{"record":{"id":"c331f275c6caeefc","repo":"rust-lang/cargo","slug":"no-credential-providers-could-handle-the-request","errorCode":null,"errorMessage":"no credential providers could handle the request","messagePattern":"no credential providers could handle the request","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/util/auth/mod.rs","lineNumber":494,"sourceCode":"        })?;\n        match provider.perform(&registry, &action, &args[1..]) {\n            Ok(response) => return Ok(response),\n            Err(cargo_credential::Error::UrlNotSupported) => {}\n            Err(cargo_credential::Error::NotFound) => any_not_found = true,\n            e => {\n                return e.with_context(|| {\n                    format!(\n                        \"credential provider `{}` failed action `{action}`\",\n                        args.join(\" \")\n                    )\n                });\n            }\n        }\n    }\n    if any_not_found {\n        Err(cargo_credential::Error::NotFound.into())\n    } else {\n        anyhow::bail!(\"no credential providers could handle the request\")\n    }\n}\n\n/// Returns the token to use for the given registry.\n/// If a `login_url` is provided and a token is not available, the\n/// `login_url` will be included in the returned error.\npub fn auth_token(\n    gctx: &GlobalContext,\n    sid: &SourceId,\n    login_url: Option<&Url>,\n    operation: Operation<'_>,\n    headers: Vec<String>,\n    require_cred_provider_config: bool,\n) -> CargoResult<String> {\n    match auth_token_optional(gctx, sid, operation, headers, require_cred_provider_config)? {\n        Some(token) => Ok(token.expose()),\n        None => Err(AuthorizationError::new(\n            gctx,","sourceCodeStart":476,"sourceCodeEnd":512,"githubUrl":"https://github.com/rust-lang/cargo/blob/98a09e7e7d62850f14e5b6132101fc1edd19a16f/src/util/auth/mod.rs#L476-L512","documentation":"Cargo iterates every configured credential provider for a registry (cargo:token, cargo:paseto, wincred, macos-keychain, libsecret, or an external credential-process). Each provider returns either UrlNotSupported (skipped) or NotFound. This bail fires only when no provider reported it could handle the registry URL and none reported NotFound, meaning the request shape is recognized but unmatched by any provider's URL pattern.","triggerScenarios":"Calling auth_token()/auth() against a private/alternate registry whose configured credential provider does not claim the registry's index URL, or invoking a registry operation (publish, yank, fetch) when no credential provider is configured for that registry at all.","commonSituations":"Missing [registry] table / registry-<name> entry in .cargo/config.toml; credential-process configured for a different URL than the registry index; credential provider returns UrlNotSupported for a self-hosted/Artifactory/GitLab registry; CARGO_REGISTRY_<name>_TOKEN unset and no provider listed.","solutions":["Configure a credential provider for the registry in .cargo/config.toml: [registry.my-registry] with a credential-provider entry, or set CARGO_REGISTRY_MY-REGISTRY_TOKEN.","Run `cargo login --registry <name>` to store a token via cargo:token.","Verify the credential provider's accepted URL pattern matches the registry index URL printed by Cargo.","If using a custom credential-process, test it with the registry URL in isolation and confirm it does not emit UrlNotSupported."],"exampleFix":"// before: no provider configured, private registry publish fails\n// .cargo/config.toml is empty\n\n// after: .cargo/config.toml\n// [registry.my-registry]\n// credential-provider = \"cargo:token\"\n// then: cargo login --registry my-registry","handlingStrategy":"validation","validationCode":"use cargo::util::auth;\n\nfn registry_has_provider(gctx: &GlobalContext, sid: &SourceId) -> bool {\n    auth::credential_provider(gctx, sid, /*require=*/false, /*check_config=*/true)\n        .map(|v| !v.is_empty())\n        .unwrap_or(false)\n}\n\n// call before publish/fetch on a private registry:\n// if !registry_has_provider(gctx, sid) { eprintln!(\"configure a credential provider first\"); }","typeGuard":null,"tryCatchPattern":"// Rust: these bail as anyhow::Error; surface a user hint.\nmatch auth::auth(gctx, sid, /*...*/) {\n    Ok(resp) => { /* use resp */ }\n    Err(e) if e.to_string().contains(\"no credential providers\") => {\n        eprintln!(\"No credential provider matched registry {}. Add a [registry.<name>] credential-provider or set CARGO_REGISTRY_<NAME>_TOKEN.\", sid.url());\n        return Err(e);\n    }\n    Err(e) => return Err(e),\n}","preventionTips":["Always configure a credential-provider entry for private registries in .cargo/config.toml.","Run `cargo login --registry <name>` once per machine/user before first publish.","In CI, inject tokens via documented CARGO_REGISTRY_<NAME>_TOKEN env vars rather than relying on default providers."],"tags":["auth","credentials","registry","configuration"],"backgroundTag":null,"analyzedSha":"98a09e7e7d62850f14e5b6132101fc1edd19a16f","analyzedAt":"2026-08-11T17:42:36.556Z","contentChangedAt":"2026-08-11T17:42:36.556Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}