You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS SES API及Java SDK发邮件失败(403错误)求助

Fixing InvalidClientTokenId (403) Error with Amazon SES Java SDK

Hey there, let's walk through the most common fixes for this frustrating 403 InvalidClientTokenId error when sending emails via Amazon SES using the AWS SDK for Java. Here's what to check step by step:

1. Verify Your AWS Credentials Are Correct

The most frequent cause is typos or incorrect access keys.

  • Double-check your AWS Access Key ID and Secret Access Key—even a single extra space, missing character, or swapped key pair will trigger this error.
  • If you're using the default credential provider chain (recommended), confirm the values in your ~/.aws/credentials file (macOS/Linux) or C:\Users\<your-username>\.aws\credentials (Windows) are accurate.
  • Avoid hardcoding credentials in your code, but if you are, make sure there are no typos in the strings you're passing to the SDK.

2. Ensure Your IAM User Has SES Permissions

Your AWS IAM user needs explicit permissions to interact with SES.

  • Go to the AWS IAM Console, find your user, and check the attached policies. At minimum, they should include permissions for ses:SendEmail and ses:SendRawEmail.
  • You can attach the managed policy AmazonSESFullAccess for testing (though in production, use a custom policy with least privilege), or create a tailored policy like this:
    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": [
                    "ses:SendEmail",
                    "ses:SendRawEmail"
                ],
                "Resource": "*"
            }
        ]
    }
    

3. Confirm the Correct AWS Region Is Configured

SES is a regional service, so your SDK must target the same region where your SES account is set up (e.g., us-east-1, eu-west-1).

  • In the Java SDK, make sure you're specifying the region when building your SES client. For SDK v1:
    AmazonSES sesClient = AmazonSESClientBuilder.standard()
        .withRegion(Regions.US_EAST_1)
        .build();
    
    For SDK v2 (recommended for newer projects):
    SesClient sesClient = SesClient.builder()
        .region(Region.US_EAST_1)
        .build();
    
  • Mismatched regions can lead to invalid token errors even if your credentials are correct.

4. Check if Credentials Are Expired or Revoked

  • If you're using temporary credentials (e.g., from AWS STS), verify they haven't expired. Temporary credentials have a limited lifespan (default 1 hour).
  • If you're using long-term credentials, check the IAM Console to ensure the access key hasn't been disabled or revoked by an administrator.

5. Test with AWS CLI to Isolate the Issue

To rule out code-specific problems, test sending an email directly with the AWS CLI:

aws ses send-email --from "your-verified-email@example.com" --to "recipient@example.com" --subject "Test SES Email" --text "This is a test" --region us-east-1
  • If the CLI command fails with the same error, the issue is with your credentials/permissions, not your Java code.
  • If the CLI works, debug your Java code's credential provider or region configuration.

Bonus: Update Your AWS SDK for Java

Outdated SDK versions can have compatibility issues with AWS services. Make sure you're using the latest stable version of the SDK (v1 or v2). For Maven, check your pom.xml dependencies to ensure they're up to date.


内容的提问来源于stack exchange,提问作者Ityav

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:11:51