使用AWS SES API及Java SDK发邮件失败(403错误)求助
Hey there, let's walk through the most common fixes for this frustrating 403 InvalidClientTokenId error when sending emails via Amazon SES using the AWS SDK for Java. Here's what to check step by step:
1. Verify Your AWS Credentials Are Correct
The most frequent cause is typos or incorrect access keys.
- Double-check your AWS Access Key ID and Secret Access Key—even a single extra space, missing character, or swapped key pair will trigger this error.
- If you're using the default credential provider chain (recommended), confirm the values in your
~/.aws/credentialsfile (macOS/Linux) orC:\Users\<your-username>\.aws\credentials(Windows) are accurate. - Avoid hardcoding credentials in your code, but if you are, make sure there are no typos in the strings you're passing to the SDK.
2. Ensure Your IAM User Has SES Permissions
Your AWS IAM user needs explicit permissions to interact with SES.
- Go to the AWS IAM Console, find your user, and check the attached policies. At minimum, they should include permissions for
ses:SendEmailandses:SendRawEmail. - You can attach the managed policy
AmazonSESFullAccessfor testing (though in production, use a custom policy with least privilege), or create a tailored policy like this:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "ses:SendEmail", "ses:SendRawEmail" ], "Resource": "*" } ] }
3. Confirm the Correct AWS Region Is Configured
SES is a regional service, so your SDK must target the same region where your SES account is set up (e.g., us-east-1, eu-west-1).
- In the Java SDK, make sure you're specifying the region when building your SES client. For SDK v1:
For SDK v2 (recommended for newer projects):AmazonSES sesClient = AmazonSESClientBuilder.standard() .withRegion(Regions.US_EAST_1) .build();SesClient sesClient = SesClient.builder() .region(Region.US_EAST_1) .build(); - Mismatched regions can lead to invalid token errors even if your credentials are correct.
4. Check if Credentials Are Expired or Revoked
- If you're using temporary credentials (e.g., from AWS STS), verify they haven't expired. Temporary credentials have a limited lifespan (default 1 hour).
- If you're using long-term credentials, check the IAM Console to ensure the access key hasn't been disabled or revoked by an administrator.
5. Test with AWS CLI to Isolate the Issue
To rule out code-specific problems, test sending an email directly with the AWS CLI:
aws ses send-email --from "your-verified-email@example.com" --to "recipient@example.com" --subject "Test SES Email" --text "This is a test" --region us-east-1
- If the CLI command fails with the same error, the issue is with your credentials/permissions, not your Java code.
- If the CLI works, debug your Java code's credential provider or region configuration.
Bonus: Update Your AWS SDK for Java
Outdated SDK versions can have compatibility issues with AWS services. Make sure you're using the latest stable version of the SDK (v1 or v2). For Maven, check your pom.xml dependencies to ensure they're up to date.
内容的提问来源于stack exchange,提问作者Ityav

