Ffile2fix
Sign in Get started

How to fix "Permission denied (publickey)" with Git and SSH

[email protected]: Permission denied (publickey).
fatal: Could not read from remote repository.

Please make sure you have the correct access rights
and the repository exists.

The Git host rejected the SSH connection because none of the keys your SSH client offered is linked to an account with access. Either no key exists on this machine, the right key is not being offered, or it was never added to GitHub, GitLab or Bitbucket.

Also appears as: [email protected]: Permission denied (publickey,keyboard-interactive). · [email protected]: Permission denied (publickey). · ERROR: Repository not found. fatal: Could not read from remote repository. · Load key "/home/user/.ssh/id_ed25519": bad permissions

Common causes

  • No SSH key exists on this machine or server (common on a new cPanel account or VPS)
  • A key exists but its public half was never added to your account or as a deploy key
  • SSH offers the wrong key because the key has a non-default name and ~/.ssh/config does not point to it
  • The private key file has loose permissions, so SSH refuses to use it
  • Running git with sudo or as a different user (cron, www-data, deploy) that has its own empty ~/.ssh
  • The deploy key is attached to a different repository, or is read-only and you are pushing

How to fix it

  1. Test the connection. Run ssh -T [email protected] (or [email protected]). Success prints 'Hi username! You've successfully authenticated'. Add -v to see which key files are tried.
  2. Create a key if there is none. Run ssh-keygen -t ed25519 -C "[email protected]" and accept the default path ~/.ssh/id_ed25519. On cPanel you can also use SSH Access > Manage SSH Keys.
  3. Add the public key to the host. Copy the contents of ~/.ssh/id_ed25519.pub (never the private file) to GitHub Settings > SSH and GPG keys, or to the repository's Deploy keys for a server; tick 'Allow write access' only if the server must push.
  4. Point SSH at the right key. If the key has a custom name, add a Host block in ~/.ssh/config with IdentityFile and IdentitiesOnly yes, or load it with ssh-add ~/.ssh/mykey.
  5. Fix file permissions. Run chmod 700 ~/.ssh and chmod 600 ~/.ssh/id_ed25519; SSH ignores private keys other users can read.
  6. Run git as the right user. Do not use sudo git. For cron or deploy scripts, set up the key under the account that runs them, or check the remote with git remote -v in case it should use HTTPS with a token.

~/.ssh/config

Host github.com
  HostName github.com
  User git
  IdentityFile ~/.ssh/id_ed25519_site
  IdentitiesOnly yes

How to stop it happening again

  • Use one deploy key per server and repository, read-only unless pushing is required
  • Keep ~/.ssh at 700 and private keys at 600, and protect personal keys with a passphrase
  • Document which system user runs deploys and keep its key in that user's ~/.ssh

Frequently asked questions

Why does it say 'Repository not found' when the repo exists?

GitHub hides private repositories from accounts without access. You authenticated with a key that belongs to a user or deploy key without access to that repo, so check which identity ssh -T reports.

Can I use HTTPS instead of SSH?

Yes. Change the remote with git remote set-url origin https://github.com/user/repo.git and authenticate with a personal access token or Git Credential Manager; GitHub no longer accepts account passwords for Git.

Can one deploy key be used on several repositories?

No, GitHub allows a deploy key on only one repository. Create a key per repo and use Host aliases in ~/.ssh/config, or use a machine user.