Skip to content

Permission denied (publickey)

Permission denied (publickey) means the server closed the door because none of the keys your SSH client offered is accepted.

Your computer tried to log in with a key pair. The server looked at the public keys it knows for your account and found no match. GitHub’s guide says the most common reasons are: a wrong server, a wrong user name, no key in use, or a public key that is not attached to your account.

  • You used your own username. It must be git: git@github.com.
  • SSH could not find a private key file, so it offered nothing.
  • The key exists, but its public half was never added to your GitHub account.
  • You created the key with sudo or as another user, then ran Git as someone else. Then you are not using the same keys.

Git & SSH Setup covers the first steps:

  • Generate SSH key creates an ed25519 key with ssh-keygen in your .ssh folder and copies the public half so you can paste it into GitHub.
  • It never overwrites an existing key by accident. If a key is already there, you must type OVERWRITE before it replaces it, and it warns that the old key stops working everywhere it was added.
  • The key has an empty passphrase (Devpit runs ssh-keygen with an empty -N).

Devpit does not upload the key to GitHub and does not load it into the ssh-agent. Do those two steps below.

  1. Test the connection with the git user and verbose output (-v). It shows which key files SSH tried:
Terminal window
ssh -vT git@github.com
  1. Read the output. “identity file … type -1” and “Trying private key” mean SSH found no key file. Lines that say “Offering public key” mean it found one.
  2. If there is no key, run Generate SSH key in Devpit, or run ssh-keygen yourself:
Terminal window
ssh-keygen -t ed25519 -C "your_email@example.com"
  1. Make sure the ssh-agent is running and has your key. In a PowerShell window opened as administrator:
Terminal window
Get-Service -Name ssh-agent | Set-Service -StartupType Manual
Start-Service ssh-agent

Then, in a normal window, add the private key (use your own user name in the path):

Terminal window
ssh-add c:/Users/YOU/.ssh/id_ed25519
  1. Add the public key (the .pub file, for example id_ed25519.pub) to your GitHub account in your account settings, in the SSH keys section. GitHub’s guide “Adding a new SSH key to your GitHub account” shows each click.
  2. Test again. GitHub answers with “Hi USERNAME! You’ve successfully authenticated…”:
Terminal window
ssh -T git@github.com
  1. If your key has another file name, tell SSH with -i: ssh -i ~/.ssh/KEY-FILE -vT git@github.com.

Do not use sudo or administrator rights with Git for this. Keys made with elevated rights are not the keys your normal account uses.

Common questions

Which username do I use for SSH to GitHub?

Always git. All connections, including the ones for remote URLs, must be made as the git user. If you connect with your GitHub username, the connection fails with Permission denied (publickey).

Does Devpit add my key to GitHub or to the ssh-agent?

No. Devpit creates the key pair and copies the public key for you. You paste the public key into your GitHub account settings yourself, and you load the private key into the ssh-agent if you use one.

Does the key Devpit creates have a passphrase?

No. Devpit runs ssh-keygen with an empty passphrase. Anyone who can read the private key file can use the key, so keep the .ssh folder private.