{"record":{"id":"2fcef9e0ae710461","repo":"hashicorp/terraform","slug":"failed-to-request-password-s","errorCode":null,"errorMessage":"Failed to request password: %s","messagePattern":"Failed to request password: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/login.go","lineNumber":561,"sourceCode":"\n\tc.Ui.Output(\"\\n---------------------------------------------------------------------------------\\n\")\n\tc.Ui.Output(\"Terraform must temporarily use your password to request an API token.\\nThis password will NOT be saved locally.\\n\")\n\n\tusername, err := c.UIInput().Input(context.Background(), &terraform.InputOpts{\n\t\tId:    \"username\",\n\t\tQuery: fmt.Sprintf(\"Username for %s:\", hostname.ForDisplay()),\n\t})\n\tif err != nil {\n\t\tdiags = diags.Append(fmt.Errorf(\"Failed to request username: %s\", err))\n\t\treturn nil, diags\n\t}\n\tpassword, err := c.UIInput().Input(context.Background(), &terraform.InputOpts{\n\t\tId:     \"password\",\n\t\tQuery:  fmt.Sprintf(\"Password for %s:\", hostname.ForDisplay()),\n\t\tSecret: true,\n\t})\n\tif err != nil {\n\t\tdiags = diags.Append(fmt.Errorf(\"Failed to request password: %s\", err))\n\t\treturn nil, diags\n\t}\n\n\toauthConfig := &oauth2.Config{\n\t\tClientID: clientConfig.ID,\n\t\tEndpoint: clientConfig.Endpoint(),\n\t\tScopes:   clientConfig.Scopes,\n\t}\n\ttoken, err := oauthConfig.PasswordCredentialsToken(context.Background(), username, password)\n\tif err != nil {\n\t\t// FIXME: The OAuth2 library generates errors that are not appropriate\n\t\t// for a Terraform end-user audience, so once we have more experience\n\t\t// with which errors are most common we should try to recognize them\n\t\t// here and produce better error messages for them.\n\t\tdiags = diags.Append(tfdiags.Sourceless(\n\t\t\ttfdiags.Error,\n\t\t\t\"Failed to retrieve API token\",\n\t\t\tfmt.Sprintf(\"The remote host did not issue an API token: %s.\", err),","sourceCodeStart":543,"sourceCodeEnd":579,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/login.go#L543-L579","documentation":"Sibling of error 637: the password prompt (c.UIInput().Input with Secret:true) returned an error during the password-grant login flow. The cause is environmental (no/failed TTY, cancelled input), not credential validation; credential validation happens later against the OAuth token endpoint.","triggerScenarios":"Non-interactive runtime without a TTY; the password prompt was cancelled or EOF'd; a custom UIInput backend failed specifically on the secret prompt.","commonSituations":"CI/container runs of `terraform login`; stdin closed or piped; user aborted at the password prompt; terminal that cannot read hidden input.","solutions":["Supply the token via `TF_TOKEN_<hostname>` env var or the credentials file instead of interactive login.","Run login in a TTY-capable terminal.","Use the token-based login path (paste a token) or the browser OAuth flow instead of username/password.","Verify the terminal supports secret input and is not redirected."],"exampleFix":"# before: terraform login in a non-TTY shell -> 'Failed to request password'\n\n# after: skip the prompt entirely\nexport TF_TOKEN_app_terraform_io=\"<token>\"\nterraform init","handlingStrategy":"validation","validationCode":"if !canPrompt() { // see error 637's canPrompt()\n    return errors.New(\"no TTY: provide credentials via TF_TOKEN_<hostname> or the credentials file\")\n}","typeGuard":null,"tryCatchPattern":"password, err := c.UIInput().Input(ctx, opts)\nif err != nil {\n    if !canPrompt() {\n        return fmt.Errorf(\"password prompt needs a TTY; set TF_TOKEN_%s instead: %w\", hostname, err)\n    }\n    return err\n}","preventionTips":["Avoid username/password login in automation; prefer token env vars or OAuth.","Ensure stdin is a real TTY when interactive login is unavoidable.","Surface a clear 'no TTY' message instead of letting UIInput fail opaquely."],"tags":["terraform","login","auth","ui-input","tty","interactive"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}