{"record":{"id":"7eb724e038761650","repo":"clockworklabs/SpacetimeDB","slug":"permission-denied-publishing-environment-values","errorCode":null,"errorMessage":"Permission denied publishing environment values","messagePattern":"Permission denied publishing environment values","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/cli/src/subcommands/publish/environment.rs","lineNumber":154,"sourceCode":"        .body(request.encode()?)\n        .send()\n        .await?;\n    anyhow::ensure!(\n        response.status().is_success(),\n        \"Environment publish failed with HTTP {}\",\n        response.status()\n    );\n    match response\n        .json::<spacetimedb_client_api_messages::name::PublishResult>()\n        .await\n        .map_err(|_| anyhow::anyhow!(\"Invalid publish response\"))?\n    {\n        spacetimedb_client_api_messages::name::PublishResult::Success { database_identity, .. } => {\n            println!(\"Updated environment for database {database_identity}\");\n            Ok(())\n        }\n        spacetimedb_client_api_messages::name::PublishResult::PermissionDenied { .. } => {\n            anyhow::bail!(\"Permission denied publishing environment values\")\n        }\n    }\n}\n","sourceCodeStart":136,"sourceCodeEnd":158,"githubUrl":"https://github.com/clockworklabs/SpacetimeDB/blob/eddf9f5014579a50d4b67630e28b6e15cad9c4af/crates/cli/src/subcommands/publish/environment.rs#L136-L158","documentation":"After uploading environment values, the server responded with `PublishResult::PermissionDenied`, meaning the caller's identity is not authorized to modify the environment of the target database. The CLI surfaces this as a hard error and the publish of environment values fails.","triggerScenarios":"Calling `spacetime publish`/env publish for a database owned by a different identity; using a CLI identity that lost owner privileges; targeting the wrong database whose owner is another account.","commonSituations":"Switching machines or CI runners with a different logged-in identity; team projects where only the database owner may publish; revoked permissions after org changes.","solutions":["Log in / set the CLI identity that owns the database (`spacetime login`, `spacetime identity list`).","Publish the environment using the credentials of the database owner.","Verify you are targeting the intended database identity/host."],"exampleFix":"// before\nspacetime publish --server main db-name  # wrong identity\n// after\nspacetime login  # as database owner\nspacetime publish --server main db-name","handlingStrategy":"fallback","validationCode":"let identity = std::process::Command::new(\"spacetime\").args([\"identity\",\"list\"]).output()?; // confirm the owner identity is active before publishing","typeGuard":null,"tryCatchPattern":"match result { Err(e) if e.to_string().contains(\"Permission denied publishing environment\") => { eprintln!(\"Switch to the database-owner identity (spacetime login) and retry\"); }, Err(e) => return Err(e), Ok(v) => v }","preventionTips":["Publish environment changes with the identity that owns the database.","Verify active identity with `spacetime identity list` before CI publishes.","Confirm the target database identity/host matches the one you own."],"tags":["cli","permissions","publish","environment"],"backgroundTag":"permission-denied","analyzedSha":"eddf9f5014579a50d4b67630e28b6e15cad9c4af","analyzedAt":"2026-09-20T12:15:59.611Z","contentChangedAt":"2026-09-20T12:15:59.611Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}