Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstalliTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The message Permission denied (publickey) means the server refused your SSH login because it did not accept any public key from your client. It is a rejection, not a diagnosis. The same message appears whether SSH offered no key, offered the wrong one, or offered a valid key that the server does not recognize, and each case has a different fix. The steps below separate those cases first, then cover the specific corrections.
GitHub and GitLab are used as the reference platforms because their official troubleshooting pages describe this error in detail. Their usernames and account steps are platform-specific, and a self-managed server may behave differently; those differences are noted where they matter.
What the message actually tells you
GitHub’s official troubleshooting page, “Error: Permission denied (publickey),” states: “A “Permission denied” error means that the server rejected your connection.” GitLab’s documentation lists several possible causes for the same message: the public key was not added to the account, the key type is unsupported, SSH is using the wrong private key, the private key is inaccessible, local key permissions are incorrect, or the key is not loaded into ssh-agent.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →These causes sit on both sides of the connection. Some are on your computer (the wrong key is selected, the key is not loaded, file permissions are wrong). Others are on the service or server (the public key is not registered to the account). Vendor documentation does not publish how often each cause occurs, so the order below follows diagnostic logic rather than frequency.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Find out which case you have
Run these checks in order. Each one narrows the problem before you change anything.
-
Test the connection and read the result. For GitHub, run
ssh -T git@github.com. A working setup returns a greeting that includes your GitHub username and states that GitHub does not provide shell access. For GitLab, substitute your own host:ssh -T git@gitlab.example.com. -
Read the verbose log. For GitHub, run
ssh -vT git@github.com. For GitLab, runssh -Tvvv git@gitlab.example.com. Look at the identity-file lines and the “Trying private key” lines. In GitHub’s example, an identity file line ending intype -1means SSH did not find a key at that path.Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
-
List the keys loaded in the agent. Run
ssh-add -l -E sha256. If it reports “The agent has no identities,” no key is loaded. Otherwise, note the SHA256 fingerprints. -
Compare fingerprints with your account. Print the fingerprint of the key you intend to use with
ssh-keygen -lf ~/.ssh/id_ed25519.pub -E sha256(adjust the filename to your key). Then compare it with the keys listed in your hosting account’s settings.
The table maps what you see to the most likely cause.
| What you observe | Most likely case | Go to |
|---|---|---|
Identity file line ends in type -1, and no key is offered |
SSH found no key file at the path it checked | Wrong or missing key file |
| A key is offered, but its fingerprint is not in your account’s key list | Public key not registered with the account | Public key not added to the account |
| Your intended key is registered, but SSH offers a different key first | Wrong key selected | Wrong key offered |
ssh-add -l -E sha256 reports no identities |
Key not loaded into the agent | Key not loaded in ssh-agent |
Common causes and fixes
The public key is not added to the account
GitLab lists an unregistered public key as a common cause. Copy the public key with cat ~/.ssh/id_ed25519.pub, then add it in your account settings. On GitHub, this is under the SSH and GPG keys section of your account settings. Use the key file ending in .pub, never the private key file. Interface labels can change, so search your account settings for “SSH keys” if the path differs.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsThe wrong key is offered
If you have several keys, SSH may offer one that the service does not recognize before it tries the one you intended. GitLab advises checking for multiple keys and defining which one to use. Map the host to the correct key in ~/.ssh/config:
Host github.com
HostName github.com
User git
IdentityFile ~/.ssh/id_ed25519_github
IdentitiesOnly yes
IdentitiesOnly yes tells SSH to offer only the file named in IdentityFile. Test the key without a config change by running ssh -i ~/.ssh/id_ed25519_github -vT git@github.com.
Rank #4
The key is not loaded into ssh-agent
A key can be valid and registered but still unavailable if the agent does not hold it. A new terminal session or a reboot can leave it unloaded. Start an agent if needed, then add the key:
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519
Then confirm with ssh-add -l -E sha256.
The key type is not supported
GitLab lists an unsupported key type as a cause. Check the key type in the .pub file’s first field (for example, ssh-ed25519 or ssh-rsa). If the service rejects your type, generate a new key of a type it accepts, register it, and retire the old one.
Recommended Free Tools
Local permissions are too open or too restrictive
GitLab’s documented example sets the private key to 600 and the .ssh directory to 700. Apply them with:
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_ed25519
Run these as the same user who runs SSH. A key owned by another account, or unreadable by yours, cannot be used even if it is correct.
Elevated privileges use a different user’s keys
GitHub cautions against running Git with sudo or other elevated privileges. A privileged command runs under a different user account and can use that account’s SSH keys, not the ones you generated or loaded. Run Git as your normal user, and fix permissions on the repository instead of escalating the command.
Usernames, hosts, and ports
For GitHub Git access, the SSH user is git, not your GitHub username. Your username appears only in the greeting that ssh -T prints. Do not carry the git@ convention to unrelated servers; check each server’s instructions. Also confirm that the host name in your command is the one you intend. GitHub’s normal SSH connection uses port 22, but a setting such as SSH over HTTPS changes the port, so a port mismatch can look like an authentication failure in some configurations.
Free tools Windows power users keep installed
One-click scans. No signup required.
Self-managed servers
On a self-managed server, the service-side check is whether the public key appears in the target user’s authorized keys. That file is normally ~/.ssh/authorized_keys in that user’s home directory. The directory and file must not be writable by other users, and the common expectation is 700 for ~/.ssh and 600 for authorized_keys. The server must also allow public-key authentication through PubkeyAuthentication yes in its SSH daemon configuration.
When the client-side checks look correct, read the server’s logs. On Debian and Ubuntu systems, the authentication log is usually /var/log/auth.log; on Red Hat-family systems it is usually /var/log/secure. The reason SSH gives there is more specific than the client’s message. Official GitHub and GitLab pages do not cover every server’s account policy, network path, or host-specific restrictions, so when these checks do not reveal the cause, pass the log entries and your verbose output to the server’s administrator.
Optional: hardware-backed keys
Some users keep SSH keys on a FIDO2 hardware security key. This is a deliberate setup choice, not a fix for the general error. GitLab’s FIDO2 enrollment instructions require OpenSSH 8.2 or later, so check the client version with ssh -V first. Confirm that your physical key supports the key type you want, such as ed25519-sk generated with ssh-keygen -t ed25519-sk, before enrolling it with the service. Verify model compatibility with the manufacturer and the service’s documentation before buying a device.
Quick Recap
The Bottom Line
“”
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

