## TL;DR

`dbt deps` cannot authenticate to the private git repo in packages.yml. Switch the package entry to the SSH form of the URL and make sure the machine's SSH key is registered with the git host as a deploy key. Then rerun `dbt deps`.

## Error

```text
"dbt deps failed with git authentication error"
```

## Steps

1. Open `packages.yml` and check the `git` URL form for the failing package. Expected: you see whether it uses HTTPS or SSH.
2. Change HTTPS URLs to the SSH form (for example the SSH URL for your org and repo on the git host). Expected: the entry now uses SSH.
3. Verify the machine can reach the host over SSH using the git host's documented SSH connectivity test. Expected: an authenticated greeting, not a permission denied.
4. If SSH fails, add the machine's public SSH key to the git host as a deploy key with read access to the repo. Expected: the SSH test succeeds.
5. Run `dbt deps`. Expected: the package clones and installs without an auth error.

## When to use

- `dbt deps` fails with a git authentication or permission error.
- The package repo is private.

## When not to use

- The package is public (no auth needed; the problem is the URL or the revision).
- The error is about a package version conflict rather than authentication.

## Tool compatibility

- dbt Core 1.0 and later, any git host (GitHub, GitLab, Bitbucket, Azure DevOps).

## Variant phrasings

### dbt deps: repository not found on private package

The same auth failure wearing a different message; the host hides private repos from unauthenticated users.

### dbt deps hangs on a private repo

SSH prompting for a password non-interactively; the SSH key setup fixes this too.

## Why it happens

dbt shells out to git to clone package repos. Private repos reject anonymous clones, so the machine needs its own credential: an SSH key or an HTTPS credential helper.

## Edge cases

- Never commit secrets into packages.yml; use SSH keys or the machine's credential helper instead.
- In CI, inject the SSH key as a secret and start ssh-agent before `dbt deps`.
- Pin the package `revision` to a tag or SHA so rebuilds are reproducible once auth works.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst__Ner005JYfzH5gvj7A5chQ
