokenCacheEntry> {
const { status, body: rawBody } = response;
const body: { expires_in?: number; access_token?: string } = (() => {
try {
return JSON.parse(rawBody);
} catch {
throw new MongoCryptAzureKMSRequestError('Malformed JSON body in GET request.');
}
})();
if (status !== 200) {
throw new MongoCryptAzureKMSRequestError('Unable to complete request.', body);
}
if (!body.access_token) {
throw new MongoCryptAzureKMSRequestError(
'Malformed response body - missing field `access_token`.'
);
}
if (!body.expires_in) {
throw new MongoCryptAzureKMSRequestError(
'Malformed response body - missing field `expires_in`.'
);
}
const expiresInMS = Number(body.expires_in) * 1000;
if (Number.isNaN(expiresInMS)) {
throw new MongoCryptAzureKMSRequestError(
'Malformed response body - unable to parse int from `expires_in` field.'View on GitHub (pinned to dce7939f86)