AWS CLI: "Unable to Locate Credentials" — Configure or Assume a Role

The CLI found no credentials in the standard chain. Run one command to see exactly which layer it checks, then configure credentials the right way for your context (profile, env, or instance role).

What you'll see

Root causes

No credentials configured in the active profile/context

The credential chain: env vars → ~/.aws/credentials → container/instance role. aws sts get-caller-identity tests the whole chain; 'no identity' = nothing found. Non-interactive shells skip the interactive setup paths.

Wrong region/profile or expired SSO token

AWS_CONFIG_FILE/AWS_PROFILE pointing elsewhere, or an aws sso session that expired silently — the profile exists, its credentials don't.

Fix it

  1. Test the full chain
    aws sts get-caller-identity 2>&1 | head -3 ; echo $AWS_PROFILE $AWS_ACCESS_KEY_ID
  2. Configure an access key (local dev)
    aws configure   # or: aws configure --profile work
  3. SSO users: refresh the session
    aws sso login --profile my-sso-profile   # expired SSO tokens are the silent cause
  4. Servers/CI: prefer roles over static keys
    # EC2: instance profile role; ECS: task role; CI: OIDC role assumption (aws-actions/configure-aws-credentials) — no long-lived keys anywhere

Field note

aws sts get-caller-identity is the universal truth test: it works only when valid credentials exist in the chain. Cron/sudo contexts need explicit env vars or a profile via AWS_PROFILE + config files — they don't inherit your interactive shell.

Common questions

It works in my terminal but fails in cron/CI. Why?

Those contexts don't source your shell profile or share your session: pass AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY explicitly (or an instance/OIDC role), and set AWS_REGION too.

Is putting keys in env vars safe?

For local and container dev, acceptable if scoped. For CI, prefer OIDC role assumption; for servers, instance/task roles. Never commit keys or bake them into images.

Ship it right the first time

An opinionated VPC module: per-AZ NAT, explicit dependencies, EKS-ready outputs.

Terraform AWS Foundation — $37 →

One-time. Yours to modify. Instant download from the NinjaOps template store.