# Error: pulumi:providers:aws resource 'default' has a problem: Failed to refresh cached SSO credentials

## TL;DR
Your cached AWS SSO token expired. Run `aws sso login` (with `--profile [profile]` if you use one), then re-run `pulumi preview`. For CI or long-lived setups, move to Pulumi ESC with AWS OIDC dynamic credentials.

## The error

```
Diagnostics:
  pulumi:providers:aws (default):
    error: pulumi:providers:aws resource 'default' has a problem: Failed to refresh cached SSO credentials.
    Please refresh SSO login.
```

## Fix it

1. Re-authenticate: `aws sso login` (or `aws sso login --profile [profile]`).
   - Success check: the browser flow completes and the CLI reports a successful login.
2. Verify the refresh worked: `aws sts get-caller-identity --profile [profile]`.
   - Success check: it prints your identity instead of an SSO error.
3. Re-run `pulumi preview` or `pulumi up`.
   - Success check: the provider configures and the operation proceeds.
4. If this keeps recurring in automation, replace SSO-cache auth with Pulumi ESC dynamic credentials via AWS OIDC.
   - Success check: unattended runs stop failing on SSO expiry.

## When to use this
You hit this on a stack that used to work with AWS SSO, and the only thing that changed is time passing.

## When NOT to use this
Do not use this for `No valid credential sources found` (nothing configured) or `ExpiredToken` on manually exported session keys (refresh those keys instead).

## Compatibility
Pulumi CLI 3.x, Pulumi AWS provider v6.x, AWS CLI v2 with SSO configured.

## Variants
- `error: pulumi:providers:aws resource 'provider' has a problem: Failed to refresh cached SSO credentials.`
- `Unable to locate credentials` (bare; check how the project authenticates before guessing)

## Root cause
AWS SSO tokens are short-lived. The provider reads the SSO token cache written by `aws sso login`; once it expires, refresh fails and provider configuration errors out. Pulumi cannot trigger the interactive SSO flow itself.

## Edge cases
- Multiple profiles: make sure you log in to the profile your stack actually uses (`aws:profile` in stack config).
- In containers or CI there is no browser for the SSO flow. Use OIDC or static credentials there.
