{"record":{"id":"3c082f39ef1914e1","repo":"boto/boto3","slug":"unable-to-locate-credentials","errorCode":null,"errorMessage":"Unable to locate credentials","messagePattern":"Unable to locate credentials","errorType":"exception","errorClass":"NoCredentialsError","httpStatus":null,"severity":"critical","filePath":"boto3/session.py","lineNumber":93,"sourceCode":"                self._session.user_agent_extra += f\" {botocore_info}\"\n            else:\n                self._session.user_agent_extra = botocore_info\n            self._session.user_agent_name = 'Boto3'\n            self._session.user_agent_version = boto3.__version__\n\n        if profile_name is not None:\n            self._session.set_config_variable('profile', profile_name)\n\n        credentials_kwargs = {\n            \"aws_access_key_id\": aws_access_key_id,\n            \"aws_secret_access_key\": aws_secret_access_key,\n            \"aws_session_token\": aws_session_token,\n            \"aws_account_id\": aws_account_id,\n        }\n\n        if any(credentials_kwargs.values()):\n            if self._account_id_set_without_credentials(**credentials_kwargs):\n                raise NoCredentialsError()\n\n            if aws_account_id is None:\n                del credentials_kwargs[\"aws_account_id\"]\n\n            self._session.set_credentials(*credentials_kwargs.values())\n\n        if region_name is not None:\n            self._session.set_config_variable('region', region_name)\n\n        self.resource_factory = ResourceFactory(\n            self._session.get_component('event_emitter')\n        )\n        self._setup_loader()\n        self._register_default_handlers()\n\n    def __repr__(self):\n        return '{}(region_name={})'.format(\n            self.__class__.__name__,","sourceCodeStart":75,"sourceCodeEnd":111,"githubUrl":"https://github.com/boto/boto3/blob/6e10b029c1326a437932a8b24f38af69fd986e15/boto3/session.py#L75-L111","documentation":"`NoCredentialsError` at this site is raised specifically when the caller passes `aws_account_id=` to `boto3.Session(...)` (or `setup_default_session`) without also supplying real credentials (`aws_access_key_id` + `aws_secret_access_key`). boto3 cannot derive credentials from an account id alone, so it refuses rather than silently proceeding as anonymous. The shared message text ('Unable to locate credentials') is the standard botocore NoCredentialsError wording.","triggerScenarios":"Constructing a Session with `boto3.Session(aws_account_id='123456789012')` but no access key/secret and no resolvable credentials in the environment (no profile, no env vars, no IMDS). Also when only `aws_session_token` is provided without key/secret.","commonSituations":"Newer boto3 feature: `aws_account_id` was added to disambiguate accounts, but developers mistakenly treat it as a credential; running on a host without AWS credentials configured while attempting to pin an account id; CI where only an account id is injected as an env var.","solutions":["Provide real credentials alongside the account id: `boto3.Session(aws_access_key_id=..., aws_secret_access_key=..., aws_account_id=...)`.","Configure a named profile (`~/.aws/credentials` or `AWS_PROFILE`) that contains the keys, then pass only `aws_account_id`.","In an AWS runtime (EC2/Lambda/ECS/Fargate), attach an IAM role so credentials resolve automatically; then `aws_account_id` is optional.","If you genuinely want anonymous access for a public resource, drop `aws_account_id` (it forces the credentials check path)."],"exampleFix":"# before\nsess = boto3.Session(aws_account_id='123456789012')  # NoCredentialsError\n\n# after (option A: explicit keys)\nsess = boto3.Session(\n    aws_access_key_id=AK, aws_secret_access_key=SK, aws_account_id='123456789012',\n)\n# after (option B: rely on a configured profile / role, drop account_id)\nsess = boto3.Session(profile_name='prod')","handlingStrategy":"validation","validationCode":"def build_session(aws_account_id=None, **creds):\n    has_real = creds.get('aws_access_key_id') and creds.get('aws_secret_access_key')\n    if aws_account_id and not has_real and not os.environ.get('AWS_PROFILE'):\n        raise ValueError('aws_account_id provided without any credentials')\n    return boto3.Session(aws_account_id=aws_account_id, **creds)","typeGuard":"def account_id_has_credentials(aws_account_id, access_key, secret_key, session_token) -> bool:\n    if aws_account_id is None:\n        return True\n    return bool(access_key and secret_key) or bool(session_token)","tryCatchPattern":"from botocore.exceptions import NoCredentialsError\ntry:\n    sess = boto3.Session(aws_account_id=acct)\nexcept NoCredentialsError:\n    sess = boto3.Session()  # fall back to env/IMDS profile without account_id","preventionTips":["Attach an IAM role on AWS compute instead of passing static keys.","Configure AWS_PROFILE or AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY in the environment.","Only pass aws_account_id alongside real credentials or a resolvable profile."],"tags":["session","credentials","authentication","argument-validation"],"backgroundTag":null,"analyzedSha":"6e10b029c1326a437932a8b24f38af69fd986e15","analyzedAt":"2026-08-11T20:52:47.213Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}