Unable to locate credentials. You can configure credentials by running 'aws configure'
Fixes the AWS CLI error Unable to locate credentials by walking the credential chain in order: env vars, shared credentials file, SSO, instance profile. Use when any aws command fails with this error on a machine that should be authenticated. Not for InvalidClientTokenId, which is a bad key, or AccessDenied, which is a missing IAM permission.
Unable to locate credentials. You can configure credentials by running 'aws configure'
TL;DR: the CLI found no credentials anywhere it looks. Run aws configure and enter your access key pair, or if your org uses SSO run aws sso login --profile [profile]. Nine times out of ten the fix is either never having run aws configure, or AWS_PROFILE pointing at a profile that doesnt exist.
Unable to locate credentials. You can configure credentials by running "aws configure".Steps
- Confirm the failure:
aws sts get-caller-identityExpected on success: JSON with UserId, Account, and Arn. If it errors the same way, keep going.
- Check which profile is active and where values come from:
aws configure listExpected: shows the profile name and the source of each value (env, config file, or none).
- Set credentials. Static keys:
aws configureExpected: prompts for AWS Access Key ID, AWS Secret Access Key, region, and output format. SSO instead:
aws sso login --profile [your profile]Expected: browser opens for SSO, then the CLI reports a successful login.
- Verify:
aws sts get-caller-identityExpected: returns your identity with no error.
When this applies
- any aws command fails with the exact
Unable to locate credentialserror - fresh install where
aws configurewas never run - new shell where the env vars were not exported, or AWS_PROFILE names a profile with no keys
- SSO session expired
When it doesnt
InvalidClientTokenId: The security token included in the request is invalid— the key is deleted, deactivated, or mistyped; recreate it in IAM and re-run aws configureExpiredToken— refresh SSO or the temporary credentialsAccessDeniedon a specific call — identity is fine, the IAM policy is missing the action
Compatibility
AWS CLI v2 (v1 from distro repos is retired). Same chain on Linux, macOS, and Windows.
Why it happens
The CLI checks credentials in a fixed order: environment variables, the shared credentials file, SSO cache, then container or instance metadata. If none yields a key it raises this instead of guessing. The classic traps: AWS_PROFILE pointing nowhere, env vars set in one terminal but not another, and an SSO login that expired silently.
Edge cases
~/.aws/credentialsstores the secret in plain text: chmod 600 it and never commit it- a typo in the env var name is a top cause — it must be exactly AWSSECRETACCESS_KEY
- system clock skew shows up as SignatureDoesNotMatch, not this error
- in containers and EC2, prefer IAM roles over static keys so there is nothing to locate
Find this skill again
curl -s 'https://vectle.com/api/v1/search?q=aws+unable+to+locate+credentials'Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.