clockworklabs/SpacetimeDB · error
Permission denied publishing environment values
Error message
Permission denied publishing environment values
What it means
After uploading environment values, the server responded with `PublishResult::PermissionDenied`, meaning the caller's identity is not authorized to modify the environment of the target database. The CLI surfaces this as a hard error and the publish of environment values fails.
Solutions
- Log in / set the CLI identity that owns the database (`spacetime login`, `spacetime identity list`).
- Publish the environment using the credentials of the database owner.
- Verify you are targeting the intended database identity/host.
Example fix
// before spacetime publish --server main db-name # wrong identity // after spacetime login # as database owner spacetime publish --server main db-name
Defensive patterns
Strategy: fallback
Validate before calling
let identity = std::process::Command::new("spacetime").args(["identity","list"]).output()?; // confirm the owner identity is active before publishing Try / catch
match result { Err(e) if e.to_string().contains("Permission denied publishing environment") => { eprintln!("Switch to the database-owner identity (spacetime login) and retry"); }, Err(e) => return Err(e), Ok(v) => v } Prevention
- Publish environment changes with the identity that owns the database.
- Verify active identity with `spacetime identity list` before CI publishes.
- Confirm the target database identity/host matches the one you own.
When it happens
Trigger: Calling `spacetime publish`/env publish for a database owned by a different identity; using a CLI identity that lost owner privileges; targeting the wrong database whose owner is another account.
Common situations: Switching machines or CI runners with a different logged-in identity; team projects where only the database owner may publish; revoked permissions after org changes.
Understand the failure class
Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.
Related errors
- Aborted.
- Cannot read environment schema: HTTP
- Cannot use module-specific arguments
- --env-only cannot reset a database
- Environment key count exceeds limit
AI-assisted analysis of clockworklabs/SpacetimeDB@eddf9f5014 (2026-09-20).
Data as JSON: /api/errors/7eb724e038761650.
Report an issue: GitHub.
Appendix: source
Thrown at crates/cli/src/subcommands/publish/environment.rs:154
.body(request.encode()?)
.send()
.await?;
anyhow::ensure!(
response.status().is_success(),
"Environment publish failed with HTTP {}",
response.status()
);
match response
.json::<spacetimedb_client_api_messages::name::PublishResult>()
.await
.map_err(|_| anyhow::anyhow!("Invalid publish response"))?
{
spacetimedb_client_api_messages::name::PublishResult::Success { database_identity, .. } => {
println!("Updated environment for database {database_identity}");
Ok(())
}
spacetimedb_client_api_messages::name::PublishResult::PermissionDenied { .. } => {
anyhow::bail!("Permission denied publishing environment values")
}
}
}
View on GitHub (pinned to eddf9f5014)