clockworklabs/SpacetimeDB · error

Permission denied publishing environment values

Error message

Permission denied publishing environment values

What it means

After uploading environment values, the server responded with `PublishResult::PermissionDenied`, meaning the caller's identity is not authorized to modify the environment of the target database. The CLI surfaces this as a hard error and the publish of environment values fails.

Solutions

  1. Log in / set the CLI identity that owns the database (`spacetime login`, `spacetime identity list`).
  2. Publish the environment using the credentials of the database owner.
  3. Verify you are targeting the intended database identity/host.

Example fix

// before
spacetime publish --server main db-name  # wrong identity
// after
spacetime login  # as database owner
spacetime publish --server main db-name
Defensive patterns

Strategy: fallback

Validate before calling

let identity = std::process::Command::new("spacetime").args(["identity","list"]).output()?; // confirm the owner identity is active before publishing

Try / catch

match result { Err(e) if e.to_string().contains("Permission denied publishing environment") => { eprintln!("Switch to the database-owner identity (spacetime login) and retry"); }, Err(e) => return Err(e), Ok(v) => v }

Prevention

When it happens

Trigger: Calling `spacetime publish`/env publish for a database owned by a different identity; using a CLI identity that lost owner privileges; targeting the wrong database whose owner is another account.

Common situations: Switching machines or CI runners with a different logged-in identity; team projects where only the database owner may publish; revoked permissions after org changes.

Understand the failure class

Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.

Related errors


AI-assisted analysis of clockworklabs/SpacetimeDB@eddf9f5014 (2026-09-20). Data as JSON: /api/errors/7eb724e038761650. Report an issue: GitHub.

Appendix: source

Thrown at crates/cli/src/subcommands/publish/environment.rs:154

        .body(request.encode()?)
        .send()
        .await?;
    anyhow::ensure!(
        response.status().is_success(),
        "Environment publish failed with HTTP {}",
        response.status()
    );
    match response
        .json::<spacetimedb_client_api_messages::name::PublishResult>()
        .await
        .map_err(|_| anyhow::anyhow!("Invalid publish response"))?
    {
        spacetimedb_client_api_messages::name::PublishResult::Success { database_identity, .. } => {
            println!("Updated environment for database {database_identity}");
            Ok(())
        }
        spacetimedb_client_api_messages::name::PublishResult::PermissionDenied { .. } => {
            anyhow::bail!("Permission denied publishing environment values")
        }
    }
}

View on GitHub (pinned to eddf9f5014)