{"record":{"id":"99081519cd6f10f6","repo":"hashicorp/terraform","slug":"workspace-s-not-found-for-security-s-returns","errorCode":null,"errorMessage":"workspace %s not found\n\nFor security, %s returns '404 Not Found' responses for resources\nfor resources that a user doesn't have access to, in addition to resources that\ndo not exist. If the resource does exist, please check the permissions of the provided token.","messagePattern":"workspace (.+?) not found\n\nFor security, (.+?) returns '404 Not Found' responses for resources\nfor resources that a user doesn't have access to, in addition to resources that\ndo not exist\\. If the resource does exist, please check the permissions of the provided token\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend.go","lineNumber":1336,"sourceCode":"\thostname         string\n\torganization     string\n\ttoken            string\n\tworkspaceMapping WorkspaceMapping\n}\n\nfunc isLocalExecutionMode(execMode string) bool {\n\treturn execMode == \"local\"\n}\n\nfunc (b *Cloud) fetchWorkspace(ctx context.Context, organization string, workspace string) (*tfe.Workspace, error) {\n\t// Retrieve the workspace for this operation.\n\tw, err := b.client.Workspaces.Read(ctx, organization, workspace)\n\tif err != nil {\n\t\tswitch err {\n\t\tcase context.Canceled:\n\t\t\treturn nil, err\n\t\tcase tfe.ErrResourceNotFound:\n\t\t\treturn nil, fmt.Errorf(\n\t\t\t\t\"workspace %s not found\\n\\n\"+\n\t\t\t\t\tfmt.Sprintf(\"For security, %s returns '404 Not Found' responses for resources\\n\", b.appName)+\n\t\t\t\t\t\"for resources that a user doesn't have access to, in addition to resources that\\n\"+\n\t\t\t\t\t\"do not exist. If the resource does exist, please check the permissions of the provided token.\",\n\t\t\t\tworkspace,\n\t\t\t)\n\t\tdefault:\n\t\t\terr := fmt.Errorf(\n\t\t\t\t\"%s returned an unexpected error:\\n\\n%s\",\n\t\t\t\tb.appName,\n\t\t\t\terr,\n\t\t\t)\n\t\t\treturn nil, err\n\t\t}\n\t}\n\n\treturn w, nil\n}","sourceCodeStart":1318,"sourceCodeEnd":1354,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend.go#L1318-L1354","documentation":"fetchWorkspace converts tfe.ErrResourceNotFound from Workspaces.Read into a human-facing message. The message deliberately conflates 'does not exist' with 'exists but forbidden', because TFE/HCP returns 404 for both to avoid leaking resource existence. The workspace name and a permissions hint are included.","triggerScenarios":"b.client.Workspaces.Read(ctx, organization, workspace) returns tfe.ErrResourceNotFound: workspace truly missing in the org; org name misspelled; token has no access and the API masks it as 404; TF_WORKSPACE/`terraform workspace select` resolves to a name that does not exist.","commonSituations":"Wrong workspace name in cloud block; TF_WORKSPACE env var set to a non-existent workspace; token belongs to a different team with no membership on the workspace; copy-paste error in organization name.","solutions":["Verify the workspace name spelling and that it exists in the configured organization via the TFE/HCP UI.","Confirm TF_WORKSPACE is unset or points at an existing workspace.","Check that the API token's team has at least read access on the workspace (404 is returned even when access is the problem).","Verify the `hostname` and `organization` fields in the cloud block."],"exampleFix":"# before\nexport TF_WORKSPACE=Prod-Env\n\n# after\nexport TF_WORKSPACE=prod-env   # matches actual workspace name","handlingStrategy":"validation","validationCode":"func workspaceExists(client *tfe.Client, org, ws string) error {\n    if _, err := client.Workspaces.Read(ctx, org, ws); err != nil {\n        if err == tfe.ErrResourceNotFound {\n            return fmt.Errorf(\"workspace %s/%s missing or inaccessible\", org, ws)\n        }\n        return err\n    }\n    return nil\n}\n// call during `terraform init` preflight","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Preflight-check the workspace name with Workspaces.Read before runs.","Unset TF_WORKSPACE unless you intentionally pin it.","Confirm the token's team has read access on the workspace.","Double-check organization and hostname spelling."],"tags":["tfe","hcp","cloud-backend","workspace","not-found","permissions"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}