sts:AssumeRole denied ☁️ AWS

is not authorized to perform: sts:AssumeRole on resource: arn:aws:iam::...:role/...

The caller can’t assume the role — either its own policy doesn’t allow sts:AssumeRole, or the role’s trust policy doesn’t trust the caller.

Seen on: AWS

Meaning

AssumeRole needs both sides: the caller’s permission to call sts:AssumeRole on the role ARN, and the role’s trust policy listing the caller (account, user, role, service or OIDC provider). Cross-account roles and GitHub Actions OIDC roles fail on the trust side most often.

Common causes

  • Role trust policy doesn’t include the caller principal
  • Caller policy lacks sts:AssumeRole on that ARN
  • Trust policy conditions (ExternalId, MFA, OIDC sub/aud) not met
  • Typo in the role ARN/account

⚡ Quick fix

  1. Add the caller to the role’s trust policy
  2. Allow sts:AssumeRole for the caller
  3. For OIDC, check token.actions.githubusercontent.com:sub matches repo/branch

Detailed fix by platform

IAM

  1. bash
    {
      "Effect": "Allow",
      "Principal": { "Federated": "arn:aws:iam::123456789012:oidc-provider/token.actions.githubusercontent.com" },
      "Action": "sts:AssumeRoleWithWebIdentity",
      "Condition": { "StringLike": { "token.actions.githubusercontent.com:sub": "repo:myorg/myrepo:*" } }
    }

How to diagnose

  1. Trust — aws iam get-role --role-name X --query Role.AssumeRolePolicyDocument
  2. Caller — get-caller-identity
  3. Conditions — ExternalId/sub claims

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.