{"record":{"id":"e35821f17e0249af","repo":"hashicorp/terraform","slug":"http-remote-state-endpoint-requires-auth","errorCode":null,"errorMessage":"HTTP remote state endpoint requires auth","messagePattern":"HTTP remote state endpoint requires auth","errorType":"http","errorClass":null,"httpStatus":401,"severity":"error","filePath":"internal/backend/remote-state/http/client.go","lineNumber":99,"sourceCode":"\tif c.LockURL == nil {\n\t\treturn \"\", nil\n\t}\n\tc.lockID = \"\"\n\n\tjsonLockInfo := info.Marshal()\n\tresp, err := c.httpRequest(c.LockMethod, c.LockURL, &jsonLockInfo, \"lock\")\n\tif err != nil {\n\t\treturn \"\", err\n\t}\n\tdefer resp.Body.Close()\n\n\tswitch resp.StatusCode {\n\tcase http.StatusOK:\n\t\tc.lockID = info.ID\n\t\tc.jsonLockInfo = jsonLockInfo\n\t\treturn info.ID, nil\n\tcase http.StatusUnauthorized:\n\t\treturn \"\", fmt.Errorf(\"HTTP remote state endpoint requires auth\")\n\tcase http.StatusForbidden:\n\t\treturn \"\", fmt.Errorf(\"HTTP remote state endpoint invalid auth\")\n\tcase http.StatusConflict, http.StatusLocked:\n\t\tdefer resp.Body.Close()\n\t\tbody, err := io.ReadAll(resp.Body)\n\t\tif err != nil {\n\t\t\treturn \"\", &statemgr.LockError{\n\t\t\t\tErr: fmt.Errorf(\"HTTP remote state already locked, failed to read body\"),\n\t\t\t}\n\t\t}\n\t\texisting := statemgr.LockInfo{}\n\t\terr = json.Unmarshal(body, &existing)\n\t\tif err != nil {\n\t\t\treturn \"\", &statemgr.LockError{\n\t\t\t\tErr: fmt.Errorf(\"HTTP remote state already locked, failed to unmarshal body\"),\n\t\t\t}\n\t\t}\n\t\treturn \"\", &statemgr.LockError{","sourceCodeStart":81,"sourceCodeEnd":117,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/client.go#L81-L117","documentation":"The lock request returned HTTP 401 Unauthorized. The server requires authentication but none was sent, or the credentials were not recognized as auth at all. Credentials come from username/password attributes or TF_HTTP_USERNAME/TF_HTTP_PASSWORD and are sent as HTTP Basic auth (req.SetBasicAuth).","triggerScenarios":"Lock request to a server requiring basic auth while username/password are empty, or the server's auth config rejects the provided pair with a 401 (rather than 403).","commonSituations":"Forgot to set username/password; TF_HTTP_USERNAME/TF_HTTP_PASSWORD not exported in the current shell/CI; server recently had auth enabled; credentials rotated but Terraform config not updated.","solutions":["Set username and password (or export TF_HTTP_USERNAME and TF_HTTP_PASSWORD) to valid server credentials.","Confirm the credentials work with: curl -u \"$TF_HTTP_USERNAME:$TF_HTTP_PASSWORD\" -i <lock_address>.","Re-export the env vars in the same shell/CI step that runs terraform."],"exampleFix":"// before (no creds)\naddress = \"https://state.example.com/terraform\"\n// after\naddress  = \"https://state.example.com/terraform\"\nusername = var.state_user\npassword = var.state_pass","handlingStrategy":"validation","validationCode":"# Pre-flight: confirm basic auth is accepted by the endpoint\ncurl -fsS -u \"$TF_HTTP_USERNAME:$TF_HTTP_PASSWORD\" -o /dev/null -w 'http=%{http_code}\\n' \"$TF_HTTP_ADDRESS\" \\\n  || { echo 'ERROR: endpoint requires auth or rejected creds'; exit 1; }","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always set username/password (or TF_HTTP_USERNAME/TF_HTTP_PASSWORD) when the endpoint requires auth.","Export the env vars in the exact shell/CI step that runs terraform.","Probe the endpoint with curl -u before terraform init."],"tags":["auth","http","lock","http-backend","credentials"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}