hashicorp/terraform · error

organization at host not found. Please ensure that the…

Error message

organization %q at host %s not found.

Please ensure that the organization and hostname are correct and that your API token for %s is valid.

What it means

During cloud backend Configure, Terraform reads the organization's entitlements to verify the organization exists and determine its feature set. If the API returns tfe.ErrResourceNotFound (HTTP 404), the error is enhanced with guidance about verifying the organization name, hostname, and API token validity. This combined error is surfaced as a diagnostic on the 'organization' attribute.

Solutions

  1. Verify the organization name is spelled correctly in your cloud block or TF_CLOUD_ORGANIZATION.
  2. Check that your API token is valid and has access to the organization: `curl -H "Authorization: Bearer $TOKEN" https://<hostname>/api/v2/organizations/<org>`.
  3. Ensure the hostname matches the token's origin (HCP vs self-hosted TFE).
  4. Re-run `terraform login <hostname>` to refresh the token if it has expired.

Example fix

# before — wrong org name or missing token
terraform {
  cloud {
    organization = "MyOrg"
  }
}

# after — verify and correct
terraform {
  cloud {
    organization = "my-correct-org"
  }
}
# Then run: terraform login app.terraform.io
Defensive patterns

Strategy: validation

Validate before calling

// Before Configure, verify the organization exists
curl -sS -o /dev/null -w '%{http_code}' \
  -H "Authorization: Bearer $TOKEN" \
  https://<hostname>/api/v2/organizations/<org>
# Expected: 200. If 404, the org name or token is wrong.

Prevention

When it happens

Trigger: Calling b.client.Organizations.ReadEntitlements at backend.go:368 returns tfe.ErrResourceNotFound. This means the HCP Terraform / TFE API responded with 404 for the given organization name, which can mean the org doesn't exist, the name is misspelled, or the token lacks access (HCP Terraform returns 404 for both non-existent and unauthorized resources).

Common situations: Typo in the organization name in the cloud block or TF_CLOUD_ORGANIZATION env var. The API token belongs to a different organization or has been revoked. Using a token for app.terraform.io against a self-hosted TFE instance or vice versa. The organization was renamed or deleted.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/9470c42dc67cda17. Report an issue: GitHub.

Appendix: source

Thrown at internal/cloud/backend.go:371

						`HCP Terraform or Terraform Enterprise client: %s.`, err,
				),
			))
			return diags
		}
	}

	// Read the app name header and if empty, provide a default
	b.appName = b.client.AppName()
	// Validate the header's value to ensure no tampering
	if !isValidAppName(b.appName) {
		b.appName = "HCP Terraform"
	}

	// Check if the organization exists by reading its entitlements.
	entitlements, err := b.client.Organizations.ReadEntitlements(context.Background(), b.Organization)
	if err != nil {
		if err == tfe.ErrResourceNotFound {
			err = fmt.Errorf("organization %q at host %s not found.\n\n"+
				"Please ensure that the organization and hostname are correct "+
				"and that your API token for %s is valid.",
				b.Organization, b.Hostname, b.Hostname)
		}
		diags = diags.Append(tfdiags.AttributeValue(
			tfdiags.Error,
			fmt.Sprintf("Failed to read organization %q at host %s", b.Organization, b.Hostname),
			fmt.Sprintf("Encountered an unexpected error while reading the "+
				"organization settings: %s", err),
			cty.Path{cty.GetAttrStep{Name: "organization"}},
		))
		return diags
	}

	// If TF_WORKSPACE specifies a current workspace to use, make sure it's usable.
	if ws, ok := os.LookupEnv("TF_WORKSPACE"); ok {
		if ws == b.WorkspaceMapping.Name || b.WorkspaceMapping.IsTagsStrategy() {
			diag := b.validWorkspaceEnvVar(context.Background(), b.Organization, ws)

View on GitHub (pinned to d32a084675)