rust-lang/cargo · error

no credential providers could handle the request

Error message

no credential providers could handle the request

What it means

Cargo iterates every configured credential provider for a registry (cargo:token, cargo:paseto, wincred, macos-keychain, libsecret, or an external credential-process). Each provider returns either UrlNotSupported (skipped) or NotFound. This bail fires only when no provider reported it could handle the registry URL and none reported NotFound, meaning the request shape is recognized but unmatched by any provider's URL pattern.

Solutions

  1. Configure a credential provider for the registry in .cargo/config.toml: [registry.my-registry] with a credential-provider entry, or set CARGO_REGISTRY_MY-REGISTRY_TOKEN.
  2. Run `cargo login --registry <name>` to store a token via cargo:token.
  3. Verify the credential provider's accepted URL pattern matches the registry index URL printed by Cargo.
  4. If using a custom credential-process, test it with the registry URL in isolation and confirm it does not emit UrlNotSupported.

Example fix

// before: no provider configured, private registry publish fails
// .cargo/config.toml is empty

// after: .cargo/config.toml
// [registry.my-registry]
// credential-provider = "cargo:token"
// then: cargo login --registry my-registry
Defensive patterns

Strategy: validation

Validate before calling

use cargo::util::auth;

fn registry_has_provider(gctx: &GlobalContext, sid: &SourceId) -> bool {
    auth::credential_provider(gctx, sid, /*require=*/false, /*check_config=*/true)
        .map(|v| !v.is_empty())
        .unwrap_or(false)
}

// call before publish/fetch on a private registry:
// if !registry_has_provider(gctx, sid) { eprintln!("configure a credential provider first"); }

Try / catch

// Rust: these bail as anyhow::Error; surface a user hint.
match auth::auth(gctx, sid, /*...*/) {
    Ok(resp) => { /* use resp */ }
    Err(e) if e.to_string().contains("no credential providers") => {
        eprintln!("No credential provider matched registry {}. Add a [registry.<name>] credential-provider or set CARGO_REGISTRY_<NAME>_TOKEN.", sid.url());
        return Err(e);
    }
    Err(e) => return Err(e),
}

Prevention

When it happens

Trigger: Calling auth_token()/auth() against a private/alternate registry whose configured credential provider does not claim the registry's index URL, or invoking a registry operation (publish, yank, fetch) when no credential provider is configured for that registry at all.

Common situations: Missing [registry] table / registry-<name> entry in .cargo/config.toml; credential-process configured for a different URL than the registry index; credential provider returns UrlNotSupported for a self-hosted/Artifactory/GitLab registry; CARGO_REGISTRY_<name>_TOKEN unset and no provider listed.

Related errors


AI-assisted analysis of rust-lang/cargo@98a09e7e7d (2026-08-11). Data as JSON: /api/errors/c331f275c6caeefc. Report an issue: GitHub.

Appendix: source

Thrown at src/util/auth/mod.rs:494

        })?;
        match provider.perform(&registry, &action, &args[1..]) {
            Ok(response) => return Ok(response),
            Err(cargo_credential::Error::UrlNotSupported) => {}
            Err(cargo_credential::Error::NotFound) => any_not_found = true,
            e => {
                return e.with_context(|| {
                    format!(
                        "credential provider `{}` failed action `{action}`",
                        args.join(" ")
                    )
                });
            }
        }
    }
    if any_not_found {
        Err(cargo_credential::Error::NotFound.into())
    } else {
        anyhow::bail!("no credential providers could handle the request")
    }
}

/// Returns the token to use for the given registry.
/// If a `login_url` is provided and a token is not available, the
/// `login_url` will be included in the returned error.
pub fn auth_token(
    gctx: &GlobalContext,
    sid: &SourceId,
    login_url: Option<&Url>,
    operation: Operation<'_>,
    headers: Vec<String>,
    require_cred_provider_config: bool,
) -> CargoResult<String> {
    match auth_token_optional(gctx, sid, operation, headers, require_cred_provider_config)? {
        Some(token) => Ok(token.expose()),
        None => Err(AuthorizationError::new(
            gctx,

View on GitHub (pinned to 98a09e7e7d)