TL;DR: AWS does not recognize your access key at all. The usual cause is a typo, a revoked key, or credentials pasted with stray whitespace. Regenerate the key pair in IAM (or re-export the session token) and set the values again carefully.

```text
An error occurred (InvalidClientTokenId) when calling the ListBuckets operation: The security token included in the request is invalid.
```

## Fix it

1. Inspect the configured values for stray whitespace or quotes: aws configure list shows the key id with masked secret; re-enter both by hand rather than pasting. Expected: no leading/trailing spaces.
2. In the IAM console, check the access key status. If it is inactive or deleted, create a new key pair. Expected: a fresh access key id and secret.
3. If you use temporary credentials, make sure you export all three: AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_SESSION_TOKEN. A missing session token causes exactly this error. Expected: env | grep AWS shows all three.
4. Retry with `aws sts get-caller-identity`. Expected: your ARN, not an error.

## When this applies
- The error code is InvalidClientTokenId, any operation.
- You recently rotated keys or switched accounts.

## When it doesn't
- Error is SignatureDoesNotMatch: the key id is fine but the secret is wrong.
- Error is ExpiredToken -  the session token lapsed; refresh it instead.

## Compatibility
- botocore/boto3 any version; AWS CLI v1/v2.

## Why it happens
AWS looks up the access key id first, before checking the signature. An unknown, deleted, or whitespace-corrupted key id fails at lookup time, which is why the message says the token is invalid rather than the signature.

## Edge cases
- Keys copied from the console CSV sometimes pick up a trailing space; always trim.
- Multiple profiles: make sure the profile your code uses is the one you fixed (AWS_PROFILE or boto3 Session(profile_name=...)).
- Old keys cached in ~/.aws/credentials under a different profile name.
