Permission denied (publickey)
Permission denied (publickey) means the server closed the door because none of the keys your SSH client offered is accepted.
What it means
Section titled “What it means”Your computer tried to log in with a key pair. The server looked at the public keys it knows for your account and found no match. GitHub’s guide says the most common reasons are: a wrong server, a wrong user name, no key in use, or a public key that is not attached to your account.
Why it happens
Section titled “Why it happens”- You used your own username. It must be
git:git@github.com. - SSH could not find a private key file, so it offered nothing.
- The key exists, but its public half was never added to your GitHub account.
- You created the key with
sudoor as another user, then ran Git as someone else. Then you are not using the same keys.
How Devpit fixes or avoids it
Section titled “How Devpit fixes or avoids it”Git & SSH Setup covers the first steps:
- Generate SSH key creates an ed25519 key with
ssh-keygenin your.sshfolder and copies the public half so you can paste it into GitHub. - It never overwrites an existing key by accident. If a key is already there, you must type
OVERWRITEbefore it replaces it, and it warns that the old key stops working everywhere it was added. - The key has an empty passphrase (Devpit runs
ssh-keygenwith an empty-N).
Devpit does not upload the key to GitHub and does not load it into the ssh-agent. Do those two steps below.
The manual fix
Section titled “The manual fix”- Test the connection with the
gituser and verbose output (-v). It shows which key files SSH tried:
ssh -vT git@github.com- Read the output. “identity file … type -1” and “Trying private key” mean SSH found no key file. Lines that say “Offering public key” mean it found one.
- If there is no key, run Generate SSH key in Devpit, or run ssh-keygen yourself:
ssh-keygen -t ed25519 -C "your_email@example.com"- Make sure the ssh-agent is running and has your key. In a PowerShell window opened as administrator:
Get-Service -Name ssh-agent | Set-Service -StartupType ManualStart-Service ssh-agentThen, in a normal window, add the private key (use your own user name in the path):
ssh-add c:/Users/YOU/.ssh/id_ed25519- Add the public key (the
.pubfile, for exampleid_ed25519.pub) to your GitHub account in your account settings, in the SSH keys section. GitHub’s guide “Adding a new SSH key to your GitHub account” shows each click. - Test again. GitHub answers with “Hi USERNAME! You’ve successfully authenticated…”:
ssh -T git@github.com- If your key has another file name, tell SSH with
-i:ssh -i ~/.ssh/KEY-FILE -vT git@github.com.
Do not use sudo or administrator rights with Git for this. Keys made with elevated rights are not the keys your normal account uses.
Sources
Section titled “Sources”Common questions
Which username do I use for SSH to GitHub?
Always git. All connections, including the ones for remote URLs, must be made as the git user. If you connect with your GitHub username, the connection fails with Permission denied (publickey).
Does Devpit add my key to GitHub or to the ssh-agent?
No. Devpit creates the key pair and copies the public key for you. You paste the public key into your GitHub account settings yourself, and you load the private key into the ssh-agent if you use one.
Does the key Devpit creates have a passphrase?
No. Devpit runs ssh-keygen with an empty passphrase. Anyone who can read the private key file can use the key, so keep the .ssh folder private.
