## TL;DR

Your `provider` block has a field the provider rejects: a wrong format, a missing required setting, or a value from another context. Compare each field against the provider's docs, fix the block, and re-run.

## The error

```text
Error: Invalid provider configuration
```

(often followed by provider-specific detail naming the offending field)

## Steps to fix

1. Open the `provider "[name]"` block. Read the detail lines: they usually name the exact field.
   - Expected: you know which field the provider dislikes.
2. Check the provider's registry docs for that field: format (no `https://`? no trailing slash?), required vs optional, allowed values.
   - Expected: you spot the format violation.
3. Fix the block:
   ```hcl
   provider "okta" {
     org_name = "your-org-name"
     base_url = "okta.com"
   }
   ```
   - Expected: every field matches the documented format.
4. Re-run `terraform init` / `plan`.
   - Expected: provider configures successfully.

## When to use this

- Terraform fails with `Invalid provider configuration` naming a provider block field, right after writing or editing provider config.

## When NOT to use this

- `no valid credential sources` means credentials are missing entirely, a different problem. `Failed to install provider` is a download/version problem.

## Compatibility

- All Terraform versions; validation rules are provider-defined.

## Root cause

Providers validate their configuration before doing anything. Format assumptions (scheme prefixes, trailing slashes, region formats) differ per provider, and copying values from a browser URL bar or another tool's config is the usual way bad values get in.

## Edge cases

- Aliased providers (`provider "aws" { alias = "west" }`) are validated independently; the error names the alias.
- Environment-variable-based config bypasses the block; if the block looks right, check for conflicting env vars.
- Some providers validate lazily at plan time, so `init` succeeding does not prove the block is correct.