Error: pulumi:providers:aws resource 'default' has a problem: Invalid credentials configured
Fixes the Pulumi AWS provider rejecting the configured credentials. For engineers whose keys or session are present but invalid, covering rotation, typos, and revoked keys.
Error: pulumi:providers:aws resource 'default' has a problem: Invalid credentials configured
TL;DR
Credentials were found but AWS rejected them. Verify with aws sts get-caller-identity, fix the key/secret (typo, revoked key, wrong account), and re-run. For teams, move to Pulumi ESC with AWS OIDC so there are no static keys to go stale.
The error
Diagnostics:
pulumi:providers:aws (default):
error: pulumi:providers:aws resource 'default_6_18_2' has a problem: Invalid credentials configured.
Please see https://www.pulumi.com/docs/intro/cloud-providers/aws/setup/ for more information about providing credentials.Fix it
- Test the same credentials outside Pulumi:
aws sts get-caller-identity.
- Success check: if this fails, the credentials are bad; fix them in AWS IAM first.
- Common causes: a typo in the secret, a deactivated or deleted access key, keys for the wrong account, or a session token paired with the wrong key.
- Success check: a fresh key pair from IAM works in the CLI test.
- Update wherever Pulumi reads them:
pulumi config set --secret aws:secretKey [new secret]for stack config, or re-export the env vars.
- Success check:
pulumi previewpasses provider configuration.
- For a durable fix, replace static keys with Pulumi ESC dynamic credentials via AWS OIDC.
- Success check: no static keys exist to go invalid.
When to use this
You hit this when credentials are configured but AWS rejects them, as distinct from credentials being absent entirely.
When NOT to use this
Do not use this for No valid credential sources found (nothing configured) or ExpiredToken (valid keys, dead session; refresh the session).
Compatibility
Pulumi CLI 3.x, Pulumi AWS provider v6.x.
Variants
error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found.(absent, not invalid)InvalidClientTokenIdfrom raw AWS API calls with the same bad key
Root cause
The provider found a credential source and tried it, but AWS returned an auth failure: wrong secret, inactive key, or mismatched session token.
Edge cases
- Keys with special characters can get mangled by shell quoting or config file escaping. Re-enter them carefully.
- An
AWS_SESSION_TOKENleft over from an old session paired with new keys fails auth; refresh all three together.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.