InvalidParameterValueException: The role defined for the function cannot be assumed by Lambda
The execution role’s trust policy doesn’t allow lambda.amazonaws.com — or the role was just created and IAM hasn’t propagated yet.
Seen on:
AWS
Meaning
Lambda assumes the execution role. Its trust policy must name the lambda.amazonaws.com service principal. Scripts that create a role and immediately create the function also hit this for a few seconds.
Common causes
- Trust policy missing lambda.amazonaws.com
- Role created seconds ago (IAM eventual consistency)
- Wrong role ARN
⚡ Quick fix
- Fix the trust policy
- Wait ~10 seconds and retry after creating a role
- Check the ARN
Detailed fix by platform
IAM
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "lambda.amazonaws.com" }, "Action": "sts:AssumeRole" } ] }
How to diagnose
- Trust — aws iam get-role --role-name fn-role
- Timing — Just created?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- IAM AccessDeniedException AccessDeniedException: User: arn:aws:iam::... is not authorized to perform: service:Action on resource: ...
- KMS AccessDenied kms:Decrypt KMS: not authorized to perform: kms:Decrypt (or the key policy does not allow access)
- Malformed Lambda proxy response API Gateway {"message": "Internal server error"} 502 — Malformed Lambda proxy response
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026