ECR token expired ☁️ AWS

denied: Your authorization token has expired. Reauthenticate and try again. (Amazon ECR)

Docker’s login to Amazon ECR has expired — ECR tokens last 12 hours, so pushes and pulls fail until you log in again.

Seen on: AWS

Meaning

aws ecr get-login-password returns a token valid for 12 hours. Long-lived build agents, laptops and cached docker configs keep the old token. Use the ECR credential helper to refresh automatically.

Common causes

  • Docker logged in to ECR more than 12 hours ago
  • CI runner reusing a cached ~/.docker/config.json
  • Wrong region/account in the login command

⚡ Quick fix

  1. Log in again with get-login-password
  2. Install amazon-ecr-credential-helper for automatic refresh
  3. Make sure registry URL account/region match the image

Detailed fix by platform

AWS CLI

  1. aws ecr get-login-password --region eu-west-1 | docker login --username AWS --password-stdin 123456789012.dkr.ecr.eu-west-1.amazonaws.com

Docker

  1. bash
    # ~/.docker/config.json with amazon-ecr-credential-helper installed
    { "credHelpers": { "123456789012.dkr.ecr.eu-west-1.amazonaws.com": "ecr-login" } }

How to diagnose

  1. Age — When did you last log in?
  2. Registry — Account and region in the image URL
  3. Identity — aws sts get-caller-identity

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.