{"record":{"id":"0a0ae45e23f8b0ac","repo":"hashicorp/terraform","slug":"failed-to-retrieve-credentials-for-s-s","errorCode":null,"errorMessage":"failed to retrieve credentials for %s: %s","messagePattern":"failed to retrieve credentials for (.+?): (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/registry_source.go","lineNumber":144,"sourceCode":"\tcase *disco.ErrVersionNotSupported:\n\t\treturn nil, ErrHostNoProviders{\n\t\t\tHostname:        hostname,\n\t\t\tHasOtherVersion: true,\n\t\t}\n\tdefault:\n\t\treturn nil, ErrHostUnreachable{\n\t\t\tHostname: hostname,\n\t\t\tWrapped:  err,\n\t\t}\n\t}\n\n\t// Check if we have credentials configured for this hostname.\n\tcreds, err := s.services.CredentialsForHost(hostname)\n\tif err != nil {\n\t\t// This indicates that a credentials helper failed, which means we\n\t\t// can't do anything better than just pass through the helper's\n\t\t// own error message.\n\t\treturn nil, fmt.Errorf(\"failed to retrieve credentials for %s: %s\", hostname, err)\n\t}\n\n\treturn newRegistryClient(url, creds), nil\n}\n\nfunc (s *RegistrySource) ForDisplay(provider addrs.Provider) string {\n\treturn fmt.Sprintf(\"registry %s\", provider.Hostname.ForDisplay())\n}\n","sourceCodeStart":126,"sourceCodeEnd":153,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/registry_source.go#L126-L153","documentation":"Returned when RegistrySource.registryClient fails to obtain credentials for a hostname via services.CredentialsForHost. This indicates a credentials *helper* (e.g. terraform-credentials-env, a custom credential helper, or the token store) errored, not that credentials are simply absent. The '%s' suffix carries the helper's own error.","triggerScenarios":"A credential helper binary exited non-zero or returned malformed output for the given hostname; the cached token in ~/.terraform.d/credentials is corrupt; 'terraform login' stored a token that the helper cannot parse.","commonSituations":"Custom credential helper misconfigured in CLI config; helper binary not on PATH or crashing; corrupted credentials.tfrc.json; token format changed after a terraform upgrade.","solutions":["Read the trailing '%s' which contains the helper's native error and address that root cause.","Re-run 'terraform login <hostname>' to refresh the stored token.","Inspect ~/.terraform.d/credentials.tfrc.json (or the helper output) for malformed JSON.","If a custom helper is in use, run it manually with the hostname to reproduce and fix.","Temporarily unset the credential helper to confirm it is the source of the failure."],"exampleFix":"// before\nError: failed to retrieve credentials for app.terraform.io: helper exited with status 127\n// after (ensure helper is on PATH or remove the helper block from ~/.terraformrc)\ncredentials_helper \"atlassian\" { args = [] }","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"// Surface the helper's underlying error and degrade gracefully.\n_, err := source.PackageMeta(...)\nif err != nil && strings.Contains(err.Error(), \"failed to retrieve credentials for\") {\n    log.Printf(\"credential helper issue: %v\", err)\n    // fall back to anonymous registry access or prompt re-login\n}","preventionTips":["Keep credential helper binaries on PATH and tested in CI.","Validate ~/.terraform.d/credentials.tfrc.json with a JSON linter.","Periodically re-run 'terraform login' to refresh tokens."],"tags":["credentials","registry","auth","getproviders"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}