hashicorp/terraform · error

The credentials block has an invalid hostname

Error message

The credentials %q block has an invalid hostname: %s

What it means

Thrown during CLI config validation when a credentials block contains an invalid hostname. Same validation as host blocks: svchost.ForComparison must succeed for the hostname to be usable for credential matching and API token lookup.

Solutions

  1. Correct the hostname in the credentials block to a valid DNS name
  2. Ensure it matches the actual TFC/E or registry hostname exactly
  3. Remove special characters, underscores, and whitespace

Example fix

// before
credentials "app.terraform io" {
  token = "atlasv1-xxx"
}

// after
credentials "app.terraform.io" {
  token = "atlasv1-xxx"
}
Defensive patterns

Strategy: validation

Validate before calling

// Validate hostname in credentials block before writing config
func validateCredHostname(h string) error {
    _, err := svchost.ForComparison(h)
    return err
}

Prevention

When it happens

Trigger: For each key in c.Credentials, svchost.ForComparison(givenHost) returns an error due to invalid hostname format, disallowed characters (underscores, spaces), or empty string.

Common situations: Typo in the credentials hostname; using an underscore-based hostname; trailing whitespace from copy-paste; hostname that does not match the actual TFC/E or registry endpoint.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/f5d8fee9ce19385e. Report an issue: GitHub.

Appendix: source

Thrown at internal/command/cliconfig/cliconfig.go:308

	// to give proper source references to any errors. We should improve
	// on this when we change the CLI config parser to use HCL2.

	// Check that all "host" blocks have valid hostnames.
	for givenHost := range c.Hosts {
		_, err := svchost.ForComparison(givenHost)
		if err != nil {
			diags = diags.Append(
				fmt.Errorf("The host %q block has an invalid hostname: %s", givenHost, err),
			)
		}
	}

	// Check that all "credentials" blocks have valid hostnames.
	for givenHost := range c.Credentials {
		_, err := svchost.ForComparison(givenHost)
		if err != nil {
			diags = diags.Append(
				fmt.Errorf("The credentials %q block has an invalid hostname: %s", givenHost, err),
			)
		}
	}

	// Should have zero or one "credentials_helper" blocks
	if len(c.CredentialsHelpers) > 1 {
		diags = diags.Append(
			fmt.Errorf("No more than one credentials_helper block may be specified"),
		)
	}

	// Should have zero or one "provider_installation" blocks
	if len(c.ProviderInstallation) > 1 {
		diags = diags.Append(
			fmt.Errorf("No more than one provider_installation block may be specified"),
		)
	}

View on GitHub (pinned to d32a084675)