Error: ExpiredToken - The security token included in the request is expired
Fixes Pulumi failing on AWS temporary credentials that expired. For engineers using short-lived AWS session keys whose stack breaks with ExpiredToken, covering key rotation and moving to longer-lived auth.
Error: ExpiredToken - The security token included in the request is expired
TL;DR
Your temporary AWS credentials expired. Generate a fresh set (re-run aws sso login, re-assume the role, or refresh your session token), export the new values, and re-run Pulumi.
The error
ExpiredToken - The security token included in the request is expiredFix it
- Check which credentials Pulumi is using:
aws sts get-caller-identityin the same shell.
- Success check: if this fails with ExpiredToken too, the problem is the credentials, not Pulumi.
- Refresh them the way you got them:
aws sso loginfor SSO, or re-run youraws sts assume-role/get-session-tokencall for manual temporary keys.
- Success check:
aws sts get-caller-identitysucceeds again.
- Export the fresh
AWS_ACCESS_KEY_ID,AWS_SECRET_ACCESS_KEY, andAWS_SESSION_TOKEN, then re-runpulumi up.
- Success check: the provider authenticates and the update proceeds.
- If this happens mid-run on long applies, switch to longer-lived auth (SSO with auto-refresh or Pulumi ESC OIDC) so tokens do not die halfway through.
- Success check: multi-minute applies stop failing partway.
When to use this
You hit this with temporary AWS credentials (SSO, assumed roles, session tokens) that worked earlier and then expired.
When NOT to use this
Do not use this for No valid credential sources found (nothing configured) or for static IAM user keys (those do not expire; check the key is correct and active instead).
Compatibility
Pulumi CLI 3.x, Pulumi AWS provider v6.x. The ExpiredToken text comes from AWS STS, not Pulumi.
Variants
error: pulumi:providers:aws resource 'default' has a problem: ExpiredToken - The security token included in the request is expired- The same text surfacing from
awsCLI calls before Pulumi is even involved
Root cause
Temporary AWS credentials carry an expiry. Anything cached past it (environment variables in an old shell, a stale SSO token, an assumed-role session) fails every AWS call with ExpiredToken until refreshed.
Edge cases
- A very long
pulumi upcan outlive the token it started with. Prefer refreshable auth for long runs. AWS_SESSION_TOKENfrom a different role than the key pair produces confusing auth failures; refresh all three together.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.