AWS: ExpiredToken — The security token included in the request is expired
Temporary AWS credentials (STS/SSO/assumed role) have expired.
Seen on:
AWS
Meaning
Session credentials last from 15 minutes to 12 hours. Once expired, every call fails until you refresh them.
Common causes
- SSO session expired
- Assumed-role credentials exported as env vars and not refreshed
- Long-running scripts outliving their session
- Stale
AWS_SESSION_TOKENoverriding a profile
⚡ Quick fix
aws sso login --profile <name>- Unset stale env vars:
unset AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY AWS_SESSION_TOKEN - Use SDK credential providers that refresh automatically instead of copying keys
Detailed fix by platform
AWS
- On EC2/ECS/Lambda, rely on the instance/task role — the SDK refreshes credentials automatically.
How to diagnose
- Source — Where do credentials come from (env, profile, role)?
- Expiry — When were they issued?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026