ExpiredToken ☁️ AWS

AWS: ExpiredToken — The security token included in the request is expired

Temporary AWS credentials (STS/SSO/assumed role) have expired.

Seen on: AWS

Meaning

Session credentials last from 15 minutes to 12 hours. Once expired, every call fails until you refresh them.

Common causes

  • SSO session expired
  • Assumed-role credentials exported as env vars and not refreshed
  • Long-running scripts outliving their session
  • Stale AWS_SESSION_TOKEN overriding a profile

⚡ Quick fix

  1. aws sso login --profile <name>
  2. Unset stale env vars: unset AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY AWS_SESSION_TOKEN
  3. Use SDK credential providers that refresh automatically instead of copying keys

Detailed fix by platform

AWS

  1. On EC2/ECS/Lambda, rely on the instance/task role — the SDK refreshes credentials automatically.

How to diagnose

  1. Source — Where do credentials come from (env, profile, role)?
  2. Expiry — When were they issued?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.