hashicorp/terraform · error

failed to determine request credentials

Error message

failed to determine request credentials: %s

What it means

During request building, the mirror client calls `mirrorHostCredentials()` to attach host credentials. If that lookup itself errors (see 895: invalid base URL, or the credentials source fails for the host), the error is wrapped with this prefix.

Solutions

  1. Fix the mirror base URL so `mirrorHost` succeeds.
  2. Verify credentials configuration for the mirror hostname in the CLI config / credentials helper.
  3. Run `terraform providers mirror` or a manual `curl` with the same creds to isolate auth vs URL issues.
  4. Remove the credentials block temporarily to see if the URL itself is the problem.

Example fix

// before: creds block references unknown host
credentials "mirror.local" { token = "..." } // but url is https://other.local/
// after: align URL and creds
provider_installation {
  network_mirror { url = "https://mirror.local/" }
}
credentials "mirror.local" { token = "..." }
Defensive patterns

Strategy: validation

Validate before calling

// Pre-flight: confirm creds resolve before the request loop
if creds, err := s.mirrorHostCredentials(); err != nil {
    return fmt.Errorf("mirror credentials unavailable: %w", err)
} else if creds == nil {
    log.Printf("[INFO] no mirror credentials configured; proceeding anonymous")
}

Try / catch

creds, err := s.mirrorHostCredentials()
if err != nil {
    // retry without creds as anonymous fallback
    log.Printf("[WARN] mirror creds failed (%s); retrying anonymous", err)
    creds = nil
}

Prevention

When it happens

Trigger: `s.mirrorHostCredentials()` returns an error inside the GET helper; wrapped at http_mirror_source.go:341.

Common situations: Same root causes as 895 (bad base URL) plus: the configured credentials source for the mirror hostname fails (bad token, unreachable `cli_credentials_host`); credentials helper plugin error.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/5280b0fed5c7b060. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/http_mirror_source.go:341

// produced the returned response, possibly after following some redirects.
func (s *HTTPMirrorSource) get(ctx context.Context, relativePath string) (statusCode int, body io.ReadCloser, finalURL *url.URL, error error) {
	endpointPath, err := url.Parse(relativePath)
	if err != nil {
		// Should never happen because the caller should validate all of the
		// components it's including in the path.
		return 0, nil, nil, err
	}
	endpointURL := s.baseURL.ResolveReference(endpointPath)

	req, err := retryablehttp.NewRequest("GET", endpointURL.String(), nil)
	if err != nil {
		return 0, nil, endpointURL, err
	}
	req = req.WithContext(ctx)
	req.Request.Header.Set(terraformVersionHeader, version.String())
	creds, err := s.mirrorHostCredentials()
	if err != nil {
		return 0, nil, endpointURL, fmt.Errorf("failed to determine request credentials: %s", err)
	}
	if creds != nil {
		// Note that if the initial requests gets redirected elsewhere
		// then the credentials will still be included in the new request,
		// even if they are on a different hostname. This is intentional
		// and consistent with how we handle credentials for other
		// Terraform-native services, because the user model is to configure
		// credentials for the "friendly hostname" they configured, not for
		// whatever hostname ends up ultimately serving the request as an
		// implementation detail.
		creds.PrepareRequest(req.Request)
	}

	resp, err := s.httpClient.Do(req)
	if err != nil {
		return 0, nil, endpointURL, err
	}
	defer func() {

View on GitHub (pinned to d32a084675)