{"record":{"id":"9470c42dc67cda17","repo":"hashicorp/terraform","slug":"organization-q-at-host-s-not-found-please-ensu-9470c4","errorCode":null,"errorMessage":"organization %q at host %s not found.\n\nPlease ensure that the organization and hostname are correct and that your API token for %s is valid.","messagePattern":"organization %q at host (.+?) not found\\.\n\nPlease ensure that the organization and hostname are correct and that your API token for (.+?) is valid\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend.go","lineNumber":371,"sourceCode":"\t\t\t\t\t\t`HCP Terraform or Terraform Enterprise client: %s.`, err,\n\t\t\t\t),\n\t\t\t))\n\t\t\treturn diags\n\t\t}\n\t}\n\n\t// Read the app name header and if empty, provide a default\n\tb.appName = b.client.AppName()\n\t// Validate the header's value to ensure no tampering\n\tif !isValidAppName(b.appName) {\n\t\tb.appName = \"HCP Terraform\"\n\t}\n\n\t// Check if the organization exists by reading its entitlements.\n\tentitlements, err := b.client.Organizations.ReadEntitlements(context.Background(), b.Organization)\n\tif err != nil {\n\t\tif err == tfe.ErrResourceNotFound {\n\t\t\terr = fmt.Errorf(\"organization %q at host %s not found.\\n\\n\"+\n\t\t\t\t\"Please ensure that the organization and hostname are correct \"+\n\t\t\t\t\"and that your API token for %s is valid.\",\n\t\t\t\tb.Organization, b.Hostname, b.Hostname)\n\t\t}\n\t\tdiags = diags.Append(tfdiags.AttributeValue(\n\t\t\ttfdiags.Error,\n\t\t\tfmt.Sprintf(\"Failed to read organization %q at host %s\", b.Organization, b.Hostname),\n\t\t\tfmt.Sprintf(\"Encountered an unexpected error while reading the \"+\n\t\t\t\t\"organization settings: %s\", err),\n\t\t\tcty.Path{cty.GetAttrStep{Name: \"organization\"}},\n\t\t))\n\t\treturn diags\n\t}\n\n\t// If TF_WORKSPACE specifies a current workspace to use, make sure it's usable.\n\tif ws, ok := os.LookupEnv(\"TF_WORKSPACE\"); ok {\n\t\tif ws == b.WorkspaceMapping.Name || b.WorkspaceMapping.IsTagsStrategy() {\n\t\t\tdiag := b.validWorkspaceEnvVar(context.Background(), b.Organization, ws)","sourceCodeStart":353,"sourceCodeEnd":389,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend.go#L353-L389","documentation":"During cloud backend Configure, Terraform reads the organization's entitlements to verify the organization exists and determine its feature set. If the API returns tfe.ErrResourceNotFound (HTTP 404), the error is enhanced with guidance about verifying the organization name, hostname, and API token validity. This combined error is surfaced as a diagnostic on the 'organization' attribute.","triggerScenarios":"Calling b.client.Organizations.ReadEntitlements at backend.go:368 returns tfe.ErrResourceNotFound. This means the HCP Terraform / TFE API responded with 404 for the given organization name, which can mean the org doesn't exist, the name is misspelled, or the token lacks access (HCP Terraform returns 404 for both non-existent and unauthorized resources).","commonSituations":"Typo in the organization name in the cloud block or TF_CLOUD_ORGANIZATION env var. The API token belongs to a different organization or has been revoked. Using a token for app.terraform.io against a self-hosted TFE instance or vice versa. The organization was renamed or deleted.","solutions":["Verify the organization name is spelled correctly in your cloud block or TF_CLOUD_ORGANIZATION.","Check that your API token is valid and has access to the organization: `curl -H \"Authorization: Bearer $TOKEN\" https://<hostname>/api/v2/organizations/<org>`.","Ensure the hostname matches the token's origin (HCP vs self-hosted TFE).","Re-run `terraform login <hostname>` to refresh the token if it has expired."],"exampleFix":"# before — wrong org name or missing token\nterraform {\n  cloud {\n    organization = \"MyOrg\"\n  }\n}\n\n# after — verify and correct\nterraform {\n  cloud {\n    organization = \"my-correct-org\"\n  }\n}\n# Then run: terraform login app.terraform.io","handlingStrategy":"validation","validationCode":"// Before Configure, verify the organization exists\ncurl -sS -o /dev/null -w '%{http_code}' \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  https://<hostname>/api/v2/organizations/<org>\n# Expected: 200. If 404, the org name or token is wrong.","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Verify the organization name matches exactly (case-sensitive) what is in HCP Terraform / TFE.","Run `terraform login <hostname>` to ensure a valid, current token is stored.","Double-check TF_CLOUD_ORGANIZATION env var if not using a cloud block.","Ensure the token has organization-level read access, not just workspace access."],"tags":["terraform","cloud-backend","organization","authentication","tfe-api","go"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}