botocore.exceptions.NoCredentialsError: Unable to locate credentials
Fixes boto3 failing because no AWS credentials are configured in the environment. Use when any boto3 call raises NoCredentialsError. Not for invalid or expired keys (those raise different errors).
TL;DR: boto3 looked in every credential source (env vars, shared credentials file, IAM role) and found nothing. Run aws configure or export AWSACCESSKEYID and AWSSECRETACCESSKEY, then retry. If you are on EC2/Lambda/ECS, attach an IAM role instead.
botocore.exceptions.NoCredentialsError: Unable to locate credentialsFix it
- Check what boto3 sees: run
aws sts get-caller-identity. Expected on success: your account ARN. If it errors, credentials are missing or broken. - Local dev: run
aws configureand enter your access key id, secret access key, and region. Expected: ~/.aws/credentials now has a [default] profile. - Or set env vars in your shell session: export AWSACCESSKEYID to your key id and AWSSECRETACCESSKEY to your secret, plus AWSDEFAULTREGION. Expected: the sts call succeeds.
- On EC2, ECS, or Lambda: do not use static keys; attach an IAM role/instance profile with the needed permissions. Expected: boto3 picks up role credentials automatically.
When this applies
- The error is exactly NoCredentialsError: Unable to locate credentials.
- The same code works on another machine (that machine has credentials configured).
When it doesn't
- The error is InvalidClientTokenId or SignatureDoesNotMatch: credentials exist but are wrong; check the key values.
- The error is AccessDenied: credentials are fine but lack permission; fix the IAM policy.
Compatibility
- boto3/botocore any version. AWS CLI v1/v2 for the aws configure step.
Why it happens
boto3 resolves credentials through a chain: explicit args, env vars, shared credentials file, container credentials, instance metadata. NoCredentialsError means every link came up empty.
Edge cases
- PartialCredentialsError (only one of the pair set) is a different error with a different fix: set both.
- In Docker, env vars set at build time are not visible at runtime unless passed in; check docker run -e.
- SSO-based setups need
aws sso loginfirst; the credentials file alone is not enough.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.