redis/node-redis · error · Error
MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables…
Error message
MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables must be set
What it means
The `auth-code-pkce` sample builds an MSAL authorization-code-with-PKCE provider that needs an app registration; it refuses to start unless both `MSAL_CLIENT_ID` and `MSAL_TENANT_ID` are present. Startup guard in the sample entry, after the session check.
Solutions
- Register an application in Entra ID (Azure portal) and copy its Application (client) ID and Directory (tenant) ID.
- Add `MSAL_CLIENT_ID` and `MSAL_TENANT_ID` to the sample `.env`.
- Restart the sample after setting the variables.
Example fix
# .env (before: missing) # after MSAL_CLIENT_ID=00000000-0000-0000-0000-000000000000 MSAL_TENANT_ID=00000000-0000-0000-0000-000000000000
Defensive patterns
Strategy: validation
Validate before calling
function requireEnvs(names: string[]): Record<string, string> {
const out: Record<string, string> = {};
for (const n of names) {
const v = process.env[n];
if (!v) throw new Error(`${names.join(' and ')} environment variables must be set`);
out[n] = v;
}
return out;
}
const { MSAL_CLIENT_ID, MSAL_TENANT_ID } = requireEnvs(['MSAL_CLIENT_ID', 'MSAL_TENANT_ID']); Type guard
function hasMsalEnv(): boolean {
return Boolean(process.env.MSAL_CLIENT_ID) && Boolean(process.env.MSAL_TENANT_ID);
} Prevention
- Create the Entra ID app registration before first run.
- Keep all required env vars in a version-controlled `.env.example`.
When it happens
Trigger: Running the `auth-code-pkce` sample without `MSAL_CLIENT_ID` and/or `MSAL_TENANT_ID` set. Throws at module load before MSAL is initialized.
Common situations: No Entra ID app registration created yet; registration exists but env vars not populated; `.env` incomplete; wrong env in container.
Related errors
- SESSION_SECRET environment variable must be set
- SESSION_SECRET environment variable must be set
- Invalid token response
- MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables…
- Database not found in
AI-assisted analysis of redis/node-redis@90fd0652bc (2026-08-11).
Data as JSON: /api/errors/8c6fc938af348369.
Report an issue: GitHub.
Appendix: source
Thrown at packages/entraid/samples/auth-code-pkce/index.ts:41
const app = express();
const sessionConfig = {
secret: process.env.SESSION_SECRET,
resave: false,
saveUninitialized: false,
cookie: {
secure: process.env.NODE_ENV === 'production', // Only use secure in production
httpOnly: true,
sameSite: 'lax',
maxAge: 3600000 // 1 hour
}
} as const;
app.use(session(sessionConfig));
if (!process.env.MSAL_CLIENT_ID || !process.env.MSAL_TENANT_ID) {
throw new Error('MSAL_CLIENT_ID and MSAL_TENANT_ID environment variables must be set');
}
// Initialize MSAL provider with authorization code PKCE flow
const {
getPKCECodes,
createCredentialsProvider,
getAuthCodeUrl
} = EntraIdCredentialsProviderFactory.createForAuthorizationCodeWithPKCE({
clientId: process.env.MSAL_CLIENT_ID,
redirectUri: process.env.REDIRECT_URI || 'http://localhost:3000/redirect',
authorityConfig: { type: 'multi-tenant', tenantId: process.env.MSAL_TENANT_ID },
tokenManagerConfig: DEFAULT_TOKEN_MANAGER_CONFIG
});
app.get('/login', async (req: AuthRequest, res: Response) => {
try {
// Generate PKCE Codes before starting the authorization flow
const pkceCodes = await getPKCECodes();View on GitHub (pinned to 90fd0652bc)