mongodb/node-mongodb-native · critical · MongoCryptError
unidentifiable error in MongoCrypt - received an error…
Error message
unidentifiable error in MongoCrypt - received an error status from `libmongocrypt` but received no error message.
What it means
The CSFLE state machine exited with MONGOCRYPT_CTX_ERROR but context.status.message was empty — libmongocrypt reported an error status without a human-readable message. The driver substitutes this descriptive string so the rejection is not a bare empty message. It almost always points to a lower-level libmongocrypt/KMS problem the driver cannot introspect.
Solutions
- Enable CSFLE debug logging (setAutoEncryptionExtraOptions / logger) to capture libmongocrypt's raw diagnostics, which often contain the real cause.
- Verify the value being encrypted/decrypted is a valid BSON-serializable / Binary(6) value respectively.
- Check that the data key document in the key vault is well-formed (not truncated, correct _id, correct keyMaterial).
- Align libmongocrypt/crypt_shared and driver versions if the input is known-good.
Defensive patterns
Strategy: try-catch
Try / catch
try {
await clientEncryption.encrypt(value, opts);
} catch (e) {
if (e instanceof MongoCryptError && /unidentifiable error/.test(e.message)) {
// enable CSFLE debug logging and retry to capture libmongocrypt diagnostics
}
throw e;
} Prevention
- Enable CSFLE logging (AutoEncryption logger) in non-prod to capture libmongocrypt messages.
- Validate input is a BSON-serializable value (encrypt) or a Binary subtype 6 (decrypt) before calling.
When it happens
Trigger: libmongocrypt hits an internal error (e.g. malformed BSON passed to a context, unsupported algorithm, KMS TLS failure) and sets ERROR without populating the message; corrupted/empty payload fed to decrypt; missing or malformed data key material.
Common situations: Feeding a non-Binary / wrong-subtype value to decrypt; passing malformed BSON to an expression encryption; KMS TLS handshake failure before libmongocrypt can describe it; version skew between libmongocrypt and the driver's expected message contract.
Related errors
- Unknown state
- unreachable state machine state: entered…
- unreachable state machine state: entered…
- Expected result of decryption to be deserialized BSON object
- Finalization error
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/3930f263f933aa66.
Report an issue: GitHub.
Appendix: source
Thrown at src/client-side-encryption/state_machine.ts:291
throw new MongoCryptError(message);
}
result = finalizedContext;
break;
}
default:
throw new MongoCryptError(`Unknown state: ${getState()}`);
}
}
if (getState() === MONGOCRYPT_CTX_ERROR || result == null) {
const message = getStatus().message;
if (!message) {
debug(
`unidentifiable error in MongoCrypt - received an error status from \`libmongocrypt\` but received no error message.`
);
}
throw new MongoCryptError(
message ??
'unidentifiable error in MongoCrypt - received an error status from `libmongocrypt` but received no error message.'
);
}
return result;
}
/**
* Handles the request to the KMS service. Exposed for testing purposes. Do not directly invoke.
* @param kmsContext - A C++ KMS context returned from the bindings
* @returns A promise that resolves when the KMS reply has be fully parsed
*/
async kmsRequest(
request: MongoCryptKMSRequest,
options?: { timeoutContext?: TimeoutContext } & Abortable
): Promise<void> {
const parsedUrl = request.endpoint.split(':');View on GitHub (pinned to dce7939f86)