There was a problem refreshing your current auth tokens: invalid_grant (gcloud)
Fixes the gcloud invalid_grant token error when stored OAuth tokens can no longer be refreshed. Use when gcloud reports 'There was a problem refreshing your current auth tokens' with 'Token has been expired or revoked'. The fix is revoke plus fresh login. Not for first-time login failures.
Your stored refresh token is dead (revoked or expired). Run gcloud auth revoke for the account, then gcloud auth login fresh. Retrying the same command will keep failing because the CLI cannot mint new access tokens from a dead refresh token.
ERROR: (gcloud.auth.login) There was a problem refreshing your current auth tokens: ('invalid_grant: Token has been expired or revoked.')Fix
- Revoke the dead credential:
gcloud auth revoke [account] Expected: Revoked credentials for [[account]].
- Log in fresh:
gcloud auth loginExpected: full browser consent flow; do not reuse an old approval, complete it end to end.
- Verify the token refreshes:
gcloud auth print-access-tokenExpected: a token prints with no error.
- If it was ADC (application code) rather than the CLI, refresh that store instead:
gcloud auth application-default loginWhen this applies
invalid_grant: Token has been expired or revokedongcloud auth login,print-access-token, or any command.- After removing Cloud SDK access at myaccount.google.com permissions, or an admin session revoke.
When it does NOT apply
- First-ever login failing: check the browser completes the flow and the machine clock is correct.
Your current active account does not have any valid credentials: nothing is stored at all; just log in.- Service-account key errors: keys do not use refresh tokens; check the key file instead.
Compatibility
- Google Cloud SDK (gcloud) all recent versions; affects user-account OAuth only.
Why it happens
User-account auth relies on a long-lived refresh token to mint 60-minute access tokens. Google-side revocation (user removed third-party access, admin reset sessions, token lifetime policy) kills the refresh token, and the CLI's next refresh attempt returns invalid_grant. Nothing client-side can resurrect it; only a new consent flow mints a replacement.
Edge cases
- If this recurs quickly, check whether a security policy auto-revokes OAuth grants (common on managed corporate Google Workspace).
- Service accounts activated with
gcloud auth activate-service-accountare immune to this; consider one for automation. gcloud auth application-default loginwrites a separate ADC file with its own refresh token; fix the right store.