redis/node-redis · error · Error
Invalid authority configuration
Error message
Invalid authority configuration
What it means
`EntraIdCredentialsProviderFactory.getAuthority()` switches on `config.type` and only knows `'multi-tenant'`, `'custom'`, and `'default'` (the `AuthorityConfig` discriminated union). Any other value hits the `default` branch and throws 'Invalid authority configuration'. TypeScript narrows the union so this is primarily a runtime/JSDoc-default concern when config arrives untyped.
Solutions
- Use exactly one of: `{ type: 'multi-tenant', tenantId }`, `{ type: 'custom', authorityUrl }`, or `{ type: 'default' }`.
- Validate/normalize the `type` string before constructing the config (case-sensitive).
- Type the config source as `AuthorityConfig` so the compiler rejects bad values.
Example fix
// before
getAuthority({ type: 'multitenant', tenantId: 'xxx' }); // typo
// after
getAuthority({ type: 'multi-tenant', tenantId: 'xxx' }); Defensive patterns
Strategy: type-guard
Validate before calling
function normalizeAuthority(c: unknown) {
if (c && typeof c === 'object' && 'type' in c) {
const t = (c as { type: string }).type;
if (t === 'multi-tenant' || t === 'custom' || t === 'default') return c;
}
throw new Error(`Unknown authority type; expected multi-tenant|custom|default`);
} Type guard
function isAuthorityConfig(c: unknown): c is { type: 'multi-tenant'; tenantId: string } | { type: 'custom'; authorityUrl: string } | { type: 'default' } {
if (!c || typeof c !== 'object') return false;
const t = (c as { type?: unknown }).type;
return t === 'multi-tenant' || t === 'custom' || t === 'default';
} Try / catch
try { EntraIdCredentialsProviderFactory.getAuthority(cfg); }
catch (e) {
if (String(e).includes('Invalid authority configuration')) {
cfg = { type: 'default' as const };
EntraIdCredentialsProviderFactory.getAuthority(cfg);
} else throw e;
} Prevention
- Type config sources as AuthorityConfig so the compiler rejects bad discriminators.
- Validate config loaded from env/JSON against the union before use.
When it happens
Trigger: Passing an `AuthorityConfig` whose `type` is not one of the three valid literals, e.g. from parsed JSON/env where the field is missing, misspelled ('multitenant'), or lowercased differently.
Common situations: Loading authority config from environment/JSON without validation; typo in the discriminator; version skew where a caller sends an old/new type string.
Related errors
- MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables…
- Client Side Caching is only supported with RESP3
- Client Side Caching is only supported with RESP3
- Cluster already open
- Config file not found at path
AI-assisted analysis of redis/node-redis@90fd0652bc (2026-08-11).
Data as JSON: /api/errors/9283ac9ba7b763da.
Report an issue: GitHub.
Appendix: source
Thrown at packages/entraid/lib/entra-id-credentials-provider-factory.ts:258
return new EntraidCredentialsProvider(tm, idp, {
onReAuthenticationError: params.onReAuthenticationError,
credentialsMapper: params.credentialsMapper ?? DEFAULT_CREDENTIALS_MAPPER,
onRetryableError: params.onRetryableError
});
}
};
}
static getAuthority(config: AuthorityConfig): string {
switch (config.type) {
case 'multi-tenant':
return `https://login.microsoftonline.com/${config.tenantId}`;
case 'custom':
return config.authorityUrl;
case 'default':
return 'https://login.microsoftonline.com/common';
default:
throw new Error('Invalid authority configuration');
}
}
}
export const REDIS_SCOPE_DEFAULT = 'https://redis.azure.com/.default';
export const REDIS_SCOPE = 'https://redis.azure.com'
export type AuthorityConfig =
| { type: 'multi-tenant'; tenantId: string }
| { type: 'custom'; authorityUrl: string }
| { type: 'default' };
export type PKCEParams = {
code: string;
verifier: string;
clientInfo?: string;
}View on GitHub (pinned to 90fd0652bc)