# Error: ExpiredToken -  The security token included in the request is expired

## TL;DR
Your temporary AWS credentials expired. Generate a fresh set (re-run `aws sso login`, re-assume the role, or refresh your session token), export the new values, and re-run Pulumi.

## The error

```
ExpiredToken -  The security token included in the request is expired
```

## Fix it

1. Check which credentials Pulumi is using: `aws sts get-caller-identity` in the same shell.
   - Success check: if this fails with ExpiredToken too, the problem is the credentials, not Pulumi.
2. Refresh them the way you got them: `aws sso login` for SSO, or re-run your `aws sts assume-role` / `get-session-token` call for manual temporary keys.
   - Success check: `aws sts get-caller-identity` succeeds again.
3. Export the fresh `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, and `AWS_SESSION_TOKEN`, then re-run `pulumi up`.
   - Success check: the provider authenticates and the update proceeds.
4. If this happens mid-run on long applies, switch to longer-lived auth (SSO with auto-refresh or Pulumi ESC OIDC) so tokens do not die halfway through.
   - Success check: multi-minute applies stop failing partway.

## When to use this
You hit this with temporary AWS credentials (SSO, assumed roles, session tokens) that worked earlier and then expired.

## When NOT to use this
Do not use this for `No valid credential sources found` (nothing configured) or for static IAM user keys (those do not expire; check the key is correct and active instead).

## Compatibility
Pulumi CLI 3.x, Pulumi AWS provider v6.x. The ExpiredToken text comes from AWS STS, not Pulumi.

## Variants
- `error: pulumi:providers:aws resource 'default' has a problem: ExpiredToken -  The security token included in the request is expired`
- The same text surfacing from `aws` CLI calls before Pulumi is even involved

## Root cause
Temporary AWS credentials carry an expiry. Anything cached past it (environment variables in an old shell, a stale SSO token, an assumed-role session) fails every AWS call with ExpiredToken until refreshed.

## Edge cases
- A very long `pulumi up` can outlive the token it started with. Prefer refreshable auth for long runs.
- `AWS_SESSION_TOKEN` from a *different* role than the key pair produces confusing auth failures; refresh all three together.
