is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam::...:role/...
The caller can’t assume the role — either its own policy doesn’t allow sts:AssumeRole, or the role’s trust policy doesn’t trust the caller.
Seen on:
AWS
Meaning
AssumeRole needs both sides: the caller’s permission to call sts:AssumeRole on the role ARN, and the role’s trust policy listing the caller (account, user, role, service or OIDC provider). Cross-account roles and GitHub Actions OIDC roles fail on the trust side most often.
Common causes
- Role trust policy doesn’t include the caller principal
- Caller policy lacks sts:AssumeRole on that ARN
- Trust policy conditions (ExternalId, MFA, OIDC sub/aud) not met
- Typo in the role ARN/account
⚡ Quick fix
- Add the caller to the role’s trust policy
- Allow sts:AssumeRole for the caller
- For OIDC, check token.actions.githubusercontent.com:sub matches repo/branch
Detailed fix by platform
IAM
- bash
{ "Effect": "Allow", "Principal": { "Federated": "arn:aws:iam::123456789012:oidc-provider/token.actions.githubusercontent.com" }, "Action": "sts:AssumeRoleWithWebIdentity", "Condition": { "StringLike": { "token.actions.githubusercontent.com:sub": "repo:myorg/myrepo:*" } } }
How to diagnose
- Trust — aws iam get-role --role-name X --query Role.AssumeRolePolicyDocument
- Caller — get-caller-identity
- Conditions — ExternalId/sub claims
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026