VectleSkillsError: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID

Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID

Export

Fixes Pulumi failing on AWS profiles that use role assumption with an MFA device. For engineers using aws:profile with a role_arn and mfa_serial whose preview fails at getCallerIdentity, with workarounds for the MFA gap.

Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID

TL;DR

Pulumi's AWS provider does not handle IAM roles that require an MFA device the way the AWS CLI does. If your profile chains to a role with mfa_serial, authenticate first with the AWS CLI (aws sts assume-role with your MFA code), export the temporary credentials, and point Pulumi at them.

The error

Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID and/or SecretAccessKey - see https://pulumi.io/install/aws.html for details on configuration

Fix it

  1. Confirm your profile needs MFA: check ~/.aws/config for mfa_serial under the profile you set as aws:profile.
  • Success check: you see the MFA serial and a role_arn with source_profile.
  1. Assume the role manually with an MFA code: aws sts assume-role --role-arn [role arn] --role-session-name pulumi --serial-number [mfa arn] --token-code [code] --profile [source profile].
  • Success check: the command returns temporary AccessKeyId, SecretAccessKey, and SessionToken.
  1. Export the three values as AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_SESSION_TOKEN, then run pulumi preview without aws:profile set.
  • Success check: the getCallerIdentity invocation succeeds and the preview renders.
  1. For a durable setup, switch to Pulumi ESC with AWS OIDC dynamic credentials instead of MFA-chained profiles.
  • Success check: clean-shell pulumi up works with no static credentials.

When to use this

You hit this with aws:profile pointing at a profile that assumes a role through an MFA device, where aws --profile [name] ec2 describe-instances works (it prompts for MFA) but Pulumi fails.

When NOT to use this

Do not use this for plain missing credentials or expired SSO tokens. This is specifically the MFA role-assumption gap.

Compatibility

Pulumi CLI 3.x, Pulumi AWS provider v6.x. The behavior difference vs the AWS CLI is long-standing.

Variants

  • error: unable to discover AWS AccessKeyID and/or SecretAccessKey on a profile with role_arn but no MFA
  • Pulumi hanging when the session token from a manual assume-role expires (re-export fresh credentials)

Root cause

The AWS CLI prompts for an MFA code when a profile chains to an MFA-protected role. Pulumi's provider never prompts, so credential discovery silently finds nothing and the getCallerIdentity data source invocation fails.

Edge cases

  • Temporary credentials expire. When the session token expires Pulumi can hang rather than error clearly; re-export fresh ones.
  • aws:skipCredentialsValidation does not bypass this; the failure happens during credential discovery, not validation.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Error%3A+invocation+of+aws%3Aindex%2FgetCallerIdentity%3AgetCallerIdentity+returned+an+error%3A+unable+to+discover+AWS+AccessKeyID&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.