TL;DR: Your lock file only has hashes for the platform it was generated on (e.g. macOS arm64), and CI runs on another (linux amd64). Record hashes for ALL your platforms with `tofu providers lock -platform=...` and commit the result. Never delete the lock file.

```text
Error: registered checksum for provider ... does not match
```

## Steps

1. Confirm it's a platform gap: the error appears on a different OS/arch than the machine that generated `.terraform.lock.hcl`.
   Expected: local init works, CI init fails (or vice versa).
2. Record every platform you use:
   ```
   tofu providers lock \
     -platform=linux_amd64 \
     -platform=darwin_arm64 \
     -platform=linux_arm64
   ```
   Expected: the lock file gains `zh:` hashes for each platform.
3. Commit the updated `.terraform.lock.hcl`.
   Expected: CI and local both init clean.

## When this applies

- Checksum mismatch that appears only on a specific platform.
- Mixed team (macOS + Linux) or CI on a different arch than dev machines.

## When it doesn't apply

- `Error: Inconsistent dependency lock file`: that's a version-selection conflict, fixed by re-resolving, not by adding platforms.
- Mismatch on the SAME platform after no upgrade: investigate a tampered mirror or corrupted cache before accepting new hashes.

## Tool versions

All OpenTofu versions.

## Why it happens

The lock file pins hashes per platform. A lock generated on one machine only knows that machine's platform; any other platform's download has no recorded hash to compare against, so init refuses rather than trusting an unpinned binary.

## Edge cases

- If you DID upgrade a provider intentionally, `tofu init -upgrade` regenerates hashes; use that instead of hand-editing.
- Deleting the lock file "fixes" it by removing all pins, which moves the problem to the next person and every future CI run. Don't.