hashicorp/terraform · error
Failed to request password
Error message
Failed to request password: %s
What it means
Sibling of error 637: the password prompt (c.UIInput().Input with Secret:true) returned an error during the password-grant login flow. The cause is environmental (no/failed TTY, cancelled input), not credential validation; credential validation happens later against the OAuth token endpoint.
Solutions
- Supply the token via `TF_TOKEN_<hostname>` env var or the credentials file instead of interactive login.
- Run login in a TTY-capable terminal.
- Use the token-based login path (paste a token) or the browser OAuth flow instead of username/password.
- Verify the terminal supports secret input and is not redirected.
Example fix
# before: terraform login in a non-TTY shell -> 'Failed to request password' # after: skip the prompt entirely export TF_TOKEN_app_terraform_io="<token>" terraform init
Defensive patterns
Strategy: validation
Validate before calling
if !canPrompt() { // see error 637's canPrompt()
return errors.New("no TTY: provide credentials via TF_TOKEN_<hostname> or the credentials file")
} Try / catch
password, err := c.UIInput().Input(ctx, opts)
if err != nil {
if !canPrompt() {
return fmt.Errorf("password prompt needs a TTY; set TF_TOKEN_%s instead: %w", hostname, err)
}
return err
} Prevention
- Avoid username/password login in automation; prefer token env vars or OAuth.
- Ensure stdin is a real TTY when interactive login is unavoidable.
- Surface a clear 'no TTY' message instead of letting UIInput fail opaquely.
When it happens
Trigger: Non-interactive runtime without a TTY; the password prompt was cancelled or EOF'd; a custom UIInput backend failed specifically on the secret prompt.
Common situations: CI/container runs of `terraform login`; stdin closed or piped; user aborted at the password prompt; terminal that cannot read hidden input.
Related errors
- Failed to request username
- Failed to retrieve token
- Couldn't create initial workspace
- couldn't read information for cloud run
- couldn't read plan data for cloud run
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/2fcef9e0ae710461.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/login.go:561
c.Ui.Output("\n---------------------------------------------------------------------------------\n")
c.Ui.Output("Terraform must temporarily use your password to request an API token.\nThis password will NOT be saved locally.\n")
username, err := c.UIInput().Input(context.Background(), &terraform.InputOpts{
Id: "username",
Query: fmt.Sprintf("Username for %s:", hostname.ForDisplay()),
})
if err != nil {
diags = diags.Append(fmt.Errorf("Failed to request username: %s", err))
return nil, diags
}
password, err := c.UIInput().Input(context.Background(), &terraform.InputOpts{
Id: "password",
Query: fmt.Sprintf("Password for %s:", hostname.ForDisplay()),
Secret: true,
})
if err != nil {
diags = diags.Append(fmt.Errorf("Failed to request password: %s", err))
return nil, diags
}
oauthConfig := &oauth2.Config{
ClientID: clientConfig.ID,
Endpoint: clientConfig.Endpoint(),
Scopes: clientConfig.Scopes,
}
token, err := oauthConfig.PasswordCredentialsToken(context.Background(), username, password)
if err != nil {
// FIXME: The OAuth2 library generates errors that are not appropriate
// for a Terraform end-user audience, so once we have more experience
// with which errors are most common we should try to recognize them
// here and produce better error messages for them.
diags = diags.Append(tfdiags.Sourceless(
tfdiags.Error,
"Failed to retrieve API token",
fmt.Sprintf("The remote host did not issue an API token: %s.", err),View on GitHub (pinned to d32a084675)