{"record":{"id":"9c2112e0334f54b0","repo":"hashicorp/terraform","slug":"failed-to-retrieve-token-s","errorCode":null,"errorMessage":"Failed to retrieve token: %s","messagePattern":"Failed to retrieve token: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/login.go","lineNumber":644,"sourceCode":"\n\t// credsCtx might not be set if we're using a mock credentials source\n\t// in a test, but it should always be set in normal use.\n\tif credsCtx != nil {\n\t\tswitch credsCtx.Location {\n\t\tcase cliconfig.CredentialsViaHelper:\n\t\t\tc.Ui.Output(fmt.Sprintf(\"Terraform will store the token in the configured %q credentials helper\\nfor use by subsequent commands.\\n\", credsCtx.HelperType))\n\t\tcase cliconfig.CredentialsInPrimaryFile, cliconfig.CredentialsNotAvailable:\n\t\t\tc.Ui.Output(fmt.Sprintf(\"Terraform will store the token in plain text in the following file\\nfor use by subsequent commands:\\n    %s\\n\", credsCtx.LocalFilename))\n\t\t}\n\t}\n\n\ttoken, err := c.UIInput().Input(context.Background(), &terraform.InputOpts{\n\t\tId:     \"token\",\n\t\tQuery:  fmt.Sprintf(\"Token for %s:\", hostname.ForDisplay()),\n\t\tSecret: true,\n\t})\n\tif err != nil {\n\t\tdiags := diags.Append(fmt.Errorf(\"Failed to retrieve token: %s\", err))\n\t\treturn \"\", diags\n\t}\n\n\ttoken = strings.TrimSpace(token)\n\tcfg := &tfe.Config{\n\t\tAddress:  service.String(),\n\t\tBasePath: service.Path,\n\t\tToken:    token,\n\t\tHeaders:  make(http.Header),\n\t}\n\tclient, err := tfe.NewClient(cfg)\n\tif err != nil {\n\t\tdiags = diags.Append(fmt.Errorf(\"Failed to create API client: %s\", err))\n\t\treturn \"\", diags\n\t}\n\tuser, err := client.Users.ReadCurrent(context.Background())\n\tif err == tfe.ErrUnauthorized {\n\t\tdiags = diags.Append(fmt.Errorf(\"Token is invalid: %s\", err))","sourceCodeStart":626,"sourceCodeEnd":662,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/login.go#L626-L662","documentation":"Thrown by the manual-token branch of login.go when c.UIInput().Input fails for the token prompt. This is the path where the user pastes a token (as opposed to the OAuth/password flows); the error means the prompt to read the token could not complete, not that the token is invalid. Token validity is checked afterwards via tfe.NewClient.","triggerScenarios":"Non-interactive environment with no TTY; the token prompt was cancelled, empty, or EOF'd; a custom UIInput backend errored on the secret prompt.","commonSituations":"Running `terraform login` in CI/containers; stdin closed or piped; user aborted at the token prompt; automating login where a TTY is unavailable.","solutions":["Set the token directly via `TF_TOKEN_<hostname>` env var or write it to ~/.terraform.d/credentials.tfrc.json.","Run `terraform login` in a real terminal so the prompt can be read.","Use the browser OAuth flow instead of manual token entry.","Ensure stdin is an interactive TTY when manual entry is required."],"exampleFix":"# before: terraform login (token path) with no TTY -> 'Failed to retrieve token'\n\n# after: write the credentials file directly\ncat > ~/.terraform.d/credentials.tfrc.json <<EOF\n{ \"credentials\": { \"app.terraform.io\": { \"token\": \"<token>\" } } }\nEOF\nterraform init","handlingStrategy":"validation","validationCode":"if !canPrompt() { // see error 637's canPrompt()\n    return errors.New(\"no TTY: set TF_TOKEN_<hostname> or write ~/.terraform.d/credentials.tfrc.json\")\n}","typeGuard":null,"tryCatchPattern":"token, err := c.UIInput().Input(ctx, opts)\nif err != nil {\n    if !canPrompt() {\n        return fmt.Errorf(\"token prompt needs a TTY; set TF_TOKEN_%s or use the OAuth flow: %w\", hostname, err)\n    }\n    return err\n}","preventionTips":["Provide the token via TF_TOKEN_<hostname> or the credentials file in non-interactive environments.","Prefer the browser OAuth flow over manual token entry when a TTY is unavailable.","Check for a TTY before invoking `terraform login` in scripts."],"tags":["terraform","login","auth","token","ui-input","tty","interactive"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}