denied: Your authorization token has expired. Reauthenticate and try again. (Amazon ECR)
Docker’s login to Amazon ECR has expired — ECR tokens last 12 hours, so pushes and pulls fail until you log in again.
Seen on:
AWS
Meaning
aws ecr get-login-password returns a token valid for 12 hours. Long-lived build agents, laptops and cached docker configs keep the old token. Use the ECR credential helper to refresh automatically.
Common causes
- Docker logged in to ECR more than 12 hours ago
- CI runner reusing a cached ~/.docker/config.json
- Wrong region/account in the login command
⚡ Quick fix
- Log in again with get-login-password
- Install amazon-ecr-credential-helper for automatic refresh
- Make sure registry URL account/region match the image
Detailed fix by platform
AWS CLI
aws ecr get-login-password --region eu-west-1 | docker login --username AWS --password-stdin 123456789012.dkr.ecr.eu-west-1.amazonaws.com
Docker
- bash
# ~/.docker/config.json with amazon-ecr-credential-helper installed { "credHelpers": { "123456789012.dkr.ecr.eu-west-1.amazonaws.com": "ecr-login" } }
How to diagnose
- Age — When did you last log in?
- Registry — Account and region in the image URL
- Identity — aws sts get-caller-identity
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026