# Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID

## TL;DR
Pulumi's AWS provider does not handle IAM roles that require an MFA device the way the AWS CLI does. If your profile chains to a role with `mfa_serial`, authenticate first with the AWS CLI (`aws sts assume-role` with your MFA code), export the temporary credentials, and point Pulumi at them.

## The error

```
Error: invocation of aws:index/getCallerIdentity:getCallerIdentity returned an error: unable to discover AWS AccessKeyID and/or SecretAccessKey - see https://pulumi.io/install/aws.html for details on configuration
```

## Fix it

1. Confirm your profile needs MFA: check `~/.aws/config` for `mfa_serial` under the profile you set as `aws:profile`.
   - Success check: you see the MFA serial and a `role_arn` with `source_profile`.
2. Assume the role manually with an MFA code: `aws sts assume-role --role-arn [role arn] --role-session-name pulumi --serial-number [mfa arn] --token-code [code] --profile [source profile]`.
   - Success check: the command returns temporary `AccessKeyId`, `SecretAccessKey`, and `SessionToken`.
3. Export the three values as `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, and `AWS_SESSION_TOKEN`, then run `pulumi preview` without `aws:profile` set.
   - Success check: the `getCallerIdentity` invocation succeeds and the preview renders.
4. For a durable setup, switch to Pulumi ESC with AWS OIDC dynamic credentials instead of MFA-chained profiles.
   - Success check: clean-shell `pulumi up` works with no static credentials.

## When to use this
You hit this with `aws:profile` pointing at a profile that assumes a role through an MFA device, where `aws --profile [name] ec2 describe-instances` works (it prompts for MFA) but Pulumi fails.

## When NOT to use this
Do not use this for plain missing credentials or expired SSO tokens. This is specifically the MFA role-assumption gap.

## Compatibility
Pulumi CLI 3.x, Pulumi AWS provider v6.x. The behavior difference vs the AWS CLI is long-standing.

## Variants
- `error: unable to discover AWS AccessKeyID and/or SecretAccessKey` on a profile with `role_arn` but no MFA
- Pulumi hanging when the session token from a manual assume-role expires (re-export fresh credentials)

## Root cause
The AWS CLI prompts for an MFA code when a profile chains to an MFA-protected role. Pulumi's provider never prompts, so credential discovery silently finds nothing and the `getCallerIdentity` data source invocation fails.

## Edge cases
- Temporary credentials expire. When the session token expires Pulumi can hang rather than error clearly; re-export fresh ones.
- `aws:skipCredentialsValidation` does not bypass this; the failure happens during credential discovery, not validation.
