hashicorp/terraform · error
Failed to retrieve user account details
Error message
Failed to retrieve user account details: %s
What it means
Thrown during `terraform login` when `client.Users.ReadCurrent` returns an error that is NOT `tfe.ErrUnauthorized` — i.e. any other failure reaching or reading from the HCP Terraform / TFE user-account endpoint. The token itself may or may not be valid; the request could not be completed for an unrelated transport, server, or parsing reason.
Solutions
- Check connectivity: `curl -i -H "Authorization: Bearer <token>" https://<hostname>/api/v2/account/details` and inspect the HTTP status.
- If a 5xx or 429 is returned, wait and retry `terraform login`.
- Resolve TLS issues by setting `SSL_CERT_FILE` or `NODE_EXTRA_CA_CERTS` for private CAs, or updating the system trust store.
- Verify proxy settings (`HTTPS_PROXY`, `NO_PROXY`) are correct for your network.
- Read the `%s` detail — it typically includes the HTTP status code or transport error.
Example fix
# diagnose the underlying failure curl -v -H "Authorization: Bearer $TFE_TOKEN" https://tfe.corp.example.com/api/v2/account/details # fix TLS for a private CA export SSL_CERT_FILE=/etc/ssl/certs/corp-ca.pem terraform login tfe.corp.example.com
Defensive patterns
Strategy: retry
Validate before calling
// Pre-flight connectivity check to the account endpoint.
resp, err := http.Get("https://" + hostname + "/api/v2/account/details")
if err != nil {
return fmt.Errorf("cannot reach %s: %w; fix network/TLS before login", hostname, err)
}
if resp.StatusCode >= 500 {
return fmt.Errorf("server error %d from %s; retry later", resp.StatusCode, hostname)
} Type guard
null
Try / catch
// Retry transient (5xx, network) failures; do NOT retry 401 (that's error 641).
if !errors.Is(err, tfe.ErrUnauthorized) && isTransient(err) {
time.Sleep(backoff); retry()
} Prevention
- Set `SSL_CERT_FILE` / `HTTPS_PROXY` correctly for private TFE / corporate networks.
- Add a connectivity pre-check in CI before `terraform login`.
- Monitor HCP Terraform status page for outages.
When it happens
Trigger: `GET /api/v2/account/details` fails with a network error (DNS, TCP, TLS), a 5xx server error, a 429 rate limit, a redirect loop, an unexpected response content-type, or a JSON decode failure inside go-tfe. Any of these fall through to the `else if err != nil` branch.
Common situations: TFE instance is temporarily down or returning 500s; corporate firewall/proxy blocks `app.terraform.io` or the private TFE host; TLS certificate mismatch or expired cert on a self-hosted TFE; HCP Terraform rate-limiting; transient connectivity blip; go-tfe version mismatch with the server's API contract.
Related errors
- no suitable TCP ports
- a network issue prevented cloud configuration;
- a network issue prevented cloud configuration;
- Attempted to find configured project
- bucket not exists
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/ee02c07acbc95a96.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/login.go:665
token = strings.TrimSpace(token)
cfg := &tfe.Config{
Address: service.String(),
BasePath: service.Path,
Token: token,
Headers: make(http.Header),
}
client, err := tfe.NewClient(cfg)
if err != nil {
diags = diags.Append(fmt.Errorf("Failed to create API client: %s", err))
return "", diags
}
user, err := client.Users.ReadCurrent(context.Background())
if err == tfe.ErrUnauthorized {
diags = diags.Append(fmt.Errorf("Token is invalid: %s", err))
return "", diags
} else if err != nil {
diags = diags.Append(fmt.Errorf("Failed to retrieve user account details: %s", err))
return "", diags
}
c.Ui.Output(fmt.Sprintf(c.Colorize().Color("\nRetrieved token for user [bold]%s[reset]\n"), user.Username))
return svcauth.HostCredentialsToken(token), nil
}
func (c *LoginCommand) interactiveContextConsent(hostname svchost.Hostname, grantType disco.OAuthGrantType, credsCtx *loginCredentialsContext) (bool, tfdiags.Diagnostics) {
var diags tfdiags.Diagnostics
mechanism := "OAuth"
if grantType == "" {
mechanism = "your browser"
}
c.Ui.Output(fmt.Sprintf("Terraform will request an API token for %s using %s.\n", hostname.ForDisplay(), mechanism))
if grantType.UsesAuthorizationEndpoint() {
c.Ui.Output(View on GitHub (pinned to d32a084675)