mongodb/node-mongodb-native · critical · MongoCryptError

unidentifiable error in MongoCrypt - received an error…

Error message

unidentifiable error in MongoCrypt - received an error status from `libmongocrypt` but received no error message.

What it means

The CSFLE state machine exited with MONGOCRYPT_CTX_ERROR but context.status.message was empty — libmongocrypt reported an error status without a human-readable message. The driver substitutes this descriptive string so the rejection is not a bare empty message. It almost always points to a lower-level libmongocrypt/KMS problem the driver cannot introspect.

Solutions

  1. Enable CSFLE debug logging (setAutoEncryptionExtraOptions / logger) to capture libmongocrypt's raw diagnostics, which often contain the real cause.
  2. Verify the value being encrypted/decrypted is a valid BSON-serializable / Binary(6) value respectively.
  3. Check that the data key document in the key vault is well-formed (not truncated, correct _id, correct keyMaterial).
  4. Align libmongocrypt/crypt_shared and driver versions if the input is known-good.
Defensive patterns

Strategy: try-catch

Try / catch

try {
  await clientEncryption.encrypt(value, opts);
} catch (e) {
  if (e instanceof MongoCryptError && /unidentifiable error/.test(e.message)) {
    // enable CSFLE debug logging and retry to capture libmongocrypt diagnostics
  }
  throw e;
}

Prevention

When it happens

Trigger: libmongocrypt hits an internal error (e.g. malformed BSON passed to a context, unsupported algorithm, KMS TLS failure) and sets ERROR without populating the message; corrupted/empty payload fed to decrypt; missing or malformed data key material.

Common situations: Feeding a non-Binary / wrong-subtype value to decrypt; passing malformed BSON to an expression encryption; KMS TLS handshake failure before libmongocrypt can describe it; version skew between libmongocrypt and the driver's expected message contract.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/3930f263f933aa66. Report an issue: GitHub.

Appendix: source

Thrown at src/client-side-encryption/state_machine.ts:291

            throw new MongoCryptError(message);
          }
          result = finalizedContext;
          break;
        }

        default:
          throw new MongoCryptError(`Unknown state: ${getState()}`);
      }
    }

    if (getState() === MONGOCRYPT_CTX_ERROR || result == null) {
      const message = getStatus().message;
      if (!message) {
        debug(
          `unidentifiable error in MongoCrypt - received an error status from \`libmongocrypt\` but received no error message.`
        );
      }
      throw new MongoCryptError(
        message ??
          'unidentifiable error in MongoCrypt - received an error status from `libmongocrypt` but received no error message.'
      );
    }

    return result;
  }

  /**
   * Handles the request to the KMS service. Exposed for testing purposes. Do not directly invoke.
   * @param kmsContext - A C++ KMS context returned from the bindings
   * @returns A promise that resolves when the KMS reply has be fully parsed
   */
  async kmsRequest(
    request: MongoCryptKMSRequest,
    options?: { timeoutContext?: TimeoutContext } & Abortable
  ): Promise<void> {
    const parsedUrl = request.endpoint.split(':');

View on GitHub (pinned to dce7939f86)