Home·Error messages

docker · Docker

The message

unauthorized: incorrect username or password

What it means

The registry rejected the credentials you sent. More often than a mistyped password, this is a password sent to a registry that no longer accepts account passwords at all — Docker Hub takes only access tokens once two-factor is on, and the GitHub and GitLab registries have always wanted a token or deploy key. docker logout clears the stored credential, then docker login again with a token. Passing it as echo $TOKEN | docker login -u user --password-stdin keeps the token out of your shell history.

The fix

docker logout && docker login
Printed by
docker
Docker
12

Docker errors only become readable once you place them in a layer — the client failing to reach the daemon, the registry refusing you, a RUN failing during the build, and a container dying the instant it starts are four different problems — and for the build and run layers the line itself is not the reason: the reason is in the output of the command that was running inside, while the cost of each fix differs by layer too.

Reading an error message

  • Read from the first line down. The lower you go the more it is about the tool’s internals; the cause is usually at the top.
  • If there is a file and a line number, start there — not the top stack frame, but the topmost line that names a file you wrote.
  • Search the message verbatim, but strip your own paths and variable names first; those are what stop the search from matching.
  • The same condition is worded differently across tool versions. If results look wrong, add the version number to the query.
  • Before pasting a fix, check what it throws away. Some of these cannot be undone.

Common questions

Q. What does “unauthorized: incorrect username or password” mean?

The registry rejected the credentials you sent. More often than a mistyped password, this is a password sent to a registry that no longer accepts account passwords at all — Docker Hub takes only access tokens once two-factor is on, and the GitHub and GitLab registries have always wanted a token or deploy key. docker logout clears the stored credential, then docker login again with a token. Passing it as echo $TOKEN | docker login -u user --password-stdin keeps the token out of your shell history.

Q. How do I fix it?

docker logout && docker login — before running it, check the explanation above for what this command discards.

Q. Which tool prints this?

docker. It sits under Docker, and the message runs to 5 words.

Errors nearby