hashicorp/terraform · error
organization at host not found. Please ensure that the…
Error message
organization %q at host %s not found. Please ensure that the organization and hostname are correct and that your API token for %s is valid.
What it means
During cloud backend Configure, Terraform reads the organization's entitlements to verify the organization exists and determine its feature set. If the API returns tfe.ErrResourceNotFound (HTTP 404), the error is enhanced with guidance about verifying the organization name, hostname, and API token validity. This combined error is surfaced as a diagnostic on the 'organization' attribute.
Solutions
- Verify the organization name is spelled correctly in your cloud block or TF_CLOUD_ORGANIZATION.
- Check that your API token is valid and has access to the organization: `curl -H "Authorization: Bearer $TOKEN" https://<hostname>/api/v2/organizations/<org>`.
- Ensure the hostname matches the token's origin (HCP vs self-hosted TFE).
- Re-run `terraform login <hostname>` to refresh the token if it has expired.
Example fix
# before — wrong org name or missing token
terraform {
cloud {
organization = "MyOrg"
}
}
# after — verify and correct
terraform {
cloud {
organization = "my-correct-org"
}
}
# Then run: terraform login app.terraform.io Defensive patterns
Strategy: validation
Validate before calling
// Before Configure, verify the organization exists
curl -sS -o /dev/null -w '%{http_code}' \
-H "Authorization: Bearer $TOKEN" \
https://<hostname>/api/v2/organizations/<org>
# Expected: 200. If 404, the org name or token is wrong. Prevention
- Verify the organization name matches exactly (case-sensitive) what is in HCP Terraform / TFE.
- Run `terraform login <hostname>` to ensure a valid, current token is stored.
- Double-check TF_CLOUD_ORGANIZATION env var if not using a cloud block.
- Ensure the token has organization-level read access, not just workspace access.
When it happens
Trigger: Calling b.client.Organizations.ReadEntitlements at backend.go:368 returns tfe.ErrResourceNotFound. This means the HCP Terraform / TFE API responded with 404 for the given organization name, which can mean the org doesn't exist, the name is misspelled, or the token lacks access (HCP Terraform returns 404 for both non-existent and unauthorized resources).
Common situations: Typo in the organization name in the cloud block or TF_CLOUD_ORGANIZATION env var. The API token belongs to a different organization or has been revoked. Using a token for app.terraform.io against a self-hosted TFE instance or vice versa. The organization was renamed or deleted.
Related errors
- Attempted to find configured project
- failed to retrieve project
- Failed to retrieve workspace
- failed to retrieve workspace
- a network issue prevented cloud configuration;
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/9470c42dc67cda17.
Report an issue: GitHub.
Appendix: source
Thrown at internal/cloud/backend.go:371
`HCP Terraform or Terraform Enterprise client: %s.`, err,
),
))
return diags
}
}
// Read the app name header and if empty, provide a default
b.appName = b.client.AppName()
// Validate the header's value to ensure no tampering
if !isValidAppName(b.appName) {
b.appName = "HCP Terraform"
}
// Check if the organization exists by reading its entitlements.
entitlements, err := b.client.Organizations.ReadEntitlements(context.Background(), b.Organization)
if err != nil {
if err == tfe.ErrResourceNotFound {
err = fmt.Errorf("organization %q at host %s not found.\n\n"+
"Please ensure that the organization and hostname are correct "+
"and that your API token for %s is valid.",
b.Organization, b.Hostname, b.Hostname)
}
diags = diags.Append(tfdiags.AttributeValue(
tfdiags.Error,
fmt.Sprintf("Failed to read organization %q at host %s", b.Organization, b.Hostname),
fmt.Sprintf("Encountered an unexpected error while reading the "+
"organization settings: %s", err),
cty.Path{cty.GetAttrStep{Name: "organization"}},
))
return diags
}
// If TF_WORKSPACE specifies a current workspace to use, make sure it's usable.
if ws, ok := os.LookupEnv("TF_WORKSPACE"); ok {
if ws == b.WorkspaceMapping.Name || b.WorkspaceMapping.IsTagsStrategy() {
diag := b.validWorkspaceEnvVar(context.Background(), b.Organization, ws)View on GitHub (pinned to d32a084675)