使用LocalStackCloud本地开发AWS应用时为何需执行aws sso login命令?
Great question! This is a super common gotcha when mixing LocalStack with an existing AWS CLI setup that uses SSO. Let's break down why this is happening and how to fix it.
Why the SSO error happens with awslocal
The awslocal command is essentially a wrapper around the regular AWS CLI that points to LocalStack's local endpoints by default. But here's the key detail: it still reads your standard AWS CLI configuration files (located at C:\Users\<YourUsername>\.aws\config and C:\Users\<YourUsername>\.aws\credentials on Windows).
If your default AWS profile (or the profile that's currently active via the AWS_PROFILE environment variable) is configured to use AWS SSO (you'll see lines like sso_start_url, sso_region, sso_account_id in your config file for that profile), the AWS CLI (and by extension awslocal) will still try to use that profile's authentication method—even when you're targeting LocalStack.
Since you haven't run aws sso login (or your token expired), the CLI can't retrieve a valid SSO token, hence the error you see:
Error when retrieving token from sso: Token has expired and refresh failed
LocalStack doesn't actually need a real AWS SSO token (or any real AWS credentials, for that matter)—it accepts dummy credentials like dummy/dummy to bypass authentication checks. The problem is just that your active AWS profile is forcing the SSO flow.
How to fix this (3 simple solutions)
You have a few straightforward ways to avoid the SSO requirement when using LocalStack:
Use a dedicated LocalStack profile
Create a new profile in your AWS credentials file (C:\Users\<YourUsername>\.aws\credentials) that uses dummy credentials (LocalStack doesn't validate these):[localstack] aws_access_key_id = dummy aws_secret_access_key = dummy region = us-east-1Then explicitly specify this profile when running
awslocal:awslocal --profile localstack ec2 describe-vpcsTemporarily override the active profile
In your DOS prompt, set theAWS_PROFILEenvironment variable to point to your new LocalStack profile before running commands:set AWS_PROFILE=localstack awslocal ec2 describe-vpcsDirectly disable authentication checks for LocalStack
You can also set environment variables to skip credential validation entirely when usingawslocal:set AWS_ACCESS_KEY_ID=dummy set AWS_SECRET_ACCESS_KEY=dummy awslocal ec2 describe-vpcs
Key takeaway
LocalStack doesn't require real AWS credentials or SSO tokens—this issue is purely a side effect of your existing AWS CLI configuration using an SSO profile by default. By switching to a dummy profile or overriding credentials, you can use awslocal and samlocal without ever needing to run aws sso login for local development.
内容来源于stack exchange

