PartialCredentialsError: Partial credentials found in env, missing: AWS_SECRET_ACCESS_KEY
Fixes AWS SDK setups where only half the credential pair is set. Use when botocore raises PartialCredentialsError naming a missing piece. Not for fully missing credentials (NoCredentialsError).
TL;DR: You set AWSACCESSKEYID but not AWSSECRETACCESSKEY, and botocore refuses to mix half a pair from env with the rest from a file. Set the missing piece in the same place as the rest, or clear the env vars and use a credentials file instead.
PartialCredentialsError: Partial credentials found in env, missing: AWS_SECRET_ACCESS_KEYFix it
- List what is set: env | grep AWS. Expected: you will see AWSACCESSKEYID without AWSSECRETACCESS_KEY (or vice versa).
- Set the missing one in the same shell/profile: export AWSSECRETACCESSKEY to your secret access key. Using temporary credentials? Also export AWSSESSIONTOKEN. Expected: env | grep AWS shows the full set.
- Or go the other way: unset the AWS_ env vars and put the full pair in ~/.aws/credentials via aws configure. Expected: aws sts get-caller-identity succeeds.
- Never split the pair across sources; botocore picks one source and requires it complete.
When this applies
- The error is PartialCredentialsError and names the missing piece.
When it doesn't
- Nothing is set at all: that is NoCredentialsError, a different fix.
- All three are set and it still fails: check for typos or an expired session token.
Compatibility
- botocore/boto3 any version.
Why it happens
Credential resolution is per-source and all-or-nothing: env vars beat the credentials file, but only if they form a complete set. A lone AWSACCESSKEY_ID blocks the file from being consulted, then fails completeness.
Edge cases
- CI systems sometimes inject only the key id as a secret; add the secret too.
- AWSSESSIONTOKEN from an old session lingers after the key id was rotated; unset all three and start fresh.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.