Error: Failed to install provider
Fixes OpenTofu's 'Error: Failed to install provider' when the registry demands auth or the download fails. Use when tofu init fails installing a specific provider version with a registry or network complaint. Not for 'Failed to query available provider packages' (resolution) or checksum mismatches.
TL;DR: tofu can't download the provider: the registry asked for auth credentials, or the connection failed. Read the tail of the message. requires authentication credentials on registry.opentofu.org has been a transient registry-side incident; TLS timeouts are your network. Retry first, then check proxy and mirrors.
Error: Failed to install provider
Error while installing hashicorp/random v3.7.2: host registry.opentofu.org
requires authentication credentialsSteps
- Read the tail of the error (the part after the provider name and version). It distinguishes the causes:
requires authentication credentials/403 Forbidden: registry-side or proxy issue.TLS handshake timeout/could not connect: your network.checksum mismatch: lock file problem, different fix.
Expected: you can name the cause.
- Retry once. Registry-side blips and rate limits are transient.
Expected: the second tofu init succeeds.
- If it persists, check the path to the registry: proxy env vars (
HTTPS_PROXY), egress firewall rules, and whethercurl -sI https://registry.opentofu.organswers from the same machine.
Expected: you find the broken hop.
- For air-gapped or flaky networks, install via a filesystem mirror: download the provider zip once, unpack it under the documented local mirror directory layout, and re-run init.
Expected: init uses the local copy without touching the network.
When this applies
tofu initfails onError while installing [provider] v[version]:with a registry, auth, or network complaint.- It worked before with no config change (points at transient/registry-side).
When it doesn't apply
Error: Failed to query available provider packagesfails earlier, at version LISTING; this error fails at DOWNLOAD.- Checksum mismatches (
doesn't match any of the checksums previously recorded) are a lock-file problem; fix withtofu providers lock.
Tool versions
All OpenTofu versions.
Why it happens
Installing is a plain HTTPS download from the registry (or a mirror). Anything that breaks HTTPS here, broken proxy, egress block, expired CA bundle, registry incident, surfaces as this error, after version resolution already succeeded.
Edge cases
- Corporate MITM proxies: the Go HTTP client needs the proxy CA in the system trust store, or every registry call fails TLS.
- Don't "fix" a 403 by adding registry credentials to your CLI config unless you actually use a private registry. The public registry needs no auth; a 403 there is an incident or a proxy mangling the request.
- CI runners with IPv6-only egress have hit discovery-document failures; forcing IPv4 or fixing egress is the fix, not the config.