# Unable to locate credentials. You can configure credentials by running 'aws configure'

TL;DR: the CLI found no credentials anywhere it looks. Run `aws configure` and enter your access key pair, or if your org uses SSO run `aws sso login --profile [profile]`. Nine times out of ten the fix is either never having run aws configure, or AWS_PROFILE pointing at a profile that doesnt exist.

```text
Unable to locate credentials. You can configure credentials by running "aws configure".
```

## Steps

1. Confirm the failure:

```bash
aws sts get-caller-identity
```

Expected on success: JSON with UserId, Account, and Arn. If it errors the same way, keep going.

2. Check which profile is active and where values come from:

```bash
aws configure list
```

Expected: shows the profile name and the source of each value (env, config file, or none).

3. Set credentials. Static keys:

```bash
aws configure
```

Expected: prompts for AWS Access Key ID, AWS Secret Access Key, region, and output format. SSO instead:

```bash
aws sso login --profile [your profile]
```

Expected: browser opens for SSO, then the CLI reports a successful login.

4. Verify:

```bash
aws sts get-caller-identity
```

Expected: returns your identity with no error.

## When this applies

- any aws command fails with the exact `Unable to locate credentials` error
- fresh install where `aws configure` was never run
- new shell where the env vars were not exported, or AWS_PROFILE names a profile with no keys
- SSO session expired

## When it doesnt

- `InvalidClientTokenId: The security token included in the request is invalid` — the key is deleted, deactivated, or mistyped; recreate it in IAM and re-run aws configure
- `ExpiredToken` — refresh SSO or the temporary credentials
- `AccessDenied` on a specific call — identity is fine, the IAM policy is missing the action

## Compatibility

AWS CLI v2 (v1 from distro repos is retired). Same chain on Linux, macOS, and Windows.

## Why it happens

The CLI checks credentials in a fixed order: environment variables, the shared credentials file, SSO cache, then container or instance metadata. If none yields a key it raises this instead of guessing. The classic traps: AWS_PROFILE pointing nowhere, env vars set in one terminal but not another, and an SSO login that expired silently.

## Edge cases

- `~/.aws/credentials` stores the secret in plain text: chmod 600 it and never commit it
- a typo in the env var name is a top cause — it must be exactly AWS_SECRET_ACCESS_KEY
- system clock skew shows up as SignatureDoesNotMatch, not this error
- in containers and EC2, prefer IAM roles over static keys so there is nothing to locate

## Find this skill again

```bash
curl -s 'https://vectle.com/api/v1/search?q=aws+unable+to+locate+credentials'
```
