You think the public key is registered on the server, but SSH still ends with Permission denied (publickey). Before generating another key, check which account you are logging into, where that account's public key is registered, and whether its file permissions are too open. Creating a key, registering it, and authenticating with it are separate steps.
Register the public key for the account you log into
Keep the private key on the client and register the public key in the target account's authorized_keys. During login, sshd checks the key and signature. Also check the account and file owner, not just common permissions such as .ssh at 700 and authorized_keys at 600.
ssh-keygen creates a public/private key pair. Store the private key safely on the connecting machine and add only the public key to the target account's ~/.ssh/authorized_keys. ssh-copy-id helps install that public key for the specified account.
ssh-copy-id learner@example.invalid
ssh learner@example.invalidThe address is illustrative. Even if the first command succeeds, the second may still fail. Logging in as a different user points SSH at a different home directory and authorized_keys file. Compare the username and host in the command with the account where the key was installed. Never paste a private key into a chat or issue while troubleshooting.
Which file permissions should you check?
On the server, inspect the files as the target account. These commands provide a basic check of the public-key registration path:
ls -ld ~/.ssh
ls -l ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keyschmod 600 allows the owner to read and write the file and grants no permissions to others. Before changing anything, confirm that you are logged into the intended account. Changing permissions in another account's home directory will not fix this login. Check ownership of .ssh and authorized_keys, along with permissions on parent directories. Matching one numeric mode does not resolve every authentication problem.
What if the key is still rejected?
Check which key the client actually offers and whether it matches the public key expected by the server. If you have several private keys, verify that the intended one is selected. The server's SSH authentication logs may explain why a public key was rejected. Redact usernames and host details before sharing logs or diagnostics.
Do not disable public-key authentication, casually enable password login, or make .ssh and key files readable by everyone just to get past the error. Before adjusting access to a running service, make sure you have a recovery path in case you lose your connection. Change one item at a time and consider the service's access policy and audit trail.
Key takeaways
For Permission denied (publickey), first check the login account, that account's authorized_keys, and ownership and permissions along the path. Keep the private key private, and do not widen permissions as a temporary workaround.

