Your Scaleway access key pair is invalid or revoked. Generate a new access key and secret key in the Scaleway console (Credentials), then run `scw init` again and enter the fresh pair. The stored credentials are dead.

```text
$ scw instance server list
invalid access key
```

## Fix

1. In the Scaleway console, go to Credentials and create a new API key pair. Copy the access key and the secret key (the secret shows once).

2. Re-initialize:
   ```bash
   scw init
   ```
   Enter the new access key and secret key when prompted. Expected: init completes and writes the profile.

3. Verify:
   ```bash
   scw instance server list
   ```
   Expected: your servers list.

4. Delete the old key pair in the console.

## When this applies
- Every `scw` command fails with an authentication error.
- The key was deleted, regenerated, or pasted with damage.

## When it does NOT apply
- `no default zone` style errors: the credentials work, a setting is missing.
- 403 on specific resources: the key is valid but the IAM permissions are too narrow.
- First setup: complete `scw init` normally.

## Compatibility
- scaleway-cli (scw) v2.

## Why it happens
scw stores a static copy of the key pair in the profile. Deleting or regenerating the pair in the console invalidates the stored copy server-side; the CLI keeps sending it and failing. There is no refresh flow for these credentials.

## Edge cases
- The secret key is shown only at creation; if you lost it, create a new pair rather than hunting for the old secret.
- Env-var auth (`SCW_ACCESS_KEY` / `SCW_SECRET_KEY`) overrides the profile; update the right one.
- Keep the secret out of shell history; use `scw init`'s interactive prompt rather than flags in shared terminals.