VectleSkillsError: ExpiredToken - The security token included in the request is expired

Error: ExpiredToken - The security token included in the request is expired

Export

Fixes Pulumi failing on AWS temporary credentials that expired. For engineers using short-lived AWS session keys whose stack breaks with ExpiredToken, covering key rotation and moving to longer-lived auth.

Error: ExpiredToken - The security token included in the request is expired

TL;DR

Your temporary AWS credentials expired. Generate a fresh set (re-run aws sso login, re-assume the role, or refresh your session token), export the new values, and re-run Pulumi.

The error

ExpiredToken -  The security token included in the request is expired

Fix it

  1. Check which credentials Pulumi is using: aws sts get-caller-identity in the same shell.
  • Success check: if this fails with ExpiredToken too, the problem is the credentials, not Pulumi.
  1. Refresh them the way you got them: aws sso login for SSO, or re-run your aws sts assume-role / get-session-token call for manual temporary keys.
  • Success check: aws sts get-caller-identity succeeds again.
  1. Export the fresh AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_SESSION_TOKEN, then re-run pulumi up.
  • Success check: the provider authenticates and the update proceeds.
  1. If this happens mid-run on long applies, switch to longer-lived auth (SSO with auto-refresh or Pulumi ESC OIDC) so tokens do not die halfway through.
  • Success check: multi-minute applies stop failing partway.

When to use this

You hit this with temporary AWS credentials (SSO, assumed roles, session tokens) that worked earlier and then expired.

When NOT to use this

Do not use this for No valid credential sources found (nothing configured) or for static IAM user keys (those do not expire; check the key is correct and active instead).

Compatibility

Pulumi CLI 3.x, Pulumi AWS provider v6.x. The ExpiredToken text comes from AWS STS, not Pulumi.

Variants

  • error: pulumi:providers:aws resource 'default' has a problem: ExpiredToken - The security token included in the request is expired
  • The same text surfacing from aws CLI calls before Pulumi is even involved

Root cause

Temporary AWS credentials carry an expiry. Anything cached past it (environment variables in an old shell, a stale SSO token, an assumed-role session) fails every AWS call with ExpiredToken until refreshed.

Edge cases

  • A very long pulumi up can outlive the token it started with. Prefer refreshable auth for long runs.
  • AWS_SESSION_TOKEN from a different role than the key pair produces confusing auth failures; refresh all three together.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Error%3A+ExpiredToken+-++The+security+token+included+in+the+request+is+expired&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.