mongodb/node-mongodb-native · error · MongoAPIError

username and password cannot be provided when using…

Error message

username and password cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.

What it means

Thrown by MongoAPIError when the connection uses authMechanism=MONGODB-AWS but a username or password is also present (in the URI or options). For MONGODB-AWS, the driver delegates credential discovery to the AWS SDK (env vars, ECS/EKS, EC2 IMDS, shared config), so embedding credentials in the URI defeats that and is rejected. Found at src/connection_string.ts:424 inside the isAws branch of credential post-processing.

Solutions

  1. Remove the username:password segment from the URI and remove the `auth` option; let the AWS SDK supply credentials via AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY env vars (or role/IMDS).
  2. If you must pass static IAM credentials, set env vars AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY (and AWS_SESSION_TOKEN if using temporary creds) instead of the URI.
  3. Switch authMechanism to a SCRAM mechanism (SCRAM-SHA-256 default) if the account is a normal database user, not an IAM principal.

Example fix

// before
new MongoClient('mongodb+srv://AKIAxxxx:secret@cluster.example.mongodb.net/?authMechanism=MONGODB-AWS')

// after (let AWS SDK read env vars)
new MongoClient('mongodb+srv://cluster.example.mongodb.net/?authMechanism=MONGODB-AWS')
Defensive patterns

Strategy: validation

Validate before calling

function assertAwsNoUserPass(uri, options = {}) {
  const mechanism = options.authMechanism ?? (uri.match(/authMechanism=([^&]+)/i)?.[1]);
  const hasUserInfo = /^[^?]+:\/\/[^\/\?]*:[^@\?]+@/.test(uri) || (options.auth && (options.auth.username || options.auth.password));
  if (/aws/i.test(mechanism || '') && hasUserInfo) {
    throw new Error('MONGODB-AWS forbids username/password in the URI; use AWS SDK env vars.');
  }
}

Try / catch

try { const client = new MongoClient(uri, options); } catch (e) { if (e instanceof MongoAPIError && /MONGODB-AWS/.test(e.message)) { /* strip credentials and retry with env-based auth */ } else throw e; }

Prevention

When it happens

Trigger: Call `new MongoClient('mongodb+srv://user:pass@cluster.mongodb.net/?authMechanism=MONGODB-AWS')` or pass `{ auth: { username, password }, authMechanism: 'MONGODB-AWS' }` in options. Any non-empty username or password on credentials when mechanism is MONGODB-AWS triggers it.

Common situations: Copying a SCRAM-SHA connection string and just appending `&authMechanism=MONGODB-AWS`; assuming AWS auth accepts IAM access-key id / secret as the URI user/password; mixing an IAM role assumption workflow with a static-credential URI template.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/a609a834148c4649. Report an issue: GitHub.

Appendix: source

Thrown at src/connection_string.ts:424

      );
    }

    if (
      !(isGssapi || isX509 || isAws || isOidc) &&
      mongoOptions.dbName &&
      !allProvidedOptions.has('authSource')
    ) {
      // inherit the dbName unless GSSAPI or X509, then silently ignore dbName
      // and there was no specific authSource given
      mongoOptions.credentials = MongoCredentials.merge(mongoOptions.credentials, {
        source: mongoOptions.dbName
      });
    }

    if (isAws) {
      const { username, password } = mongoOptions.credentials;
      if (username || password) {
        throw new MongoAPIError(
          'username and password cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.'
        );
      }
      if (mongoOptions.credentials.mechanismProperties.AWS_SESSION_TOKEN) {
        throw new MongoAPIError(
          'AWS_SESSION_TOKEN cannot be provided when using MONGODB-AWS. Credentials must be provided in a manner that can be read by the AWS SDK.'
        );
      }
    }

    mongoOptions.credentials.validate();

    // Check if the only auth related option provided was authSource, if so we can remove credentials
    if (
      mongoOptions.credentials.password === '' &&
      mongoOptions.credentials.username === '' &&
      mongoOptions.credentials.mechanism === AuthMechanism.MONGODB_DEFAULT &&
      Object.keys(mongoOptions.credentials.mechanismProperties).length === 0

View on GitHub (pinned to dce7939f86)