hashicorp/terraform · error

Failed to retrieve user account details

Error message

Failed to retrieve user account details: %s

What it means

Thrown during `terraform login` when `client.Users.ReadCurrent` returns an error that is NOT `tfe.ErrUnauthorized` — i.e. any other failure reaching or reading from the HCP Terraform / TFE user-account endpoint. The token itself may or may not be valid; the request could not be completed for an unrelated transport, server, or parsing reason.

Solutions

  1. Check connectivity: `curl -i -H "Authorization: Bearer <token>" https://<hostname>/api/v2/account/details` and inspect the HTTP status.
  2. If a 5xx or 429 is returned, wait and retry `terraform login`.
  3. Resolve TLS issues by setting `SSL_CERT_FILE` or `NODE_EXTRA_CA_CERTS` for private CAs, or updating the system trust store.
  4. Verify proxy settings (`HTTPS_PROXY`, `NO_PROXY`) are correct for your network.
  5. Read the `%s` detail — it typically includes the HTTP status code or transport error.

Example fix

# diagnose the underlying failure
curl -v -H "Authorization: Bearer $TFE_TOKEN" https://tfe.corp.example.com/api/v2/account/details
# fix TLS for a private CA
export SSL_CERT_FILE=/etc/ssl/certs/corp-ca.pem
terraform login tfe.corp.example.com
Defensive patterns

Strategy: retry

Validate before calling

// Pre-flight connectivity check to the account endpoint.
resp, err := http.Get("https://" + hostname + "/api/v2/account/details")
if err != nil {
    return fmt.Errorf("cannot reach %s: %w; fix network/TLS before login", hostname, err)
}
if resp.StatusCode >= 500 {
    return fmt.Errorf("server error %d from %s; retry later", resp.StatusCode, hostname)
}

Type guard

null

Try / catch

// Retry transient (5xx, network) failures; do NOT retry 401 (that's error 641).
if !errors.Is(err, tfe.ErrUnauthorized) && isTransient(err) {
    time.Sleep(backoff); retry()
}

Prevention

When it happens

Trigger: `GET /api/v2/account/details` fails with a network error (DNS, TCP, TLS), a 5xx server error, a 429 rate limit, a redirect loop, an unexpected response content-type, or a JSON decode failure inside go-tfe. Any of these fall through to the `else if err != nil` branch.

Common situations: TFE instance is temporarily down or returning 500s; corporate firewall/proxy blocks `app.terraform.io` or the private TFE host; TLS certificate mismatch or expired cert on a self-hosted TFE; HCP Terraform rate-limiting; transient connectivity blip; go-tfe version mismatch with the server's API contract.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/ee02c07acbc95a96. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/login.go:665

	token = strings.TrimSpace(token)
	cfg := &tfe.Config{
		Address:  service.String(),
		BasePath: service.Path,
		Token:    token,
		Headers:  make(http.Header),
	}
	client, err := tfe.NewClient(cfg)
	if err != nil {
		diags = diags.Append(fmt.Errorf("Failed to create API client: %s", err))
		return "", diags
	}
	user, err := client.Users.ReadCurrent(context.Background())
	if err == tfe.ErrUnauthorized {
		diags = diags.Append(fmt.Errorf("Token is invalid: %s", err))
		return "", diags
	} else if err != nil {
		diags = diags.Append(fmt.Errorf("Failed to retrieve user account details: %s", err))
		return "", diags
	}
	c.Ui.Output(fmt.Sprintf(c.Colorize().Color("\nRetrieved token for user [bold]%s[reset]\n"), user.Username))

	return svcauth.HostCredentialsToken(token), nil
}

func (c *LoginCommand) interactiveContextConsent(hostname svchost.Hostname, grantType disco.OAuthGrantType, credsCtx *loginCredentialsContext) (bool, tfdiags.Diagnostics) {
	var diags tfdiags.Diagnostics
	mechanism := "OAuth"
	if grantType == "" {
		mechanism = "your browser"
	}

	c.Ui.Output(fmt.Sprintf("Terraform will request an API token for %s using %s.\n", hostname.ForDisplay(), mechanism))

	if grantType.UsesAuthorizationEndpoint() {
		c.Ui.Output(

View on GitHub (pinned to d32a084675)