UnrecognizedClientException: The security token included in the request is invalid
The access key or session token isn’t recognised — wrong/deleted key, a session token missing for temporary credentials, or a region not enabled for the account.
Seen on:
AWS
Meaning
Temporary credentials need all three values (key ID, secret, session token). Copying only two, using deleted keys, stale environment variables overriding the profile, or calling an opt-in region that isn’t enabled all produce this.
Common causes
- AWS_SESSION_TOKEN missing or stale for temporary keys
- Access key deleted/deactivated
- Old env vars overriding ~/.aws profile
- Opt-in region not enabled
⚡ Quick fix
- Check identity: aws sts get-caller-identity
- Unset stale AWS_* env vars or refresh them
- Enable the region in Account settings if opt-in
Detailed fix by platform
Shell
- bash
env | grep ^AWS_ unset AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY AWS_SESSION_TOKEN aws sts get-caller-identity --profile prod
How to diagnose
- Credentials — Where are they coming from (env, profile, role)?
- Token — Session token present?
- Region — Opt-in region?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026