Your stored refresh token is dead (revoked or expired). Run `gcloud auth revoke` for the account, then `gcloud auth login` fresh. Retrying the same command will keep failing because the CLI cannot mint new access tokens from a dead refresh token.

```text
ERROR: (gcloud.auth.login) There was a problem refreshing your current auth tokens: ('invalid_grant: Token has been expired or revoked.')
```

## Fix

1. Revoke the dead credential:
   ```bash
   gcloud auth revoke [account]
   ```
   Expected: `Revoked credentials for [[account]]`.

2. Log in fresh:
   ```bash
   gcloud auth login
   ```
   Expected: full browser consent flow; do not reuse an old approval, complete it end to end.

3. Verify the token refreshes:
   ```bash
   gcloud auth print-access-token
   ```
   Expected: a token prints with no error.

4. If it was ADC (application code) rather than the CLI, refresh that store instead:
   ```bash
   gcloud auth application-default login
   ```

## When this applies
- `invalid_grant: Token has been expired or revoked` on `gcloud auth login`, `print-access-token`, or any command.
- After removing Cloud SDK access at myaccount.google.com permissions, or an admin session revoke.

## When it does NOT apply
- First-ever login failing: check the browser completes the flow and the machine clock is correct.
- `Your current active account does not have any valid credentials`: nothing is stored at all; just log in.
- Service-account key errors: keys do not use refresh tokens; check the key file instead.

## Compatibility
- Google Cloud SDK (gcloud) all recent versions; affects user-account OAuth only.

## Why it happens
User-account auth relies on a long-lived refresh token to mint 60-minute access tokens. Google-side revocation (user removed third-party access, admin reset sessions, token lifetime policy) kills the refresh token, and the CLI's next refresh attempt returns `invalid_grant`. Nothing client-side can resurrect it; only a new consent flow mints a replacement.

## Edge cases
- If this recurs quickly, check whether a security policy auto-revokes OAuth grants (common on managed corporate Google Workspace).
- Service accounts activated with `gcloud auth activate-service-account` are immune to this; consider one for automation.
- `gcloud auth application-default login` writes a separate ADC file with its own refresh token; fix the right store.