redis/node-redis · error · Error

MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables…

Error message

MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables must be set

What it means

The `auth-code-pkce` sample builds an MSAL authorization-code-with-PKCE provider that needs an app registration; it refuses to start unless both `MSAL_CLIENT_ID` and `MSAL_TENANT_ID` are present. Startup guard in the sample entry, after the session check.

Solutions

  1. Register an application in Entra ID (Azure portal) and copy its Application (client) ID and Directory (tenant) ID.
  2. Add `MSAL_CLIENT_ID` and `MSAL_TENANT_ID` to the sample `.env`.
  3. Restart the sample after setting the variables.

Example fix

# .env (before: missing)
# after
MSAL_CLIENT_ID=00000000-0000-0000-0000-000000000000
MSAL_TENANT_ID=00000000-0000-0000-0000-000000000000
Defensive patterns

Strategy: validation

Validate before calling

function requireEnvs(names: string[]): Record<string, string> {
  const out: Record<string, string> = {};
  for (const n of names) {
    const v = process.env[n];
    if (!v) throw new Error(`${names.join(' and ')} environment variables must be set`);
    out[n] = v;
  }
  return out;
}
const { MSAL_CLIENT_ID, MSAL_TENANT_ID } = requireEnvs(['MSAL_CLIENT_ID', 'MSAL_TENANT_ID']);

Type guard

function hasMsalEnv(): boolean {
  return Boolean(process.env.MSAL_CLIENT_ID) && Boolean(process.env.MSAL_TENANT_ID);
}

Prevention

When it happens

Trigger: Running the `auth-code-pkce` sample without `MSAL_CLIENT_ID` and/or `MSAL_TENANT_ID` set. Throws at module load before MSAL is initialized.

Common situations: No Entra ID app registration created yet; registration exists but env vars not populated; `.env` incomplete; wrong env in container.

Related errors


AI-assisted analysis of redis/node-redis@90fd0652bc (2026-08-11). Data as JSON: /api/errors/8c6fc938af348369. Report an issue: GitHub.

Appendix: source

Thrown at packages/entraid/samples/auth-code-pkce/index.ts:41

const app = express();

const sessionConfig = {
  secret: process.env.SESSION_SECRET,
  resave: false,
  saveUninitialized: false,
  cookie: {
    secure: process.env.NODE_ENV === 'production', // Only use secure in production
    httpOnly: true,
    sameSite: 'lax',
    maxAge: 3600000 // 1 hour
  }
} as const;

app.use(session(sessionConfig));

if (!process.env.MSAL_CLIENT_ID || !process.env.MSAL_TENANT_ID) {
  throw new Error('MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables must be set');
}

// Initialize MSAL provider with authorization code PKCE flow
const {
  getPKCECodes,
  createCredentialsProvider,
  getAuthCodeUrl
} = EntraIdCredentialsProviderFactory.createForAuthorizationCodeWithPKCE({
  clientId: process.env.MSAL_CLIENT_ID,
  redirectUri: process.env.REDIRECT_URI || 'http://localhost:3000/redirect',
  authorityConfig: { type: 'multi-tenant', tenantId: process.env.MSAL_TENANT_ID },
  tokenManagerConfig: DEFAULT_TOKEN_MANAGER_CONFIG
});

app.get('/login', async (req: AuthRequest, res: Response) => {
  try {
    // Generate PKCE Codes before starting the authorization flow
    const pkceCodes = await getPKCECodes();

View on GitHub (pinned to 90fd0652bc)