An error occurred (InvalidClientTokenId): The security token included in the request is invalid
Fixes AWS API calls rejected because the access key id does not exist or the session token is wrong. Use when botocore raises InvalidClientTokenId. Not for AccessDenied (valid key, wrong permissions) or expired tokens.
TL;DR: AWS does not recognize your access key at all. The usual cause is a typo, a revoked key, or credentials pasted with stray whitespace. Regenerate the key pair in IAM (or re-export the session token) and set the values again carefully.
An error occurred (InvalidClientTokenId) when calling the ListBuckets operation: The security token included in the request is invalid.Fix it
- Inspect the configured values for stray whitespace or quotes: aws configure list shows the key id with masked secret; re-enter both by hand rather than pasting. Expected: no leading/trailing spaces.
- In the IAM console, check the access key status. If it is inactive or deleted, create a new key pair. Expected: a fresh access key id and secret.
- If you use temporary credentials, make sure you export all three: AWSACCESSKEYID, AWSSECRETACCESSKEY, and AWSSESSIONTOKEN. A missing session token causes exactly this error. Expected: env | grep AWS shows all three.
- Retry with
aws sts get-caller-identity. Expected: your ARN, not an error.
When this applies
- The error code is InvalidClientTokenId, any operation.
- You recently rotated keys or switched accounts.
When it doesn't
- Error is SignatureDoesNotMatch: the key id is fine but the secret is wrong.
- Error is ExpiredToken - the session token lapsed; refresh it instead.
Compatibility
- botocore/boto3 any version; AWS CLI v1/v2.
Why it happens
AWS looks up the access key id first, before checking the signature. An unknown, deleted, or whitespace-corrupted key id fails at lookup time, which is why the message says the token is invalid rather than the signature.
Edge cases
- Keys copied from the console CSV sometimes pick up a trailing space; always trim.
- Multiple profiles: make sure the profile your code uses is the one you fixed (AWSPROFILE or boto3 Session(profilename=...)).
- Old keys cached in ~/.aws/credentials under a different profile name.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.