Fix: Git Permission Denied (publickey) — SSH Key Troubleshooting

Problem

You try to push or clone from GitHub and get:

[email protected]: Permission denied (publickey).
fatal: Could not read from remote repository.

Symptoms

  • git push or git pull fails with the publickey error
  • Works yesterday, broken today (often after a reboot)
  • You have multiple GitHub accounts with different SSH keys
  • It works on one machine but not another

Root Cause

Git uses SSH to authenticate with GitHub. When you connect, GitHub checks your SSH key. This error means one of the following:

  1. No SSH key exists on your machine
  2. SSH key isn’t added to GitHub under Settings → SSH Keys
  3. SSH agent isn’t running or doesn’t have the key loaded
  4. The wrong key is offered (common with multiple GitHub accounts)

Solution

Step 1: Check if you have an SSH key

ls -la ~/.ssh

Look for files named id_ed25519, id_rsa, or similar (without .pub extension).

Step 2: Generate a key if you don’t have one

ssh-keygen -t ed25519 -C "[email protected]"

Press Enter to accept the default location. Optionally set a passphrase.

Step 3: Add the public key to GitHub

cat ~/.ssh/id_ed25519.pub

Copy the output, go to GitHub → Settings → SSH and GPG keys → New SSH key, paste it, and save.

Step 4: Test the connection

You should see: Hi username! You've successfully authenticated...

Step 5: Start the SSH agent and add your key

Often the agent isn’t running after a reboot:

eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519

To persist across reboots on macOS, add to ~/.ssh/config:

Host github.com
  AddKeysToAgent yes
  UseKeychain yes
  IdentityFile ~/.ssh/id_ed25519

Step 6: Multiple SSH keys for multiple GitHub accounts

Create a separate key for each account:

ssh-keygen -t ed25519 -C "[email protected]" -f ~/.ssh/id_ed25519_work

Configure ~/.ssh/config:

# Personal account
Host github.com-personal
  HostName github.com
  IdentityFile ~/.ssh/id_ed25519

# Work account
Host github.com-work
  HostName github.com
  IdentityFile ~/.ssh/id_ed25519_work

Then clone using the Host alias:

git clone [email protected]:username/repo.git
git clone [email protected]:company/repo.git

Verification

ssh -T [email protected]
# Hi username! You've successfully authenticated, but GitHub does not provide shell access.

git push origin main
# Should succeed

Prevention

  • Use ED25519 keys — they’re more secure and shorter than RSA
  • Add your key to the macOS Keychain with UseKeychain yes so it survives reboots
  • Document which keys are for which accounts in comments in ~/.ssh/config
  • Test with ssh -T [email protected] before troubleshooting anything else

References


Advertisement