VectleSkillsGoogle auth invalid_grant: expired or revoked refresh token, re-login

Google auth invalid_grant: expired or revoked refresh token, re-login

Export

Shows how to fix google auth invalid_grant: expired or revoked refresh token, re-login. Use it when you hit this exact problem. Skip it when your error message or symptom looks different.

TL;DR

Fix for user ADC: ` gcloud auth application-default login If that still fails, remove the stale file first (it lives in the gcloud config directory as application\default\credentials.json) and then log in again.

Steps

  1. Full error: google.auth.exceptions.RefreshError: ('invalid_grant: Bad Request', ...) or "Token has been expired or revoked."
  1. Meaning: the refresh token in your ADC file (or key-adjacent store) is no longer valid. Common causes: you revoked it in your Google account security page, it expired from long disuse, an admin revoked it, or the ADC file is stale from a previous machine image.
gcloud auth application-default login
  1. If that still fails, remove the stale file first (it lives in the gcloud config directory as applicationdefaultcredentials.json) and then log in again.
  1. Fix for service account keys: keys do not "expire" this way; invalid_grant on a key usually means the key was deleted from the SA or the SA itself was deleted/disabled. Check the SA exists and the key ID is still listed.
  1. Do not:
  • Retry in a loop. The token is dead; retries just burn time and can trip abuse detection.
  • Copy someone else's ADC file over yours. It is their identity.
  • "Fix" it by creating a key file when the real problem is a revoked user token. Match the fix to the credential type.
  1. CI note: if CI uses a key file and starts throwing invalid_grant, someone deleted the key or the SA. Rotate: create a new key (or better, move that CI to Workload Identity Federation so there is no key to revoke).
  1. Verify: gcloud auth application-default print-access-token returns a token after re-login, and the failing script runs.

When to use

You are seeing this: Full error: google.auth.exceptions.RefreshError: ('invalidgrant: Bad Request',...) or "Token has been expired or revoked." Meaning: the refresh token in your ADC file (or key-adjacent store) is no longer valid. Use this skill when you run into "Google auth invalidgrant: expired or revoked refresh token, re-login".

When not to use

If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.

Versions

No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.

Why this happens

The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Google+auth+invalid_grant%3A+expired+or+revoked+refresh+token%2C+re-login&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.