"Permission Denied (publickey)" on GitHub: How to Fix It
GitHub rejected your SSH key — either you don't have one, it isn't added to GitHub, your SSH agent isn't offering it, or you're using the wrong account. A step-by-step fix with ssh -T, plus the HTTPS alternative and the 'Support for password authentication was removed' error.
git@github.com: Permission denied (publickey).
fatal: Could not read from remote repository.
Please make sure you have the correct access rights
and the repository exists.
Git tried to talk to GitHub over SSH, and GitHub didn't recognise any key your computer offered. It's an authentication problem, not a problem with your code or repository.
Step 1: Test the connection
ssh -T git@github.com
Hi yourname! You've successfully authenticated→ SSH works. Skip to "SSH works but push still fails."Permission denied (publickey)→ keep going.
For details on what's happening, add -v:
ssh -vT git@github.com
Look for lines like Offering public key: /Users/you/.ssh/id_ed25519. If no key is offered, you don't have one or the agent isn't loading it.
Step 2: Do you have a key?
ls ~/.ssh
You're looking for a pair like id_ed25519 and id_ed25519.pub. If there's nothing, create one:
ssh-keygen -t ed25519 -C "you@example.com"
Press Enter to accept the default location; a passphrase is recommended. (SSH keys explained)
Step 3: Add the public key to GitHub
Copy the public key (the .pub file — never the other one):
cat ~/.ssh/id_ed25519.pub
On GitHub: Settings → SSH and GPG keys → New SSH key, paste it, save. Then test again with ssh -T git@github.com.
Step 4: Make sure the agent offers it
If the key has a non-default name or a passphrase, the SSH agent may not have it loaded:
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519
On macOS, add --apple-use-keychain to remember the passphrase. To make it permanent, tell SSH which key to use for GitHub in ~/.ssh/config:
Host github.com
User git
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes
(The SSH config file explained)
SSH works but push still fails
If ssh -T greets you but push says "permission denied" or "repository not found":
- Wrong account. The greeting shows which GitHub user you authenticated as. If you have a personal and a work account, you may be using the key for the wrong one. Use separate keys and host aliases in
~/.ssh/config. - No access to the repo. You need to be a collaborator (or a member of the org with access). Private repos return "not found" rather than "forbidden" when you lack access.
- Org requires SSO. Some organisations require you to authorise your SSH key for SSO in GitHub's key settings.
- Deploy keys only work for the one repository they were added to.
On a server or in an AI agent's environment
The same error on a remote server or container usually means the server has no key of its own. Options:
- Create a key on the server and add it to GitHub (as a deploy key for one repo, or to a bot account).
- Use SSH agent forwarding from your machine (
ssh -A), so the server borrows your key without storing it.
Don't copy your personal private key onto shared servers.
Or use HTTPS instead
Check which URL your repo uses:
git remote -v
git@github.com:... is SSH; https://github.com/... is HTTPS. HTTPS with the GitHub CLI is often simplest:
gh auth login
git remote set-url origin https://github.com/you/app.git
Note: GitHub doesn't accept your account password over HTTPS ("Support for password authentication was removed"). Use gh auth login, a credential manager, or a personal access token.
The summary
- Test with
ssh -T git@github.com. - Create a key if you have none; add the
.pubfile to GitHub. - Load it into the agent, or point to it in
~/.ssh/config. - If SSH works but push fails, check which account you are and whether you have access.
- HTTPS with
gh auth loginis a fine alternative.
EasySpawn gives each server its own Git setup, so Claude Code can clone, pull and push without you copying personal keys around. See how it works or join the waitlist.
Related: SSH Keys Explained · The SSH Config File Explained · Git and GitHub for Beginners · Git Push Rejected
Keep reading
"Command Not Found": The PATH Variable Explained
"command not found" or "is not recognized as an internal or external command" usually means the program is installed but your terminal doesn't know where to look. How PATH works on Mac, Linux and Windows, how to check it, and how to add a folder permanently.
Git Push Rejected: "Updates Were Rejected Because the Remote Contains Work"
git push fails with "rejected — fetch first" or "non-fast-forward" when GitHub has commits you don't. How to pull and combine them safely, when force-pushing is fine and when it destroys work, and the other rejection messages: protected branches, large files, and secrets.