Error: Invalid token (Vercel CLI)
Fixes Vercel CLI failing with Error: Invalid token. Use when vercel commands that used to work start failing because the stored token expired or was revoked, including CI runs with a stale VERCEL_TOKEN. Generates a fresh token and re-authenticates. Not for Error: No token found, which means never logged in, or team-not-found errors, which are wrong org ids.
Error: Invalid token (Vercel CLI)
TL;DR: your Vercel token expired or was revoked. Make a new one at vercel.com/account/tokens, then either run vercel login or set the new value as VERCEL_TOKEN. Verify with vercel whoami.
Error: Invalid tokenSteps
- Confirm the symptom:
vercel whoamiExpected on success: your username. Error: Invalid token means the stored credential is dead.
- Generate a fresh token from the Vercel dashboard under Settings → Tokens → Create. Give it full access if the CLI needs to deploy.
- Use it. Interactive:
vercel loginExpected: follow the prompts until it reports you are logged in. Headless or CI: set VERCEL_TOKEN in the environment to the new value. If you are unsure the token is right, test one call with it inline first: vercel list --token [your token].
- Verify:
vercel whoamiExpected: prints your account name.
When this applies
- the exact
Error: Invalid tokenon commands that used to work - CI failures right after someone rotated or revoked tokens in the dashboard
- a token copied from an old machine that has since been regenerated
When it doesnt
Error: No token found— runvercel login; there is no token at allError: Team not found— wrong VERCELORGID, that is org config not auth- fetch or network failures — that is connectivity, not credentials
Compatibility
Vercel CLI 28 and up.
Why it happens
The CLI stores one long-lived token, in the global config or in VERCEL_TOKEN. Vercel invalidates it on expiry, manual revocation, or regeneration — and the CLI has no refresh flow, so every call fails until you replace the token.
Edge cases
- tokens for CI should be short-lived (90 days) and rotated on a schedule
- never commit the token — it is a full-access credential; store it as a CI secret
- if the team enforces SSO, the interactive login must go through the SSO flow or the new token wont be accepted
Find this skill again
curl -s 'https://vectle.com/api/v1/search?q=vercel+cli+error+invalid+token'Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.