mongodb/node-mongodb-native · error · MongoAPIError
username and password cannot be provided when using…
Error message
username and password cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.
What it means
Thrown by MongoAPIError when the connection uses authMechanism=MONGODB-AWS but a username or password is also present (in the URI or options). For MONGODB-AWS, the driver delegates credential discovery to the AWS SDK (env vars, ECS/EKS, EC2 IMDS, shared config), so embedding credentials in the URI defeats that and is rejected. Found at src/connection_string.ts:424 inside the isAws branch of credential post-processing.
Solutions
- Remove the username:password segment from the URI and remove the `auth` option; let the AWS SDK supply credentials via AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY env vars (or role/IMDS).
- If you must pass static IAM credentials, set env vars AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY (and AWS_SESSION_TOKEN if using temporary creds) instead of the URI.
- Switch authMechanism to a SCRAM mechanism (SCRAM-SHA-256 default) if the account is a normal database user, not an IAM principal.
Example fix
// before
new MongoClient('mongodb+srv://AKIAxxxx:secret@cluster.example.mongodb.net/?authMechanism=MONGODB-AWS')
// after (let AWS SDK read env vars)
new MongoClient('mongodb+srv://cluster.example.mongodb.net/?authMechanism=MONGODB-AWS') Defensive patterns
Strategy: validation
Validate before calling
function assertAwsNoUserPass(uri, options = {}) {
const mechanism = options.authMechanism ?? (uri.match(/authMechanism=([^&]+)/i)?.[1]);
const hasUserInfo = /^[^?]+:\/\/[^\/\?]*:[^@\?]+@/.test(uri) || (options.auth && (options.auth.username || options.auth.password));
if (/aws/i.test(mechanism || '') && hasUserInfo) {
throw new Error('MONGODB-AWS forbids username/password in the URI; use AWS SDK env vars.');
}
} Try / catch
try { const client = new MongoClient(uri, options); } catch (e) { if (e instanceof MongoAPIError && /MONGODB-AWS/.test(e.message)) { /* strip credentials and retry with env-based auth */ } else throw e; } Prevention
- For MONGODB-AWS, never put IAM access key id / secret in the URI; rely on the AWS SDK default credential chain.
- Unit-test URI construction so that any AWS-mechanism template cannot be combined with user info.
- Keep one config module that knows the auth mechanism and emits the URI accordingly.
When it happens
Trigger: Call `new MongoClient('mongodb+srv://user:pass@cluster.mongodb.net/?authMechanism=MONGODB-AWS')` or pass `{ auth: { username, password }, authMechanism: 'MONGODB-AWS' }` in options. Any non-empty username or password on credentials when mechanism is MONGODB-AWS triggers it.
Common situations: Copying a SCRAM-SHA connection string and just appending `&authMechanism=MONGODB-AWS`; assuming AWS auth accepts IAM access-key id / secret as the URI user/password; mixing an IAM role assumption workflow with a static-credential URI template.
Related errors
- AWS_SESSION_TOKEN cannot be provided when using…
- AuthContext must provide credentials.
- authMechanism not supported
- authMechanism one of
- AuthMechanismProperties must be an object
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/a609a834148c4649.
Report an issue: GitHub.
Appendix: source
Thrown at src/connection_string.ts:424
);
}
if (
!(isGssapi || isX509 || isAws || isOidc) &&
mongoOptions.dbName &&
!allProvidedOptions.has('authSource')
) {
// inherit the dbName unless GSSAPI or X509, then silently ignore dbName
// and there was no specific authSource given
mongoOptions.credentials = MongoCredentials.merge(mongoOptions.credentials, {
source: mongoOptions.dbName
});
}
if (isAws) {
const { username, password } = mongoOptions.credentials;
if (username || password) {
throw new MongoAPIError(
'username and password cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.'
);
}
if (mongoOptions.credentials.mechanismProperties.AWS_SESSION_TOKEN) {
throw new MongoAPIError(
'AWS_SESSION_TOKEN cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.'
);
}
}
mongoOptions.credentials.validate();
// Check if the only auth related option provided was authSource, if so we can remove credentials
if (
mongoOptions.credentials.password === '' &&
mongoOptions.credentials.username === '' &&
mongoOptions.credentials.mechanism === AuthMechanism.MONGODB_DEFAULT &&
Object.keys(mongoOptions.credentials.mechanismProperties).length === 0View on GitHub (pinned to dce7939f86)