{"record":{"id":"ee02c07acbc95a96","repo":"hashicorp/terraform","slug":"failed-to-retrieve-user-account-details-s","errorCode":null,"errorMessage":"Failed to retrieve user account details: %s","messagePattern":"Failed to retrieve user account details: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/login.go","lineNumber":665,"sourceCode":"\n\ttoken = strings.TrimSpace(token)\n\tcfg := &tfe.Config{\n\t\tAddress:  service.String(),\n\t\tBasePath: service.Path,\n\t\tToken:    token,\n\t\tHeaders:  make(http.Header),\n\t}\n\tclient, err := tfe.NewClient(cfg)\n\tif err != nil {\n\t\tdiags = diags.Append(fmt.Errorf(\"Failed to create API client: %s\", err))\n\t\treturn \"\", diags\n\t}\n\tuser, err := client.Users.ReadCurrent(context.Background())\n\tif err == tfe.ErrUnauthorized {\n\t\tdiags = diags.Append(fmt.Errorf(\"Token is invalid: %s\", err))\n\t\treturn \"\", diags\n\t} else if err != nil {\n\t\tdiags = diags.Append(fmt.Errorf(\"Failed to retrieve user account details: %s\", err))\n\t\treturn \"\", diags\n\t}\n\tc.Ui.Output(fmt.Sprintf(c.Colorize().Color(\"\\nRetrieved token for user [bold]%s[reset]\\n\"), user.Username))\n\n\treturn svcauth.HostCredentialsToken(token), nil\n}\n\nfunc (c *LoginCommand) interactiveContextConsent(hostname svchost.Hostname, grantType disco.OAuthGrantType, credsCtx *loginCredentialsContext) (bool, tfdiags.Diagnostics) {\n\tvar diags tfdiags.Diagnostics\n\tmechanism := \"OAuth\"\n\tif grantType == \"\" {\n\t\tmechanism = \"your browser\"\n\t}\n\n\tc.Ui.Output(fmt.Sprintf(\"Terraform will request an API token for %s using %s.\\n\", hostname.ForDisplay(), mechanism))\n\n\tif grantType.UsesAuthorizationEndpoint() {\n\t\tc.Ui.Output(","sourceCodeStart":647,"sourceCodeEnd":683,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/login.go#L647-L683","documentation":"Thrown during `terraform login` when `client.Users.ReadCurrent` returns an error that is NOT `tfe.ErrUnauthorized` — i.e. any other failure reaching or reading from the HCP Terraform / TFE user-account endpoint. The token itself may or may not be valid; the request could not be completed for an unrelated transport, server, or parsing reason.","triggerScenarios":"`GET /api/v2/account/details` fails with a network error (DNS, TCP, TLS), a 5xx server error, a 429 rate limit, a redirect loop, an unexpected response content-type, or a JSON decode failure inside go-tfe. Any of these fall through to the `else if err != nil` branch.","commonSituations":"TFE instance is temporarily down or returning 500s; corporate firewall/proxy blocks `app.terraform.io` or the private TFE host; TLS certificate mismatch or expired cert on a self-hosted TFE; HCP Terraform rate-limiting; transient connectivity blip; go-tfe version mismatch with the server's API contract.","solutions":["Check connectivity: `curl -i -H \"Authorization: Bearer <token>\" https://<hostname>/api/v2/account/details` and inspect the HTTP status.","If a 5xx or 429 is returned, wait and retry `terraform login`.","Resolve TLS issues by setting `SSL_CERT_FILE` or `NODE_EXTRA_CA_CERTS` for private CAs, or updating the system trust store.","Verify proxy settings (`HTTPS_PROXY`, `NO_PROXY`) are correct for your network.","Read the `%s` detail — it typically includes the HTTP status code or transport error."],"exampleFix":"# diagnose the underlying failure\ncurl -v -H \"Authorization: Bearer $TFE_TOKEN\" https://tfe.corp.example.com/api/v2/account/details\n# fix TLS for a private CA\nexport SSL_CERT_FILE=/etc/ssl/certs/corp-ca.pem\nterraform login tfe.corp.example.com","handlingStrategy":"retry","validationCode":"// Pre-flight connectivity check to the account endpoint.\nresp, err := http.Get(\"https://\" + hostname + \"/api/v2/account/details\")\nif err != nil {\n    return fmt.Errorf(\"cannot reach %s: %w; fix network/TLS before login\", hostname, err)\n}\nif resp.StatusCode >= 500 {\n    return fmt.Errorf(\"server error %d from %s; retry later\", resp.StatusCode, hostname)\n}","typeGuard":"null","tryCatchPattern":"// Retry transient (5xx, network) failures; do NOT retry 401 (that's error 641).\nif !errors.Is(err, tfe.ErrUnauthorized) && isTransient(err) {\n    time.Sleep(backoff); retry()\n}","preventionTips":["Set `SSL_CERT_FILE` / `HTTPS_PROXY` correctly for private TFE / corporate networks.","Add a connectivity pre-check in CI before `terraform login`.","Monitor HCP Terraform status page for outages."],"tags":["terraform","login","network","tfe-api","transport"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}