Comparison · verified August 2026
An alternative to HCP Terraform
HashiCorp renamed Terraform Cloud to HCP Terraform in April 2024. This page is about replacing it: the same API your tooling already speaks, remote state and remote runs, billed by the minute you use rather than by the size of the estate you are keeping still.
The change you make
A hostname, in the block you already have
We implement the Terraform Cloud API, so tofu, the CLI, go-tfe and your existing tooling talk to us without modification. Point the hostname at us and your workspaces, state and runs behave as they did.
Feature parity
What carries over, and what does not
The third column is the one worth reading, and it is the reason the other two are worth believing. If something in it is load-bearing for you, we would rather you found out here than three weeks into a migration.
Same as HCP Terraform
- The Terraform Cloud API
Same JSON:API. Existing tooling works unmodified. - Remote state, locking, versioning, outputs
- Remote plan and apply with approvals
- VCS-driven runs
GitHub, GitHub Apps, GitLab, Forgejo. Webhooks and run triggers. - Workspaces, variables and variable sets
Including sensitive values and precedence. - Private module registry
- Teams, RBAC and workspace permissions
- Self-hosted agents and agent pools
- Dynamic provider credentials
OIDC workload identity, no long-lived cloud keys. - Notifications
Webhook, Slack, Microsoft Teams, email.
What we add
- State diff, rollback and a 30-day recovery window
HCP's states screen is a flat list of version IDs with no diff and no rollback. - Never billed per resource under management
HCP charges for the size of your estate whether or not you touch it. - Never billed per seat
Invite the whole company. - Run-minutes, shared with your CI
One allowance, one invoice.
Not yet
- terraform login
It is turned off deliberately, and this row claimed the opposite until 2026-09-02. `terraform login` drives an OAuth flow through /oauth and /app on the engine host, and our load balancer answers only machine paths there — the engine's browser surface is unreachable by design, because there is exactly one place a customer signs in and it is the dashboard. You set TF_TOKEN_tf_runners_io from a token in your dashboard instead: one line in a shell profile, and the same value `terraform login` would have stored for you. - Terraform itself — we run OpenTofu
Terraform 1.6+ is BUSL-licensed and its grant forbids hosting it competitively, so your configuration is executed by tofu. The language is not the problem — the two are converging, and Terraform 1.15's own headline was closing gaps to OpenTofu. What does differ is the lock file: tofu init rewrites registry.terraform.io entries to registry.opentofu.org and drops the hashes, because OpenTofu rebuilds providers rather than redistributing HashiCorp's. We never write that lock file back to your repository, and we serve HashiCorp's own provider builds from our mirror — so what runs here is the artifact you pinned. If you need the Terraform binary itself, run it yourself, on machines you own, under your own grant. A self-hosted agent is not a way to do that: it executes runs with OpenTofu too. - Terraform-only language features
action blocks (1.14), convert() (1.15) and terraform query / .tfquery.hcl (1.14) have no tofu equivalent yet. The gap runs one to two release cycles and closes in both directions. - Sentinel policies
Never. It is HashiCorp proprietary. OPA/Rego is planned. - Cost estimation
Planned, via Infracost. - Drift detection and health assessments
Planned. - Private provider registry
Planned. The module registry works today. - Run tasks and no-code modules
Planned. - Stacks
Not planned. - SAML and SCIM
Planned. OIDC and OAuth work today.
Questions
The ones worth asking before you move
Is runners.io affiliated with HashiCorp?
No. Terraform, HCP Terraform and Terraform Cloud are HashiCorp products, and Terraform and HashiCorp are HashiCorp's trademarks. We name them to describe what our product is compatible with and where it differs, which is the only use we make of them. We are not affiliated with, endorsed by or sponsored by HashiCorp.
Was Terraform Cloud renamed?
Yes. HashiCorp renamed Terraform Cloud to HCP Terraform in April 2024. It is the same hosted product, and existing accounts moved across without anybody having to do anything. Both names appear on this page because both are still in use.
Do I have to change my Terraform configuration?
One block. Add a hostname to your cloud block — hostname = "tf.runners.io" alongside the organization you already have — and your workspaces, state and runs behave as they did. We implement the Terraform Cloud API, so the CLI, go-tfe and anything else built on that API talk to us without modification. Authentication differs in one way and it is deliberate: terraform login is not supported, because the engine's browser flow is turned off at our edge. You copy a token from your dashboard and set TF_TOKEN_tf_runners_io instead.
Why does it run OpenTofu rather than Terraform?
Terraform 1.6 and later are licensed under the BUSL, whose Additional Use Grant excludes offering the software itself on a hosted basis competitively. So your configuration is executed by tofu rather than by terraform. The language is not the obstacle — the two are converging, and Terraform 1.15's own headline was closing gaps to OpenTofu. If you need the Terraform binary specifically, run it yourself, on machines you own, under your own grant. A self-hosted agent is not a way to do that: it executes runs with OpenTofu too.
What happens to my .terraform.lock.hcl?
Nothing. tofu init rewrites registry.terraform.io entries to registry.opentofu.org and drops the hashes, because OpenTofu rebuilds providers rather than redistributing HashiCorp's builds. We never write that lock file back to your repository, and we serve HashiCorp's own provider builds from our mirror — so what runs here is the artefact you pinned.
How is it billed?
By the run-minute, from the same allowance your CI jobs draw on. Never per resource under management, and never per seat — so an estate you rarely touch costs nothing to keep, and inviting the whole company costs nothing either. One meter, one invoice.
What is missing compared to HCP Terraform?
Sentinel policies, which are HashiCorp proprietary and will never be here — OPA/Rego is planned instead. Cost estimation, drift detection, health assessments, a private provider registry, run tasks, no-code modules, SAML and SCIM are all planned but not shipped. Stacks are not planned. The full list is on this page, above.