{"record":{"id":"b38cac87adc1faac","repo":"hashicorp/terraform","slug":"the-string-provided-in-credentials-is-neither-vali","errorCode":null,"errorMessage":"the string provided in credentials is neither valid json nor a valid file path","messagePattern":"the string provided in credentials is neither valid json nor a valid file path","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/gcs/backend.go","lineNumber":204,"sourceCode":"\t} else {\n\t\tcreds = os.Getenv(\"GOOGLE_CREDENTIALS\")\n\t}\n\n\tif tokenSource != nil {\n\t\tcredOptions = append(credOptions, option.WithTokenSource(tokenSource))\n\t} else if creds != \"\" {\n\n\t\t// to mirror how the provider works, we accept the file path or the contents\n\t\tcontents, err := readPathOrContents(creds)\n\t\tif err != nil {\n\t\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\t\tfmt.Errorf(\"Error loading credentials: %s\", err),\n\t\t\t)\n\t\t}\n\n\t\tif !json.Valid([]byte(contents)) {\n\t\t\treturn backendbase.ErrorAsDiagnostics(\n\t\t\t\tfmt.Errorf(\"the string provided in credentials is neither valid json nor a valid file path\"),\n\t\t\t)\n\t\t}\n\n\t\tcredOptions = append(credOptions, option.WithCredentialsJSON([]byte(contents)))\n\t}\n\n\t// Service Account Impersonation\n\tif v := data.String(\"impersonate_service_account\"); v != \"\" {\n\t\tServiceAccount := v\n\t\tvar delegates []string\n\n\t\tdelegatesVal := data.GetAttr(\"impersonate_service_account_delegates\", cty.List(cty.String))\n\t\tif !delegatesVal.IsNull() && delegatesVal.LengthInt() != 0 {\n\t\t\tdelegates = make([]string, 0, delegatesVal.LengthInt())\n\t\t\tfor it := delegatesVal.ElementIterator(); it.Next(); {\n\t\t\t\t_, v := it.Element()\n\t\t\t\tif v.IsNull() {\n\t\t\t\t\treturn backendbase.ErrorAsDiagnostics(","sourceCodeStart":186,"sourceCodeEnd":222,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/gcs/backend.go#L186-L222","documentation":"Thrown when the credentials string was read successfully (either as a file's contents or as literal text) but the result is not valid JSON. The backend mirrors the provider behavior of accepting either a file path or inline JSON, and after reading it validates with json.Valid before handing it to option.WithCredentialsJSON.","triggerScenarios":"readPathOrContents returns content that fails json.Valid — e.g., the file is not a service-account key, contains trailing garbage, was truncated, or the 'path' was actually a JSON blob missing braces.","commonSituations":"User pastes a key ID or project ID instead of the full JSON key; the JSON file has a BOM or stray newline outside the object; the value is a base64-encoded credential instead of raw JSON.","solutions":["Open the credentials content and run it through a JSON linter to locate the syntax error.","Re-download the service-account JSON key from the GCP console (IAM & Admin > Service accounts > Keys).","Ensure the file contains a single JSON object starting with '{' and ending with '}'.","Confirm you are not accidentally providing an OAuth token or API key string."],"exampleFix":"// before\nexport GOOGLE_CREDENTIALS='{ \"type\": \"service_account\" ... (truncated) }'\n// after — re-export the complete key\ngcloud iam service-accounts keys create sa.json --iam-account=terraform@proj.iam.gserviceaccount.com\nexport GOOGLE_CREDENTIALS=$(cat sa.json)","handlingStrategy":"validation","validationCode":"contents, err := readPathOrContents(creds)\nif err != nil { return err }\nif !json.Valid([]byte(contents)) {\n    return fmt.Errorf(\"credentials content failed json.Valid; re-download the service-account key\")\n}","typeGuard":"func isServiceAccountJSON(s string) bool {\n    if !json.Valid([]byte(s)) { return false }\n    var m map[string]interface{}\n    _ = json.Unmarshal([]byte(s), &m)\n    return m[\"type\"] == \"service_account\" && m[\"private_key\"] != nil\n}","tryCatchPattern":null,"preventionTips":["Re-download keys from the GCP console rather than hand-editing.","Validate the key with `jq . service-account.json` before exporting it.","Never paste partial JSON; always the complete object."],"tags":["gcs","backend","credentials","authentication","json","configuration"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}