rust-lang/cargo · error
no credential providers could handle the request
Error message
no credential providers could handle the request
What it means
Cargo iterates every configured credential provider for a registry (cargo:token, cargo:paseto, wincred, macos-keychain, libsecret, or an external credential-process). Each provider returns either UrlNotSupported (skipped) or NotFound. This bail fires only when no provider reported it could handle the registry URL and none reported NotFound, meaning the request shape is recognized but unmatched by any provider's URL pattern.
Solutions
- Configure a credential provider for the registry in .cargo/config.toml: [registry.my-registry] with a credential-provider entry, or set CARGO_REGISTRY_MY-REGISTRY_TOKEN.
- Run `cargo login --registry <name>` to store a token via cargo:token.
- Verify the credential provider's accepted URL pattern matches the registry index URL printed by Cargo.
- If using a custom credential-process, test it with the registry URL in isolation and confirm it does not emit UrlNotSupported.
Example fix
// before: no provider configured, private registry publish fails // .cargo/config.toml is empty // after: .cargo/config.toml // [registry.my-registry] // credential-provider = "cargo:token" // then: cargo login --registry my-registry
Defensive patterns
Strategy: validation
Validate before calling
use cargo::util::auth;
fn registry_has_provider(gctx: &GlobalContext, sid: &SourceId) -> bool {
auth::credential_provider(gctx, sid, /*require=*/false, /*check_config=*/true)
.map(|v| !v.is_empty())
.unwrap_or(false)
}
// call before publish/fetch on a private registry:
// if !registry_has_provider(gctx, sid) { eprintln!("configure a credential provider first"); } Try / catch
// Rust: these bail as anyhow::Error; surface a user hint.
match auth::auth(gctx, sid, /*...*/) {
Ok(resp) => { /* use resp */ }
Err(e) if e.to_string().contains("no credential providers") => {
eprintln!("No credential provider matched registry {}. Add a [registry.<name>] credential-provider or set CARGO_REGISTRY_<NAME>_TOKEN.", sid.url());
return Err(e);
}
Err(e) => return Err(e),
} Prevention
- Always configure a credential-provider entry for private registries in .cargo/config.toml.
- Run `cargo login --registry <name>` once per machine/user before first publish.
- In CI, inject tokens via documented CARGO_REGISTRY_<NAME>_TOKEN env vars rather than relying on default providers.
When it happens
Trigger: Calling auth_token()/auth() against a private/alternate registry whose configured credential provider does not claim the registry's index URL, or invoking a registry operation (publish, yank, fetch) when no credential provider is configured for that registry at all.
Common situations: Missing [registry] table / registry-<name> entry in .cargo/config.toml; credential-process configured for a different URL than the registry index; credential provider returns UrlNotSupported for a self-hosted/Artifactory/GitLab registry; CARGO_REGISTRY_<name>_TOKEN unset and no provider listed.
Related errors
- multiple registries are configured with the same index url
- credential process ` ` failed with status
- config.json not found
- local registry index path is not a directory
- local registry path is not a directory
AI-assisted analysis of rust-lang/cargo@98a09e7e7d (2026-08-11).
Data as JSON: /api/errors/c331f275c6caeefc.
Report an issue: GitHub.
Appendix: source
Thrown at src/util/auth/mod.rs:494
})?;
match provider.perform(®istry, &action, &args[1..]) {
Ok(response) => return Ok(response),
Err(cargo_credential::Error::UrlNotSupported) => {}
Err(cargo_credential::Error::NotFound) => any_not_found = true,
e => {
return e.with_context(|| {
format!(
"credential provider `{}` failed action `{action}`",
args.join(" ")
)
});
}
}
}
if any_not_found {
Err(cargo_credential::Error::NotFound.into())
} else {
anyhow::bail!("no credential providers could handle the request")
}
}
/// Returns the token to use for the given registry.
/// If a `login_url` is provided and a token is not available, the
/// `login_url` will be included in the returned error.
pub fn auth_token(
gctx: &GlobalContext,
sid: &SourceId,
login_url: Option<&Url>,
operation: Operation<'_>,
headers: Vec<String>,
require_cred_provider_config: bool,
) -> CargoResult<String> {
match auth_token_optional(gctx, sid, operation, headers, require_cred_provider_config)? {
Some(token) => Ok(token.expose()),
None => Err(AuthorizationError::new(
gctx,View on GitHub (pinned to 98a09e7e7d)