”Cannot authenticate to provider”
Your AWS SSO session expired (most common, locally)
Your AWS SSO session expired (most common, locally)
SSO sessions last 8–12 hours. Run:A long-running process recovers on its own once you do — SecRefs does not
cache failures, so the next resolution succeeds without a restart.
No credentials at all
No credentials at all
Could not load credentials from any providers means the whole AWS credential
chain came up empty. Set AWS_PROFILE, export static keys, or attach an
instance role.Bitwarden or Vault token missing
Bitwarden or Vault token missing
Set
BWS_ACCESS_TOKEN for Bitwarden, or VAULT_ADDR and VAULT_TOKEN for
Vault. Both are read from the environment; SecRefs never stores them.”Failed to resolve N secret reference(s)”
AccessDenied is deliberately not treated as an authentication failure.
Your credentials worked — a policy said no to one secret. Sending you to
re-login would waste your time.Diagnosing without resolving
check validates every reference and never returns a plaintext value: