Start with the exact action and full error: does clone, fetch, or pull work while git push fails, or does GitHub reject the connection altogether? “Permission denied (publickey),” “Permission to user/repo denied to other-user,” and “Access denied by policy settings” point to different failure stages and need different fixes.
First identify what is being denied
Separate four possible stages: reaching the expected GitHub host and repository, authenticating as an account or app, being authorized for that repository and operation, and satisfying a product or organization policy. Record the command or action and the complete error before changing credentials.
- Clone, fetch, or pull succeeds but push fails: the credential may authenticate and permit reading while the account lacks write access. This is usually a repository-permission issue, not a broken key.
- SSH reports
Permission denied (publickey): GitHub rejected the SSH authentication attempt. Check the host, offered key, agent, and account association. - Authentication succeeds but one repository is denied: the account may not have access, or the SSH key may be a deploy key restricted to a different repository.
- The message mentions policy, subscription, or OAuth
access_denied: investigate the named product’s entitlement or organization settings, or whether the user declined an app authorization.
Check that Git is targeting the intended repository
From the repository directory, run:
git remote -v
Confirm the displayed owner, repository name, host, and protocol. A typo, an unexpected remote, or a repository that has moved or been renamed can resemble an access denial. Note whether the URL begins with an SSH form such as [email protected]: or an HTTPS form such as https://github.com/; the checks differ by protocol.
For SSH: distinguish authentication from repository access
Test which GitHub account the SSH key authenticates
Run:
ssh -T [email protected]
Use git as the SSH username; do not substitute your GitHub account name. A successful test greets the account, for example: “Hi USERNAME! You’ve successfully authenticated, but GitHub does not provide shell access.” This confirms which account authenticated, not whether it can access every repository. The test may return exit code 1 despite a successful greeting, so do not treat that exit code alone as proof authentication failed. See GitHub’s SSH connection test.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
If the public-key authentication fails
GitHub says a “Permission denied” error means the server rejected the connection. Use verbose SSH output to see what the client offers, then check the agent and account key settings:
ssh -vT [email protected]
ssh-add -l -E sha256
- In the verbose output, check that the client is connecting to
github.comand offering the intended key. - Confirm that the intended identity is loaded in the SSH agent. If it is not, load the appropriate key using your system’s SSH-agent procedure.
- Compare the key fingerprint with the public key listed under SSH keys in the GitHub account you intend to use.
- Avoid running Git with
sudowhen the key is configured for your ordinary user; the elevated process may use a different account’s SSH configuration or agent.
GitHub’s public-key troubleshooting guide covers host, username, key selection, and agent checks.
Rank #2
If SSH authenticates but the repository is denied
Use the greeting to verify the account is the one expected. Then ask the repository owner or organization administrator to check that account’s repository access and the permission needed for the requested operation. Also check whether the key is a deploy key attached to a different repository: a successful SSH test does not make a repository-specific deploy key valid for another repository. GitHub explains this distinction in its repository access troubleshooting guidance.
When reading works but writing does not
Read access and write access are different authorization levels. If clone, fetch, or pull works but push is rejected, the fact that the credential authenticates successfully does not establish that it may write. Ask the repository owner or organization administrator for the access required to push. Do not repeatedly replace or rotate a key or token that already authenticates as the correct account; a credential change cannot grant repository permission.
Rank #3
For HTTPS, tokens, or app and CLI credentials
Find out which credential the failing operation actually uses before changing it. A machine may have a stored HTTPS credential, an environment token, or an app or CLI authorization, and the active credential may belong to a different account than expected.
- Verify the account associated with the credential, and whether the credential is valid and unexpired.
- Check that its repository selection or scope includes the target repository.
- Check that it has the permission required for the specific operation. A token that permits reading may not permit pushing or another write action.
- Prefer the narrowest repository access and permissions that complete the task. Exact permissions vary with the GitHub operation and product, so use that product’s current permission guidance rather than granting broad access by default.
Codespaces repository credentials
GitHub’s Codespaces repository-authentication guidance says the default HTTPS credential is a GITHUB_TOKEN configured to access the source repository. If the Codespace needs another repository, configure only the required access; that can include Contents permission where appropriate. Follow GitHub’s guidance for allowing a Codespace to access a repository, and match the permissions to the actual operation.
When the denial names policy, Copilot CLI, or OAuth
Policy or product entitlement
“Access denied by policy settings” is not the same as an SSH key rejection or a missing repository write permission. Check the organization policy and the entitlement for the specific product or feature named by the message. For example, GitHub documents policy and entitlement checks for Copilot CLI; an organization administrator may need to enable the relevant access. Do not apply Copilot-specific remedies to ordinary Git clone or push errors.
OAuth authorization declined
An OAuth callback containing access_denied can mean the user rejected the application’s authorization request, rather than that Git itself lacks repository permission. The relevant OAuth troubleshooting page is for GitHub Enterprise Server 3.18; it describes redirecting to the registered callback URL with parameters that summarize the error. Confirm the product, server edition, and complete callback error before following that branch: Troubleshooting authorization request errors.
Recommended Free Tools
Quick Recap
Best Value
Choose the remedy that matches the failure stage
| What you observe | Likely stage | What to check next |
|---|---|---|
Permission denied (publickey) |
SSH authentication | Host and SSH username, key offered, agent identity, and whether the public key belongs to the intended GitHub account. |
| SSH greeting names the expected account, but one repository is denied | Repository authorization or repository-specific key scope | Account membership and permission; whether the key is a deploy key attached to another repository. |
| Read operations work; push fails | Write authorization | Ask the repository owner or organization administrator for the required write access. |
| HTTPS or CLI action fails despite using the expected account | Token or app scope and permissions | Active credential, validity, account, repository selection, and operation-specific permission. |
Message names policy, entitlement, or OAuth access_denied |
Product policy or app authorization | Check the named product’s organization settings or entitlement, or whether OAuth authorization was declined. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




