dbt deps failed with git authentication error"
Fixes dbt deps git authentication failures for private package repos by switching packages.yml to the SSH URL form and registering the machine's SSH key with the git host. Use when dbt deps fails cloning a private repo. Not for public packages, which need no authentication.
TL;DR
dbt deps cannot authenticate to the private git repo in packages.yml. Switch the package entry to the SSH form of the URL and make sure the machine's SSH key is registered with the git host as a deploy key. Then rerun dbt deps.
Error
"dbt deps failed with git authentication error"Steps
- Open
packages.ymland check thegitURL form for the failing package. Expected: you see whether it uses HTTPS or SSH. - Change HTTPS URLs to the SSH form (for example the SSH URL for your org and repo on the git host). Expected: the entry now uses SSH.
- Verify the machine can reach the host over SSH using the git host's documented SSH connectivity test. Expected: an authenticated greeting, not a permission denied.
- If SSH fails, add the machine's public SSH key to the git host as a deploy key with read access to the repo. Expected: the SSH test succeeds.
- Run
dbt deps. Expected: the package clones and installs without an auth error.
When to use
dbt depsfails with a git authentication or permission error.- The package repo is private.
When not to use
- The package is public (no auth needed; the problem is the URL or the revision).
- The error is about a package version conflict rather than authentication.
Tool compatibility
- dbt Core 1.0 and later, any git host (GitHub, GitLab, Bitbucket, Azure DevOps).
Variant phrasings
dbt deps: repository not found on private package
The same auth failure wearing a different message; the host hides private repos from unauthenticated users.
dbt deps hangs on a private repo
SSH prompting for a password non-interactively; the SSH key setup fixes this too.
Why it happens
dbt shells out to git to clone package repos. Private repos reject anonymous clones, so the machine needs its own credential: an SSH key or an HTTPS credential helper.
Edge cases
- Never commit secrets into packages.yml; use SSH keys or the machine's credential helper instead.
- In CI, inject the SSH key as a secret and start ssh-agent before
dbt deps. - Pin the package
revisionto a tag or SHA so rebuilds are reproducible once auth works.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst__Ner005JYfzH5gvj7A5chQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.