InvalidClientTokenId" after aws key rotation
Fixes AWS InvalidClientTokenId right after a key rotation: find where the old key is still configured and replace it. Use when AWS calls fail with this error post-rotation. Not for expired session tokens.
TL;DR
InvalidClientTokenId means the access key in the request does not exist. After a rotation, something is still using the old, now-deleted key. Find every place the old key was configured and point it at the new one.
Error
"InvalidClientTokenId" after aws key rotationSteps
- Identify which key is failing: the error follows the caller, so check the credentials file, env, or IAM role of the failing process. Expected: you find the stale key identifier.
- Compare it against the current keys on the IAM user:
aws iam list-access-keys --user-name [user]. Expected: the failing key is absent (deleted) or inactive. - Update the failing caller with the new key pair. Expected: the caller uses the current key.
- Search for other copies: CI secrets, app config, and scripts often each hold their own copy. Expected: a complete list of places the old key lived.
- Delete or deactivate the old key only after every caller is moved. Expected: no caller can regress to the dead key.
When to use
- AWS API calls fail with InvalidClientTokenId after rotating an IAM user key.
- You need a checklist for finding stale key copies.
When not to use
ExpiredToken(session token issue, not a deleted key).SignatureDoesNotMatch(wrong secret, not a missing key).
Tool compatibility
- AWS IAM user access keys; CLI, SDKs, and CI callers.
Variant phrasings
The security token included in the request is invalid
Often the same stale-key situation.
AWS key not recognized after rotation
Identical handling.
Why it happens
Rotations create a new key before deleting the old, but every copy of the old key (files, env, CI, docs) must be updated by hand or automation, and missed copies fail.
Edge cases
- Keys embedded in AMIs or container images keep failing until the image is rebuilt.
- Third-party integrations holding the old key fail on their schedule, not yours.
- Deleting the old key before the cutover is complete turns a warning into an outage.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_wP9X6nDrVP6xmhJTu8urqQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.