Google auth invalid_grant: expired or revoked refresh token, re-login
Shows how to fix google auth invalid_grant: expired or revoked refresh token, re-login. Use it when you hit this exact problem. Skip it when your error message or symptom looks different.
TL;DR
Fix for user ADC: ` gcloud auth application-default login If that still fails, remove the stale file first (it lives in the gcloud config directory as application\default\credentials.json) and then log in again.
Steps
- Full error: google.auth.exceptions.RefreshError: ('invalid_grant: Bad Request', ...) or "Token has been expired or revoked."
- Meaning: the refresh token in your ADC file (or key-adjacent store) is no longer valid. Common causes: you revoked it in your Google account security page, it expired from long disuse, an admin revoked it, or the ADC file is stale from a previous machine image.
gcloud auth application-default login- If that still fails, remove the stale file first (it lives in the gcloud config directory as applicationdefaultcredentials.json) and then log in again.
- Fix for service account keys: keys do not "expire" this way; invalid_grant on a key usually means the key was deleted from the SA or the SA itself was deleted/disabled. Check the SA exists and the key ID is still listed.
- Do not:
- Retry in a loop. The token is dead; retries just burn time and can trip abuse detection.
- Copy someone else's ADC file over yours. It is their identity.
- "Fix" it by creating a key file when the real problem is a revoked user token. Match the fix to the credential type.
- CI note: if CI uses a key file and starts throwing invalid_grant, someone deleted the key or the SA. Rotate: create a new key (or better, move that CI to Workload Identity Federation so there is no key to revoke).
- Verify:
gcloud auth application-default print-access-tokenreturns a token after re-login, and the failing script runs.
When to use
You are seeing this: Full error: google.auth.exceptions.RefreshError: ('invalidgrant: Bad Request',...) or "Token has been expired or revoked." Meaning: the refresh token in your ADC file (or key-adjacent store) is no longer valid. Use this skill when you run into "Google auth invalidgrant: expired or revoked refresh token, re-login".
When not to use
If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.
Versions
No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.
Why this happens
The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.