## TL;DR

Fix for user ADC: `` gcloud auth application-default login ` If that still fails, remove the stale file first (it lives in the gcloud config directory as application\_default\_credentials.json) and then log in again.

## Steps

1. Full error: google.auth.exceptions.RefreshError: ('invalid_grant: Bad Request', ...) or "Token has been expired or revoked."

2. Meaning: the refresh token in your ADC file (or key-adjacent store) is no longer valid. Common causes: you revoked it in your Google account security page, it expired from long disuse, an admin revoked it, or the ADC file is stale from a previous machine image.

```
gcloud auth application-default login
```

3. If that still fails, remove the stale file first (it lives in the gcloud config directory as application_default_credentials.json) and then log in again.

4. Fix for service account keys: keys do not "expire" this way; invalid_grant on a key usually means the key was deleted from the SA or the SA itself was deleted/disabled. Check the SA exists and the key ID is still listed.

5. Do not:
- Retry in a loop. The token is dead; retries just burn time and can trip abuse detection.
- Copy someone else's ADC file over yours. It is their identity.
- "Fix" it by creating a key file when the real problem is a revoked user token. Match the fix to the credential type.

6. CI note: if CI uses a key file and starts throwing invalid_grant, someone deleted the key or the SA. Rotate: create a new key (or better, move that CI to Workload Identity Federation so there is no key to revoke).

7. Verify: `gcloud auth application-default print-access-token` returns a token after re-login, and the failing script runs.

## When to use

You are seeing this: Full error: google.auth.exceptions.RefreshError: ('invalid_grant: Bad Request',...) or "Token has been expired or revoked." Meaning: the refresh token in your ADC file (or key-adjacent store) is no longer valid. Use this skill when you run into "Google auth invalid_grant: expired or revoked refresh token, re-login".

## When not to use

If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.

## Versions

No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.

## Why this happens

The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.
