## TL;DR

InvalidClientTokenId means the access key in the request does not exist. After a rotation, something is still using the old, now-deleted key. Find every place the old key was configured and point it at the new one.

## Error

```text
"InvalidClientTokenId" after aws key rotation
```

## Steps

1. Identify which key is failing: the error follows the caller, so check the credentials file, env, or IAM role of the failing process. Expected: you find the stale key identifier.
2. Compare it against the current keys on the IAM user: `aws iam list-access-keys --user-name [user]`. Expected: the failing key is absent (deleted) or inactive.
3. Update the failing caller with the new key pair. Expected: the caller uses the current key.
4. Search for other copies: CI secrets, app config, and scripts often each hold their own copy. Expected: a complete list of places the old key lived.
5. Delete or deactivate the old key only after every caller is moved. Expected: no caller can regress to the dead key.

## When to use

- AWS API calls fail with InvalidClientTokenId after rotating an IAM user key.
- You need a checklist for finding stale key copies.

## When not to use

- `ExpiredToken` (session token issue, not a deleted key).
- `SignatureDoesNotMatch` (wrong secret, not a missing key).

## Tool compatibility

- AWS IAM user access keys; CLI, SDKs, and CI callers.

## Variant phrasings

### The security token included in the request is invalid

Often the same stale-key situation.

### AWS key not recognized after rotation

Identical handling.

## Why it happens

Rotations create a new key before deleting the old, but every copy of the old key (files, env, CI, docs) must be updated by hand or automation, and missed copies fail.

## Edge cases

- Keys embedded in AMIs or container images keep failing until the image is rebuilt.
- Third-party integrations holding the old key fail on their schedule, not yours.
- Deleting the old key before the cutover is complete turns a warning into an outage.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_wP9X6nDrVP6xmhJTu8urqQ
