unauthorized: authentication required (docker push / pull)
The registry needs credentials for this operation and the request had none or had expired ones.
Seen on:
Docker
Meaning
Docker sends credentials per registry host from ~/.docker/config.json (or a credential helper). If you logged in to docker.io but push to ghcr.io, or your token expired (ECR tokens last 12 hours, GitHub PATs can expire), the registry answers unauthorized.
Common causes
- Not logged in to this registry host
- Token/password expired or revoked
- Credential helper failing silently
- CI job missing the login step
⚡ Quick fix
- docker login <registry-host> again
- For GHCR use a PAT with read:packages/write:packages
- For ECR run aws ecr get-login-password
Detailed fix by platform
Docker
echo $CR_PAT | docker login ghcr.io -u USERNAME --password-stdin
How to diagnose
- Host — Which registry is in the image name?
- Config — auths entry for that host?
- Token — Still valid and scoped?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AADSTS50126 AADSTS50126: Error validating credentials due to invalid username or password
- ACR unauthorized Azure Container Registry: unauthorized: authentication required, visit https://aka.ms/acr/authorization (AKS ErrImagePull 401)
- auth/invalid-credential Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
Most viewed in Docker
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026