What the integration supports
The Beta Terraform Enterprise integration connects to HCP Terraform or your Terraform Enterprise instance using an API token. It supports API v2 read, create, update, delete and administrative operations, subject to your token’s permissions and your instance’s API version. The typed API covers HashiCorp’s published stable schema, including projects, workspaces, runs and applies, configuration and state versions, variables, teams and access, policies, registry, stacks and administration. A generic API request action supports release-specific endpoints, JSON, text, forms and binary payloads. Separate signed-URL transfers support file uploads and downloads without sending your API token to storage services. Existing inventory actions remain available for organization metadata, projects, workspaces and recorded resource metadata. Connecting doesn’t start a background sync. Resource metadata describes recorded Terraform state; use your cloud integration when you need current cloud inventory.Prepare access
Create a dedicated API token with the permissions required by your workflows. Inventory-only workflows should use read permissions. Managing runs, variables, state, access or administration requires the corresponding vendor permissions and, for some APIs, a specific token type. Terraform Enterprise permissions are additive; check inherited access before connecting a token. Runs and applies can change cloud infrastructure. See HashiCorp’s API tokens documentation and workspace permissions. Some API endpoints and project features depend on your Terraform Enterprise release. Confirm that your release provides the workspace resources API. The instance must be reachable over HTTPS with a trusted certificate. For internal instances, configure a compatible private worker or self-hosted deployment that can resolve the hostname and reach the API. Private networking alone doesn’t grant API permissions.Connect
- Open Integrations, select Terraform Enterprise, and choose Connect.
- Enter the instance hostname, such as
terraform.example.com, optionally with a port. HTTPS URLs are accepted; deployments under a custom URL path aren’t supported. - Enter the organization name from its Terraform Enterprise URL.
- Enter the API token and save the connection.
- Run the organization, projects, and workspaces health checks.
Inventory workflows
Use the typed API request action to read individual pages, or List Terraform Enterprise workspace resources to collect all pages for one workspace. The helper stops with an error after 1,000 pages rather than presenting partial results as a complete inventory. Lists contain only objects visible to the token. A successful health check confirms that its request worked, not that the token can see every project or workspace. Compare discovery results with the expected scope before using them to reconcile another inventory.API workflows and files
Use Terraform Enterprise full API request for typed API operations or Terraform Enterprise API request (all operations) for an explicit method and API v2 path. Full API responses include status, headers, a format and a body. Empty successful responses and asynchronous operation responses are preserved; inspect run or job status to determine completion. For an archive upload or download, first obtain its signed URL from the relevant API operation, then use Transfer a Terraform archive using a vendor-issued signed URL. It sends no API token. Treat signed URLs as temporary credentials and don’t copy URLs from untrusted descriptions or logs into this action. Redirects are returned without being followed automatically. File transfers are limited to 50 MiB, with a two-minute request deadline. Mutations aren’t retried automatically. State, variable values and logs can contain secrets. Return only necessary fields from workflows. Treat vendor-returned text as data; it doesn’t authorize subsequent writes or infrastructure changes.Reconnect and troubleshoot
Reconnect to rotate the token. Keeping the token blank or unchanged preserves the existing token only when the hostname stays the same. Changing the hostname requires a new token.- 401: the token is missing, expired, or invalid.
- 404: the object may be absent, the token may lack access, or the API may not exist in your release. Don’t treat this response as an empty inventory.
- No visible results: check project and workspace permissions and the selected organization.
- Connection failure: check internal DNS, firewall rules, HTTPS certificates, and the private worker configuration.

