hashicorp/terraform · error

failed to retrieve credentials for

Error message

failed to retrieve credentials for %s: %s

What it means

Returned when RegistrySource.registryClient fails to obtain credentials for a hostname via services.CredentialsForHost. This indicates a credentials *helper* (e.g. terraform-credentials-env, a custom credential helper, or the token store) errored, not that credentials are simply absent. The '%s' suffix carries the helper's own error.

Solutions

  1. Read the trailing '%s' which contains the helper's native error and address that root cause.
  2. Re-run 'terraform login <hostname>' to refresh the stored token.
  3. Inspect ~/.terraform.d/credentials.tfrc.json (or the helper output) for malformed JSON.
  4. If a custom helper is in use, run it manually with the hostname to reproduce and fix.
  5. Temporarily unset the credential helper to confirm it is the source of the failure.

Example fix

// before
Error: failed to retrieve credentials for app.terraform.io: helper exited with status 127
// after (ensure helper is on PATH or remove the helper block from ~/.terraformrc)
credentials_helper "atlassian" { args = [] }
Defensive patterns

Strategy: try-catch

Try / catch

// Surface the helper's underlying error and degrade gracefully.
_, err := source.PackageMeta(...)
if err != nil && strings.Contains(err.Error(), "failed to retrieve credentials for") {
    log.Printf("credential helper issue: %v", err)
    // fall back to anonymous registry access or prompt re-login
}

Prevention

When it happens

Trigger: A credential helper binary exited non-zero or returned malformed output for the given hostname; the cached token in ~/.terraform.d/credentials is corrupt; 'terraform login' stored a token that the helper cannot parse.

Common situations: Custom credential helper misconfigured in CLI config; helper binary not on PATH or crashing; corrupted credentials.tfrc.json; token format changed after a terraform upgrade.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/0a0ae45e23f8b0ac. Report an issue: GitHub.

Appendix: source

Thrown at internal/getproviders/registry_source.go:144

	case *disco.ErrVersionNotSupported:
		return nil, ErrHostNoProviders{
			Hostname:        hostname,
			HasOtherVersion: true,
		}
	default:
		return nil, ErrHostUnreachable{
			Hostname: hostname,
			Wrapped:  err,
		}
	}

	// Check if we have credentials configured for this hostname.
	creds, err := s.services.CredentialsForHost(hostname)
	if err != nil {
		// This indicates that a credentials helper failed, which means we
		// can't do anything better than just pass through the helper's
		// own error message.
		return nil, fmt.Errorf("failed to retrieve credentials for %s: %s", hostname, err)
	}

	return newRegistryClient(url, creds), nil
}

func (s *RegistrySource) ForDisplay(provider addrs.Provider) string {
	return fmt.Sprintf("registry %s", provider.Hostname.ForDisplay())
}

View on GitHub (pinned to d32a084675)