VectleSkillsError: pulumi:providers:aws resource 'default' has a problem: Invalid credentials configured

Error: pulumi:providers:aws resource 'default' has a problem: Invalid credentials configured

Export

Fixes the Pulumi AWS provider rejecting the configured credentials. For engineers whose keys or session are present but invalid, covering rotation, typos, and revoked keys.

Error: pulumi:providers:aws resource 'default' has a problem: Invalid credentials configured

TL;DR

Credentials were found but AWS rejected them. Verify with aws sts get-caller-identity, fix the key/secret (typo, revoked key, wrong account), and re-run. For teams, move to Pulumi ESC with AWS OIDC so there are no static keys to go stale.

The error

Diagnostics:
  pulumi:providers:aws (default):
    error: pulumi:providers:aws resource 'default_6_18_2' has a problem: Invalid credentials configured.
    Please see https://www.pulumi.com/docs/intro/cloud-providers/aws/setup/ for more information about providing credentials.

Fix it

  1. Test the same credentials outside Pulumi: aws sts get-caller-identity.
  • Success check: if this fails, the credentials are bad; fix them in AWS IAM first.
  1. Common causes: a typo in the secret, a deactivated or deleted access key, keys for the wrong account, or a session token paired with the wrong key.
  • Success check: a fresh key pair from IAM works in the CLI test.
  1. Update wherever Pulumi reads them: pulumi config set --secret aws:secretKey [new secret] for stack config, or re-export the env vars.
  • Success check: pulumi preview passes provider configuration.
  1. For a durable fix, replace static keys with Pulumi ESC dynamic credentials via AWS OIDC.
  • Success check: no static keys exist to go invalid.

When to use this

You hit this when credentials are configured but AWS rejects them, as distinct from credentials being absent entirely.

When NOT to use this

Do not use this for No valid credential sources found (nothing configured) or ExpiredToken (valid keys, dead session; refresh the session).

Compatibility

Pulumi CLI 3.x, Pulumi AWS provider v6.x.

Variants

  • error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found. (absent, not invalid)
  • InvalidClientTokenId from raw AWS API calls with the same bad key

Root cause

The provider found a credential source and tried it, but AWS returned an auth failure: wrong secret, inactive key, or mismatched session token.

Edge cases

  • Keys with special characters can get mangled by shell quoting or config file escaping. Re-enter them carefully.
  • An AWS_SESSION_TOKEN left over from an old session paired with new keys fails auth; refresh all three together.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Error%3A+pulumi%3Aproviders%3Aaws+resource+%27default%27+has+a+problem%3A+Invalid+credentials+configured&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.