TL;DR: The credentials are wrong or stale. Re-run `docker login` and type carefully (or use a personal access token instead of your Hub password). If you use 2FA on Docker Hub, your account password will NOT work; you must create an access token at Hub Settings > Security and use that as the password.

## The error

```text
Error response from daemon: Get "https://registry-1.docker.io/v2/": unauthorized: incorrect username or password
```

## Fix it

1. Log in fresh:
   `docker login`
   Expected: prompts for username and password, then `Login Succeeded`.
2. On Docker Hub with 2FA: create a Personal Access Token (Hub > Account Settings > Security > New Access Token) and paste the token at the password prompt.
3. Verify:
   `docker pull [private-image]`
   Expected: succeeds.

## When this applies
- `docker login` rejected
- Authenticated pulls failing after a password change

## When this does NOT apply
- Cloud registries (ECR/GCR/ACR use short-lived tokens; different flow)
- "authentication required" with no credential attempt (never logged in)

## Versions
All Docker versions; Docker Hub behavior.

## Why it happens
The registry validates the basic-auth pair on every token request. Wrong password, changed password, or Hub-side 2FA (which disables password auth for the CLI) all produce this exact message.

## Edge cases
- Special characters in passwords can break non-interactive `docker login -u user -p` (shell interpolation); prefer interactive login or --password-stdin.
- Stale entries in ~/.docker/config.json or the credential helper override fresh logins; `docker logout` clears them.
- Rate-limited anonymous pulls show toomanyrequests, not unauthorized; do not confuse them.
