hashicorp/terraform · error
failed to retrieve credentials for
Error message
failed to retrieve credentials for %s: %s
What it means
Returned when RegistrySource.registryClient fails to obtain credentials for a hostname via services.CredentialsForHost. This indicates a credentials *helper* (e.g. terraform-credentials-env, a custom credential helper, or the token store) errored, not that credentials are simply absent. The '%s' suffix carries the helper's own error.
Solutions
- Read the trailing '%s' which contains the helper's native error and address that root cause.
- Re-run 'terraform login <hostname>' to refresh the stored token.
- Inspect ~/.terraform.d/credentials.tfrc.json (or the helper output) for malformed JSON.
- If a custom helper is in use, run it manually with the hostname to reproduce and fix.
- Temporarily unset the credential helper to confirm it is the source of the failure.
Example fix
// before
Error: failed to retrieve credentials for app.terraform.io: helper exited with status 127
// after (ensure helper is on PATH or remove the helper block from ~/.terraformrc)
credentials_helper "atlassian" { args = [] } Defensive patterns
Strategy: try-catch
Try / catch
// Surface the helper's underlying error and degrade gracefully.
_, err := source.PackageMeta(...)
if err != nil && strings.Contains(err.Error(), "failed to retrieve credentials for") {
log.Printf("credential helper issue: %v", err)
// fall back to anonymous registry access or prompt re-login
} Prevention
- Keep credential helper binaries on PATH and tested in CI.
- Validate ~/.terraform.d/credentials.tfrc.json with a JSON linter.
- Periodically re-run 'terraform login' to refresh tokens.
When it happens
Trigger: A credential helper binary exited non-zero or returned malformed output for the given hostname; the cached token in ~/.terraform.d/credentials is corrupt; 'terraform login' stored a token that the helper cannot parse.
Common situations: Custom credential helper misconfigured in CLI config; helper binary not on PATH or crashing; corrupted credentials.tfrc.json; token format changed after a terraform upgrade.
Related errors
- can not get from Terraform backend configuration
- failed to retrieve cryptographic signature for provider
- HTTP remote state endpoint requires auth
- registry response includes invalid protocol string
- registry response includes invalid SHASUMS signature URL…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/0a0ae45e23f8b0ac.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getproviders/registry_source.go:144
case *disco.ErrVersionNotSupported:
return nil, ErrHostNoProviders{
Hostname: hostname,
HasOtherVersion: true,
}
default:
return nil, ErrHostUnreachable{
Hostname: hostname,
Wrapped: err,
}
}
// Check if we have credentials configured for this hostname.
creds, err := s.services.CredentialsForHost(hostname)
if err != nil {
// This indicates that a credentials helper failed, which means we
// can't do anything better than just pass through the helper's
// own error message.
return nil, fmt.Errorf("failed to retrieve credentials for %s: %s", hostname, err)
}
return newRegistryClient(url, creds), nil
}
func (s *RegistrySource) ForDisplay(provider addrs.Provider) string {
return fmt.Sprintf("registry %s", provider.Hostname.ForDisplay())
}
View on GitHub (pinned to d32a084675)