VectleSkillsDiagnose: invalid_grant Token has been expired or revoked

Diagnose: invalid_grant Token has been expired or revoked

Export

Shows how to fix diagnose: invalid_grant Token has been expired or revoked. Use it when you hit this exact problem. Skip it when your error message or symptom looks different.

TL;DR

For "google.auth.exceptions.RefreshError: ('invalid_grant: Bad Request', ...)": for key files: the key was deleted from the service account, or the SA was deleted/disabled. Check the ADC file timestamp; ancient files from old machine images are suspect. - Key file: gcloud iam service-accounts keys list --iam-account [SA-EMAIL] - is your key ID still there?

google.auth.exceptions.RefreshError: ('invalid_grant: Bad Request', ...)

Steps

  1. Symptom: google.auth.exceptions.RefreshError: ('invalid_grant: Bad Request', ...) or "Token has been expired or revoked."
  1. Cause: the refresh token ADC is holding is no longer valid. For user credentials: revoked in account settings, expired from disuse, or admin-revoked. For key files: the key was deleted from the service account, or the SA was deleted/disabled.
  1. Confirm:
  • User ADC: gcloud auth application-default print-access-token fails the same way. Check the ADC file timestamp; ancient files from old machine images are suspect.
  • Key file: gcloud iam service-accounts keys list --iam-account [SA-EMAIL] - is your key ID still there? Is the SA itself still enabled?
  1. Fix:
  • User ADC: delete the stale applicationdefaultcredentials.json and run gcloud auth application-default login fresh.
  • Key file: if the key was deleted, create a new one (or better, move to Workload Identity Federation so there is no key to die). If the SA was deleted, that is a bigger incident; recreate and re-grant.
  1. Do not retry in a loop. The token is dead; retries burn time and can look abusive. Also do not "fix" user-ADC invalid_grant by minting a key file; match the fix to the credential type.
  1. Verify: print-access-token returns a token, and the original script authenticates. In CI, confirm the new key or federation config is what the job actually loads (echo the key ID or check the WIF setup).

When to use

You are seeing this: Symptom: google.auth.exceptions.RefreshError: ('invalid\grant: Bad Request',...) or "Token has been expired or revoked." Cause: the refresh token ADC is holding is no longer valid. Use this skill when you run into "Diagnose: invalidgrant Token has been expired or revoked".

When not to use

If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.

Versions

No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.

Why this happens

The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.

Edge cases

  • Also do not "fix" user-ADC invalid_grant by minting a key file; match the fix to the credential type.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Diagnose%3A+invalid_grant+Token+has+been+expired+or+revoked&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.