VectleSkillsAn error occurred (InvalidClientTokenId): The security token included in the request is invalid

An error occurred (InvalidClientTokenId): The security token included in the request is invalid

Export

Fixes the AWS CLI InvalidClientTokenId error, meaning the access key is wrong, revoked, or belongs to a different account. Use when the error says 'The security token included in the request is invalid'. The fix is re-entering correct credentials, not refreshing a session. Not for ExpiredToken.

Your access key is wrong, deleted, or from a different account. Re-enter credentials with aws configure --profile my-profile (or regenerate the key pair in the IAM console first if the key was deleted or deactivated). This is not a session expiry, so aws sso login alone will not help unless you are on SSO.

An error occurred (InvalidClientTokenId) when calling the ListBuckets operation: The security token included in the request is invalid.

Fix

  1. Confirm which identity is actually being used:
   aws sts get-caller-identity --profile my-profile

Expected on success: your UserId, Account, Arn. If this fails, the credentials for that profile are bad.

  1. Check the obvious: open ~/.aws/credentials and look for copy/paste damage (trailing spaces, truncated keys, keys pasted into the wrong profile section).
  1. If the key was deleted or deactivated in IAM, create a fresh access key pair in the IAM console, then:
   aws configure --profile my-profile

Paste the new key ID and secret when prompted. Expected: aws sts get-caller-identity --profile my-profile succeeds.

  1. If you are on SSO rather than static keys, re-authenticate instead:
   aws sso login --profile my-profile

When this applies

  • The error is (InvalidClientTokenId) with The security token included in the request is invalid.
  • Commands worked before and broke after a key rotation, or never worked with these keys.

When it does NOT apply

  • ExpiredToken: the key is fine, the temporary session lapsed. Refresh the session.
  • SignatureDoesNotMatch: the secret is wrong but the key ID exists. Re-enter the secret carefully.
  • AccessDenied: credentials are valid, permissions are missing.

Compatibility

  • AWS CLI v1 and v2.

Why it happens

AWS cannot find the access key ID in its records for the target account. Usual causes: the key was deleted or deactivated, it belongs to a different account than the one being called, or it was mistyped during aws configure.

Edge cases

  • AWS_ACCESS_KEY_ID env vars override the credentials file; a stale exported key produces this error even with a correct file. Check env | grep AWS_.
  • Keys are per-account: a key from account A used against account B resources fails this way.
  • After aws configure, old sessions cached in ~/.aws/cli/cache can linger; clear the cache if the error persists with fresh keys.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=An+error+occurred+%28InvalidClientTokenId%29%3A+The+security+token+included+in+the+request+is+invalid&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.