Skip to content
Discussion options

You must be logged in to vote

The InvalidClientTokenId error usually means Terraform is attempting to use credentials that AWS does not recognize, even though your CLI session with aws sts get-caller-identity looks correct. Please walk through some checks to make sure everything is set up properly.

  1. Confirm SuperAdmin is configured correctly
  • Make sure MFA is enabled and that your local session is authenticated with MFA.
  • Please try signing out and signing back in as SuperAdmin to ensure you’re prompted for MFA.
  • Reference: How to Create SuperAdmin User.
  1. Verify you are using SuperAdmin locally
  • From Geodesic, run aws sts get-caller-identity.
  • You should see the SuperAdmin identity, as you’ve shown.
  1. Check the tfstat…

Replies: 1 comment 1 reply

Comment options

milldr
Aug 29, 2025
Maintainer Sponsor

You must be logged in to vote
1 reply
@jochem725
Comment options

Answer selected by jochem725
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants