VectleSkillsAn error occurred (ExpiredToken): The security token included in the request is expired

An error occurred (ExpiredToken): The security token included in the request is expired

Export

Fixes the AWS CLI ExpiredToken error where temporary credentials (SSO, STS, or IAM role sessions) have passed their expiration. Use when aws commands fail with 'The security token included in the request is expired'. Not for InvalidClientTokenId (wrong keys) or AccessDenied (permissions).

Your temporary AWS credentials ran out. Run aws sso login --profile your-profile to get a fresh session, then retry the command. If you are not on SSO, mint new temporary credentials (STS) or re-export fresh ones. The error is expected behavior, not a misconfiguration.

An error occurred (ExpiredToken) when calling the ListBuckets operation: The security token included in the request is expired

Fix

  1. If you use AWS IAM Identity Center (SSO), refresh the session:
   aws sso login --profile your-profile

Expected: a browser window opens, you approve, and the CLI prints Successfully logged into Start URL.

  1. Verify the fresh identity works:
   aws sts get-caller-identity --profile your-profile

Expected: JSON with your UserId, Account, and Arn. No error.

  1. If you use STS temporary credentials (not SSO), get new ones and update ~/.aws/credentials or your env vars, then retry.
  1. If ExpiredToken appears immediately after a successful aws sso login, stale environment variables are overriding your profile. Check:
   env | grep AWS_

If AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, or AWS_SESSION_TOKEN are set, unset them:

   unset AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY AWS_SESSION_TOKEN

Expected: aws sts get-caller-identity --profile your-profile now works.

When this applies

  • Any aws command fails with (ExpiredToken) and The security token included in the request is expired.
  • You use aws sso login, assumed roles, get-session-token, or EC2/ECS task roles with cached creds.

When it does NOT apply

  • InvalidClientTokenId or InvalidAccessKeyId: those mean the keys are wrong or revoked, not expired. Re-enter credentials with aws configure.
  • AccessDenied: the credentials are valid but lack permission. That is an IAM policy problem.
  • Unable to locate credentials: nothing is configured at all.

Compatibility

  • AWS CLI v2 (all recent versions). SSO flow requires CLI v2; aws configure sso is not a v1 command.

Why it happens

Temporary credentials have a fixed lifetime. SSO sessions typically last 8-12 hours, assumed-role sessions 1-12 hours depending on configuration. When the clock runs out, every API call fails with ExpiredToken until you re-authenticate. The CLI caches role credentials in ~/.aws/cli/cache, so a revoked or expired cached session can also linger there.

Edge cases

  • Clock skew: if your system clock is far off, tokens can look expired early. Sync with NTP.
  • CI jobs longer than the session duration: refresh mid-job or use a longer session duration on the role.
  • rm -r ~/.aws/cli/cache forces the CLI to drop cached role credentials and fetch fresh ones.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=An+error+occurred+%28ExpiredToken%29%3A+The+security+token+included+in+the+request+is+expired&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.