SSH "Permission denied (publickey)": the complete fix path
⏱️ 2 min read
What the error means
The server offered only publickey auth, and your key did not match any key in ~/.ssh/authorized_keys (or the file was not readable). The message is accurate: it is not a wrong password, it is a rejected key.
Checklist, fastest first
- Verbose it.
ssh -v user@hostshows exactly which keys are offered. If yours is not in the list, the client side is the problem; if it is offered and rejected, the server side is. - Is the right key loaded?
ssh-add -l. If empty:ssh-add ~/.ssh/id_ed25519. Usessh -i ~/.ssh/id_ed25519explicitly to test. - Permissions. This is the classic:
chmod 700 ~/.ssh chmod 600 ~/.ssh/authorized_keys chmod 600 ~/.ssh/id_ed25519
StrictModes rejects world-writable files silently. - Wrong username. Cloud images vary:
rooton Vultr,ubuntuon Ubuntu AWS/DigitalOcean images,ec2-useron Amazon Linux. - Pubkey not in authorized_keys.
ssh-copy-id user@hostdoes it correctly; or append manually and confirm withsudo cat /home/user/.ssh/authorized_keyson the server console.
Server-side settings that bite
On the server, check PubkeyAuthentication yes and that AuthorizedKeysFile was not redirected in sshd_config. After edits: sudo sshd -t && sudo systemctl reload sshd. Keep one console session open while testing lockouts.
Lockouts
If you are managing multiple boxes, key-based access plus a bastion beats password sprawl. For teams, device-aware access control is the grown-up version: NordLayer handles posture checks and per-device access. (Partner link.)