# Error: pulumi:providers:aws resource 'default' has a problem: Invalid credentials configured

## TL;DR
Credentials were found but AWS rejected them. Verify with `aws sts get-caller-identity`, fix the key/secret (typo, revoked key, wrong account), and re-run. For teams, move to Pulumi ESC with AWS OIDC so there are no static keys to go stale.

## The error

```
Diagnostics:
  pulumi:providers:aws (default):
    error: pulumi:providers:aws resource 'default_6_18_2' has a problem: Invalid credentials configured.
    Please see https://www.pulumi.com/docs/intro/cloud-providers/aws/setup/ for more information about providing credentials.
```

## Fix it

1. Test the same credentials outside Pulumi: `aws sts get-caller-identity`.
   - Success check: if this fails, the credentials are bad; fix them in AWS IAM first.
2. Common causes: a typo in the secret, a deactivated or deleted access key, keys for the wrong account, or a session token paired with the wrong key.
   - Success check: a fresh key pair from IAM works in the CLI test.
3. Update wherever Pulumi reads them: `pulumi config set --secret aws:secretKey [new secret]` for stack config, or re-export the env vars.
   - Success check: `pulumi preview` passes provider configuration.
4. For a durable fix, replace static keys with Pulumi ESC dynamic credentials via AWS OIDC.
   - Success check: no static keys exist to go invalid.

## When to use this
You hit this when credentials are configured but AWS rejects them, as distinct from credentials being absent entirely.

## When NOT to use this
Do not use this for `No valid credential sources found` (nothing configured) or `ExpiredToken` (valid keys, dead session; refresh the session).

## Compatibility
Pulumi CLI 3.x, Pulumi AWS provider v6.x.

## Variants
- `error: pulumi:providers:aws resource 'default' has a problem: No valid credential sources found.` (absent, not invalid)
- `InvalidClientTokenId` from raw AWS API calls with the same bad key

## Root cause
The provider found a credential source and tried it, but AWS returned an auth failure: wrong secret, inactive key, or mismatched session token.

## Edge cases
- Keys with special characters can get mangled by shell quoting or config file escaping. Re-enter them carefully.
- An `AWS_SESSION_TOKEN` left over from an old session paired with new keys fails auth; refresh all three together.
