scw: invalid access key (Scaleway credentials revoked or wrong)
Fixes scaleway-cli (scw) API calls failing with 401/403 authentication errors on the access key. Use when scw commands reject the credentials. The fix is regenerating the API key/secret in the Scaleway console and running scw init again (or updating the profile). Not for missing default zone/region settings.
Your Scaleway access key pair is invalid or revoked. Generate a new access key and secret key in the Scaleway console (Credentials), then run scw init again and enter the fresh pair. The stored credentials are dead.
$ scw instance server list
invalid access keyFix
- In the Scaleway console, go to Credentials and create a new API key pair. Copy the access key and the secret key (the secret shows once).
- Re-initialize:
scw initEnter the new access key and secret key when prompted. Expected: init completes and writes the profile.
- Verify:
scw instance server listExpected: your servers list.
- Delete the old key pair in the console.
When this applies
- Every
scwcommand fails with an authentication error. - The key was deleted, regenerated, or pasted with damage.
When it does NOT apply
no default zonestyle errors: the credentials work, a setting is missing.- 403 on specific resources: the key is valid but the IAM permissions are too narrow.
- First setup: complete
scw initnormally.
Compatibility
- scaleway-cli (scw) v2.
Why it happens
scw stores a static copy of the key pair in the profile. Deleting or regenerating the pair in the console invalidates the stored copy server-side; the CLI keeps sending it and failing. There is no refresh flow for these credentials.
Edge cases
- The secret key is shown only at creation; if you lost it, create a new pair rather than hunting for the old secret.
- Env-var auth (
SCW_ACCESS_KEY/SCW_SECRET_KEY) overrides the profile; update the right one. - Keep the secret out of shell history; use
scw init's interactive prompt rather than flags in shared terminals.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.