{"record":{"id":"f5d8fee9ce19385e","repo":"hashicorp/terraform","slug":"the-credentials-q-block-has-an-invalid-hostname","errorCode":null,"errorMessage":"The credentials %q block has an invalid hostname: %s","messagePattern":"The credentials %q block has an invalid hostname: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/cliconfig/cliconfig.go","lineNumber":308,"sourceCode":"\t// to give proper source references to any errors. We should improve\n\t// on this when we change the CLI config parser to use HCL2.\n\n\t// Check that all \"host\" blocks have valid hostnames.\n\tfor givenHost := range c.Hosts {\n\t\t_, err := svchost.ForComparison(givenHost)\n\t\tif err != nil {\n\t\t\tdiags = diags.Append(\n\t\t\t\tfmt.Errorf(\"The host %q block has an invalid hostname: %s\", givenHost, err),\n\t\t\t)\n\t\t}\n\t}\n\n\t// Check that all \"credentials\" blocks have valid hostnames.\n\tfor givenHost := range c.Credentials {\n\t\t_, err := svchost.ForComparison(givenHost)\n\t\tif err != nil {\n\t\t\tdiags = diags.Append(\n\t\t\t\tfmt.Errorf(\"The credentials %q block has an invalid hostname: %s\", givenHost, err),\n\t\t\t)\n\t\t}\n\t}\n\n\t// Should have zero or one \"credentials_helper\" blocks\n\tif len(c.CredentialsHelpers) > 1 {\n\t\tdiags = diags.Append(\n\t\t\tfmt.Errorf(\"No more than one credentials_helper block may be specified\"),\n\t\t)\n\t}\n\n\t// Should have zero or one \"provider_installation\" blocks\n\tif len(c.ProviderInstallation) > 1 {\n\t\tdiags = diags.Append(\n\t\t\tfmt.Errorf(\"No more than one provider_installation block may be specified\"),\n\t\t)\n\t}\n","sourceCodeStart":290,"sourceCodeEnd":326,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/cliconfig/cliconfig.go#L290-L326","documentation":"Thrown during CLI config validation when a credentials block contains an invalid hostname. Same validation as host blocks: svchost.ForComparison must succeed for the hostname to be usable for credential matching and API token lookup.","triggerScenarios":"For each key in c.Credentials, svchost.ForComparison(givenHost) returns an error due to invalid hostname format, disallowed characters (underscores, spaces), or empty string.","commonSituations":"Typo in the credentials hostname; using an underscore-based hostname; trailing whitespace from copy-paste; hostname that does not match the actual TFC/E or registry endpoint.","solutions":["Correct the hostname in the credentials block to a valid DNS name","Ensure it matches the actual TFC/E or registry hostname exactly","Remove special characters, underscores, and whitespace"],"exampleFix":"// before\ncredentials \"app.terraform io\" {\n  token = \"atlasv1-xxx\"\n}\n\n// after\ncredentials \"app.terraform.io\" {\n  token = \"atlasv1-xxx\"\n}","handlingStrategy":"validation","validationCode":"// Validate hostname in credentials block before writing config\nfunc validateCredHostname(h string) error {\n    _, err := svchost.ForComparison(h)\n    return err\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use valid DNS hostnames in credentials blocks","Ensure the credentials hostname matches the registry or TFE endpoint exactly","Avoid whitespace and special characters in credential hostnames","Use terraform login to set credentials, which validates the hostname automatically"],"tags":["cli-config","hostname","validation","dns","credentials"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}