aws sam invalid token included in the request is invalid

Viewed 7603

I am working using aws sam and when try to make sam deploy. I get this error:

Error: Failed to create managed resources: An error occurred (InvalidClientTokenId) when calling the CreateChangeSet operation: The security token included in the request is invalid. 

I had already changed my credentials from .aws and changed them using the command aws configure. I also get the error when I try to access to anything online, like if I try to upload a file to a S3 bucket.

Error: botocore.exceptions.ClientError: An error occurred (UnrecognizedClientException) when calling the UpdateItem operation: The security token included in the request is invalid.

Any ideas?

3 Answers

You need to check if you have set the default credentials in your ~/.aws/credentials file if you have multiple and don't have a default specified in the shared credentials file plus you don't have anything set in your environment sam cli will fail with the above messages.

You use this this doc for setting them

I guess your credentials are OK but, check again if you are pointing to the right region. That was my problem indeed.

My particular resolution when I received the "token invalid in request" was:

  1. I tried using a different profile than default, updated the default to the profile I wanted to run with
  2. Start "sam init" with the default set as needed and don't make changes when going from init to build to deploy. Documentation states setting env var's for keys but have not tried it.
Related