error: You must be logged in to the server (Unauthorized)
The cluster rejected kubectl’s credentials — expired token, wrong kubeconfig user, or cloud IAM identity not allowed.
Seen on:
Kubernetes
Meaning
Unlike Forbidden (known user, no permission), Unauthorized means the API server doesn’t accept who you are at all. Cloud clusters use short-lived tokens from aws/gcloud/az; expired SSO sessions, the wrong AWS profile, or an IAM role missing from EKS access cause it.
Common causes
- Expired cloud SSO session or token
- Wrong AWS profile/role for EKS (not in aws-auth / access entries)
- Rotated certificates or revoked service account token
- kubeconfig pointing at another cluster’s user
⚡ Quick fix
- Refresh credentials (aws sso login, gcloud auth login, az login) and regenerate kubeconfig
- Check which identity you use (aws sts get-caller-identity)
- Ensure that identity is mapped in the cluster
Detailed fix by platform
AWS
- bash
aws sso login --profile prod aws eks update-kubeconfig --name my-cluster --profile prod kubectl get nodes
GCP
gcloud container clusters get-credentials my-cluster --region us-central1
How to diagnose
- Context — kubectl config current-context
- Identity — Cloud caller identity
- Mapping — EKS access entry/aws-auth
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Kubernetes
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026