aws sso login succeeds but every command still fails with ExpiredToken
Fixes the maddening case where aws sso login succeeds but every command still fails with ExpiredToken. Use when the login flow completes yet the error persists. The cause is stale AWS_ environment variables overriding the fresh SSO session. Not for genuinely expired sessions.
The login worked, but stale AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY / AWS_SESSION_TOKEN environment variables are overriding your fresh SSO session. Run unset AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY AWS_SESSION_TOKEN, then retry. Env vars always beat the config file.
An error occurred (ExpiredToken) when calling the ListBuckets operation: The security token included in the request is expired(The twist: you JUST ran aws sso login successfully and it still fails.)
Fix
- Check for overriding env vars:
env | grep AWS_ Expected culprits: AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN set to old values.
- Unset them (do not set them to empty strings):
unset AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY AWS_SESSION_TOKEN Expected: env | grep AWS_ no longer shows them.
- Retry with the profile:
aws sts get-caller-identity --profile your-profileExpected: success, using the fresh SSO session.
- Make it permanent: remove the exports from
~/.bashrc,~/.zshrc, or your IDE's env config so new shells do not reintroduce the stale keys.
When this applies
aws sso logincompletes successfully but commands immediately fail withExpiredToken.aws configure listshows credentials coming fromenvrather than the profile.
When it does NOT apply
- The SSO session is genuinely expired (hours old): just
aws sso loginagain. InvalidClientTokenId: the keys themselves are wrong, not merely stale.
Compatibility
- AWS CLI v1 and v2. The env-over-file precedence is the same in both.
Why it happens
The CLI's credential precedence is: env vars first, then config/credentials files, then SSO cache. aws sso login refreshes the cache, but if your shell exports old keys, the CLI never looks at the fresh session. This commonly comes from a .bashrc export added months ago for a different task.
Edge cases
AWS_PROFILEset to an empty string is a separate trap (The config profile () could not be found);unsetit too if present.- Tools like direnv or IDE run configs can inject these vars invisibly; check those if
envlooks clean in your terminal but the error persists in the tool.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.