remotion-dev/remotion · error · Error
No valid AWS Caller Identity detected
Error message
No valid AWS Caller Identity detected
What it means
simulatePermissions() calls AWS STS GetCallerIdentity to determine the current principal. If the response has no Arn field, Remotion cannot determine which IAM entity to simulate permissions for and throws this error. This typically means the AWS credentials are invalid, expired, or not configured at all.
Solutions
- Verify AWS credentials are configured: run aws sts get-caller-identity in a terminal and confirm it returns a valid ARN.
- Set AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY (and AWS_SESSION_TOKEN if using temporary credentials) environment variables, or configure the correct AWS profile.
- If using AWS SSO, run aws sso login to refresh credentials before running simulatePermissions().
- Check that the region passed to simulatePermissions() matches a region where your credentials are valid.
Defensive patterns
Strategy: validation
Validate before calling
import {STSClient, GetCallerIdentityCommand} from '@aws-sdk/client-sts';
async function assertAwsCredentialsValid(region: string): Promise<void> {
const client = new STSClient({region});
const response = await client.send(new GetCallerIdentityCommand({}));
if (!response.Arn) {
throw new Error('AWS credentials are not configured or are invalid.');
}
}
await assertAwsCredentialsValid(region); Prevention
- Run aws sts get-caller-identity before calling simulatePermissions() to verify credentials.
- Ensure AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY (and AWS_SESSION_TOKEN) env vars are set.
- Refresh AWS SSO or temporary credentials before they expire.
- Use the correct AWS profile if multiple profiles are configured.
When it happens
Trigger: Calling simulatePermissions({region, ...}) when the AWS SDK cannot establish a valid caller identity — no credentials configured, expired temporary credentials, wrong profile, or a misconfigured credential provider chain.
Common situations: AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY env vars not set or expired session token; wrong AWS profile selected; running in an environment without IAM role attached (e.g. local dev without configured credentials); credentials have been revoked.
Related errors
- AWS Caller Identity partition
- Unknown AWS Caller Identity ARN detected
- UnrecognizedClientException: The AWS credentials provided…
- UnrecognizedClientException: The AWS credentials provided…
- Unsupported AWS Caller Identity as Assumed-Role ARN detected
AI-assisted analysis of remotion-dev/remotion@10db9de073 (2026-08-22).
Data as JSON: /api/errors/a76f5322e9c74508.
Report an issue: GitHub.
Appendix: source
Thrown at packages/lambda/src/api/iam-validation/simulate.ts:45
export type SimulatePermissionsOutput = {
results: SimulationResult[];
};
/*
* @description Simulates calls using the AWS Simulator to validate the correct permissions.
* @see [Documentation](https://remotion.dev/docs/lambda/simulatepermissions)
*/
export const simulatePermissions = async (
options: SimulatePermissionsInput,
): Promise<SimulatePermissionsOutput> => {
const callerIdentity = await LambdaClientInternals.getStsClient(
options.region,
options.requestHandler,
).send(new GetCallerIdentityCommand({}));
if (!callerIdentity?.Arn) {
throw new Error('No valid AWS Caller Identity detected');
}
const {partition: regionPartition} =
LambdaClientInternals.getAwsRegionMetadata(options.region);
const callerArn = resolveCallerArnForSimulation({
callerIdentityArn: callerIdentity.Arn,
region: options.region,
regionPartition,
});
const results: SimulationResult[] = [];
for (const per of getRequiredPermissions(regionPartition)) {
const result = await simulateRule({
actionNames: per.actions,
arn: callerArn,
region: options.region,
resource: per.resource,View on GitHub (pinned to 10db9de073)