Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

The message Permission denied (publickey) means the server refused your SSH login because it did not accept any public key from your client. It is a rejection, not a diagnosis. The same message appears whether SSH offered no key, offered the wrong one, or offered a valid key that the server does not recognize, and each case has a different fix. The steps below separate those cases first, then cover the specific corrections.

GitHub and GitLab are used as the reference platforms because their official troubleshooting pages describe this error in detail. Their usernames and account steps are platform-specific, and a self-managed server may behave differently; those differences are noted where they matter.

What the message actually tells you

GitHub’s official troubleshooting page, “Error: Permission denied (publickey),” states: “A “Permission denied” error means that the server rejected your connection.” GitLab’s documentation lists several possible causes for the same message: the public key was not added to the account, the key type is unsupported, SSH is using the wrong private key, the private key is inaccessible, local key permissions are incorrect, or the key is not loaded into ssh-agent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These causes sit on both sides of the connection. Some are on your computer (the wrong key is selected, the key is not loaded, file permissions are wrong). Others are on the service or server (the public key is not registered to the account). Vendor documentation does not publish how often each cause occurs, so the order below follows diagnostic logic rather than frequency.

#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Find out which case you have

Run these checks in order. Each one narrows the problem before you change anything.

  1. Test the connection and read the result. For GitHub, run ssh -T git@github.com. A working setup returns a greeting that includes your GitHub username and states that GitHub does not provide shell access. For GitLab, substitute your own host: ssh -T git@gitlab.example.com.

  2. Read the verbose log. For GitHub, run ssh -vT git@github.com. For GitLab, run ssh -Tvvv git@gitlab.example.com. Look at the identity-file lines and the “Trying private key” lines. In GitHub’s example, an identity file line ending in type -1 means SSH did not find a key at that path.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    Rank #2
    Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
    • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
    • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
    • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
    • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
    • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  3. List the keys loaded in the agent. Run ssh-add -l -E sha256. If it reports “The agent has no identities,” no key is loaded. Otherwise, note the SHA256 fingerprints.

  4. Compare fingerprints with your account. Print the fingerprint of the key you intend to use with ssh-keygen -lf ~/.ssh/id_ed25519.pub -E sha256 (adjust the filename to your key). Then compare it with the keys listed in your hosting account’s settings.

The table maps what you see to the most likely cause.

What you observe Most likely case Go to
Identity file line ends in type -1, and no key is offered SSH found no key file at the path it checked Wrong or missing key file
A key is offered, but its fingerprint is not in your account’s key list Public key not registered with the account Public key not added to the account
Your intended key is registered, but SSH offers a different key first Wrong key selected Wrong key offered
ssh-add -l -E sha256 reports no identities Key not loaded into the agent Key not loaded in ssh-agent

Common causes and fixes

The public key is not added to the account

GitLab lists an unregistered public key as a common cause. Copy the public key with cat ~/.ssh/id_ed25519.pub, then add it in your account settings. On GitHub, this is under the SSH and GPG keys section of your account settings. Use the key file ending in .pub, never the private key file. Interface labels can change, so search your account settings for “SSH keys” if the path differs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The wrong key is offered

If you have several keys, SSH may offer one that the service does not recognize before it tries the one you intended. GitLab advises checking for multiple keys and defining which one to use. Map the host to the correct key in ~/.ssh/config:

Host github.com
  HostName github.com
  User git
  IdentityFile ~/.ssh/id_ed25519_github
  IdentitiesOnly yes

IdentitiesOnly yes tells SSH to offer only the file named in IdentityFile. Test the key without a config change by running ssh -i ~/.ssh/id_ed25519_github -vT git@github.com.

The key is not loaded into ssh-agent

A key can be valid and registered but still unavailable if the agent does not hold it. A new terminal session or a reboot can leave it unloaded. Start an agent if needed, then add the key:

eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519

Then confirm with ssh-add -l -E sha256.

The key type is not supported

GitLab lists an unsupported key type as a cause. Check the key type in the .pub file’s first field (for example, ssh-ed25519 or ssh-rsa). If the service rejects your type, generate a new key of a type it accepts, register it, and retire the old one.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Local permissions are too open or too restrictive

GitLab’s documented example sets the private key to 600 and the .ssh directory to 700. Apply them with:

Best Value
Yubico - YubiKey 5Ci - Multi-Factor authentication (MFA) Security Key and passkey for iPhone/Android/PC, Dual connectors for Lighting/USB-C, FIDO Certified
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_ed25519

Run these as the same user who runs SSH. A key owned by another account, or unreadable by yours, cannot be used even if it is correct.

Elevated privileges use a different user’s keys

GitHub cautions against running Git with sudo or other elevated privileges. A privileged command runs under a different user account and can use that account’s SSH keys, not the ones you generated or loaded. Run Git as your normal user, and fix permissions on the repository instead of escalating the command.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Usernames, hosts, and ports

For GitHub Git access, the SSH user is git, not your GitHub username. Your username appears only in the greeting that ssh -T prints. Do not carry the git@ convention to unrelated servers; check each server’s instructions. Also confirm that the host name in your command is the one you intend. GitHub’s normal SSH connection uses port 22, but a setting such as SSH over HTTPS changes the port, so a port mismatch can look like an authentication failure in some configurations.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Self-managed servers

On a self-managed server, the service-side check is whether the public key appears in the target user’s authorized keys. That file is normally ~/.ssh/authorized_keys in that user’s home directory. The directory and file must not be writable by other users, and the common expectation is 700 for ~/.ssh and 600 for authorized_keys. The server must also allow public-key authentication through PubkeyAuthentication yes in its SSH daemon configuration.

When the client-side checks look correct, read the server’s logs. On Debian and Ubuntu systems, the authentication log is usually /var/log/auth.log; on Red Hat-family systems it is usually /var/log/secure. The reason SSH gives there is more specific than the client’s message. Official GitHub and GitLab pages do not cover every server’s account policy, network path, or host-specific restrictions, so when these checks do not reveal the cause, pass the log entries and your verbose output to the server’s administrator.

Optional: hardware-backed keys

Some users keep SSH keys on a FIDO2 hardware security key. This is a deliberate setup choice, not a fix for the general error. GitLab’s FIDO2 enrollment instructions require OpenSSH 8.2 or later, so check the client version with ssh -V first. Confirm that your physical key supports the key type you want, such as ed25519-sk generated with ssh-keygen -t ed25519-sk, before enrolling it with the service. Verify model compatibility with the manufacturer and the service’s documentation before buying a device.

The Bottom Line

“”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.