hashicorp/terraform · error

Failed to request password

Error message

Failed to request password: %s

What it means

Sibling of error 637: the password prompt (c.UIInput().Input with Secret:true) returned an error during the password-grant login flow. The cause is environmental (no/failed TTY, cancelled input), not credential validation; credential validation happens later against the OAuth token endpoint.

Solutions

  1. Supply the token via `TF_TOKEN_<hostname>` env var or the credentials file instead of interactive login.
  2. Run login in a TTY-capable terminal.
  3. Use the token-based login path (paste a token) or the browser OAuth flow instead of username/password.
  4. Verify the terminal supports secret input and is not redirected.

Example fix

# before: terraform login in a non-TTY shell -> 'Failed to request password'

# after: skip the prompt entirely
export TF_TOKEN_app_terraform_io="<token>"
terraform init
Defensive patterns

Strategy: validation

Validate before calling

if !canPrompt() { // see error 637's canPrompt()
    return errors.New("no TTY: provide credentials via TF_TOKEN_<hostname> or the credentials file")
}

Try / catch

password, err := c.UIInput().Input(ctx, opts)
if err != nil {
    if !canPrompt() {
        return fmt.Errorf("password prompt needs a TTY; set TF_TOKEN_%s instead: %w", hostname, err)
    }
    return err
}

Prevention

When it happens

Trigger: Non-interactive runtime without a TTY; the password prompt was cancelled or EOF'd; a custom UIInput backend failed specifically on the secret prompt.

Common situations: CI/container runs of `terraform login`; stdin closed or piped; user aborted at the password prompt; terminal that cannot read hidden input.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/2fcef9e0ae710461. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/login.go:561

	c.Ui.Output("\n---------------------------------------------------------------------------------\n")
	c.Ui.Output("Terraform must temporarily use your password to request an API token.\nThis password will NOT be saved locally.\n")

	username, err := c.UIInput().Input(context.Background(), &terraform.InputOpts{
		Id:    "username",
		Query: fmt.Sprintf("Username for %s:", hostname.ForDisplay()),
	})
	if err != nil {
		diags = diags.Append(fmt.Errorf("Failed to request username: %s", err))
		return nil, diags
	}
	password, err := c.UIInput().Input(context.Background(), &terraform.InputOpts{
		Id:     "password",
		Query:  fmt.Sprintf("Password for %s:", hostname.ForDisplay()),
		Secret: true,
	})
	if err != nil {
		diags = diags.Append(fmt.Errorf("Failed to request password: %s", err))
		return nil, diags
	}

	oauthConfig := &oauth2.Config{
		ClientID: clientConfig.ID,
		Endpoint: clientConfig.Endpoint(),
		Scopes:   clientConfig.Scopes,
	}
	token, err := oauthConfig.PasswordCredentialsToken(context.Background(), username, password)
	if err != nil {
		// FIXME: The OAuth2 library generates errors that are not appropriate
		// for a Terraform end-user audience, so once we have more experience
		// with which errors are most common we should try to recognize them
		// here and produce better error messages for them.
		diags = diags.Append(tfdiags.Sourceless(
			tfdiags.Error,
			"Failed to retrieve API token",
			fmt.Sprintf("The remote host did not issue an API token: %s.", err),

View on GitHub (pinned to d32a084675)