TL;DR: Re-run docker login for the registry and make sure the snyk process sees the same docker credentials your shell does, then re-run the scan. Snyk shells out to the container runtime with its own environment, so credentials stored for one user, one config file, or one socket path may not reach it. Aligning the credential stores fixes the pull.

```text
could not pull image: unauthorized
```

1. Prove the daemon can pull. Run `docker pull [IMAGE]`.
Expected: the pull succeeds. If it fails here too, the login really is broken and you fix docker login first.
2. Check which identity docker is using. Inspect your docker config to see which registry hosts have stored credentials, and confirm the image's registry host is among them.
Expected: the registry host for your image has an entry. A missing entry, or an entry under a different hostname (index.docker.io vs docker.io), explains the failure.
3. Refresh the login explicitly for that registry host. Run `docker login [REGISTRY-HOST]` and sign in.
Expected: login succeeds and the stored credentials update.
4. Re-run the snyk scan in the same shell and user context. Run `snyk container test [IMAGE]`.
Expected: snyk pulls the image and the scan proceeds past the pull stage.

## Use this when
- docker pull works but snyk container test says unauthorized
- the failure started after a password or token rotation
- snyk runs in CI while your login was done interactively on a different machine

## Not for this skill when
- docker pull also fails; that is a docker credentials problem, not a snyk problem
- the image does not exist or the tag was deleted; unauthorized can mask a missing image on some registries, so verify the tag exists
- the error is about the snyk API rather than the registry; check snyk auth separately

## Variant phrasings
### snyk container test cannot pull private image
### snyk says unauthorized pulling image that docker can pull
### snyk container scan registry authentication failed
### docker login works but snyk container test does not

## Why it happens
Snyk does not reuse your shell's memory of a login; it reads the docker credential store as the user and environment it runs in. A login done as you does not exist for a snyk process running as a different user, in a container with a different home directory, or with a docker config pointing elsewhere. Registry hostnames also have to match exactly, because credentials are keyed by host.

## Edge cases
- Short-lived registry tokens (ECR, GCR, ACR) expire. A login from this morning can be dead by afternoon; re-login when the failure appears out of nowhere.
- Credential helpers configured in the docker config must be on the PATH of the snyk process. A helper that works in your shell but is missing in CI produces exactly this error.
- Rootless docker and rootful docker use different sockets and configs. Snyk talking to one while you logged in to the other fails the pull.
- In CI, make sure the docker login step and the snyk step share the same user, home directory, and docker config location; splitting them across containers or users breaks the chain.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_j8G473WUzDjKcIPK9Ea1yg
