Skip to content

Instantly share code, notes, and snippets.

@paolocarrasco
Last active August 21, 2026 14:04
Show Gist options
  • Select an option

  • Save paolocarrasco/18ca8fe6e63490ae1be23e84a7039374 to your computer and use it in GitHub Desktop.

Select an option

Save paolocarrasco/18ca8fe6e63490ae1be23e84a7039374 to your computer and use it in GitHub Desktop.
How to understand the `gpg failed to sign the data` problem in git

Problem

You have installed GPG, then tried to perform a git commit and suddenly you see this error message after it 😰

error: gpg failed to sign the data
fatal: failed to write commit object

Understand the error (important to solve it later!)

To understand what's going on, first check what git is doing, so add GIT_TRACE=1 at the beginning of the command you used before (git commit or git rebase or git merge or anything like that):

GIT_TRACE=1 git commit

With that you can see what GPG is doing.

You will see something like this:

10:37:22.346480 run-command.c:637       trace: run_command: gpg --status-fd=2 -bsau <your GPG key>

(First thing would be to check if your GPG key is correct)

Execute that gpg command again in the command line:

gpg --status-fd=2 -bsau <your GPG key>

👆🏻 Executing this will give you a useful output that will allow you to see what happened in detail 🙌🏼

Check now the possible solutions based on your findings 👀

Some solutions

We can have many problems, but I list what I found and some solutions posted in the thread:

  1. It could be that the GPG key was expired: https://stackoverflow.com/a/47561300/532912

  2. Another thing could be that the secret key was not set properly (In my case the message said gpg: signing failed: No secret key as it can be see in the image below). image It means that is not finding the key that was set. You would need to set up the GPG key in Git (again):

    • List the secret keys available in GPG.
    gpg --list-secret-keys --keyid-format=long
    • Copy your key
    • Set your key for your user in git
    git config --global user.signingkey <your key>
  3. Another popular solution that could help was shared here by @NirajanMahara: https://gist.github.com/paolocarrasco/18ca8fe6e63490ae1be23e84a7039374?permalink_comment_id=3767413#gistcomment-3767413

  4. A specific and popular solution posted for mac users by @lehaiquantb suggests to install pinentry (I'm not a fan of installing stuff but if you are ok with it):

brew install pinentry-mac
echo "pinentry-program $(which pinentry-mac)" >> ~/.gnupg/gpg-agent.conf
killall gpg-agent
  1. You can see in the thread of this gist other ways to find the solution to other problems. I recommend to read the Github guide for signing commits with GPG.

Hope it helps!

@dan-developer

Copy link
Copy Markdown

It seems for every branch I have, I need to execute the export GPG_TTY=$(tty) command before committing.

Is there anyway around this?

It worked for me. Thank you!

@Phrozyn

Phrozyn commented Oct 14, 2022

Copy link
Copy Markdown

For me the issue is always simply the fact that my vscode terminal window is too small, git needs like half a screen's height and about the width of this comment section for it to surface the GPG prompt, otherwise it errors out and tells you that:

error: gpg failed to sign the data
fatal: failed to write commit object

so I enlarge the window and voila all fixed when I run git commit again.

@Jeff-Tian

Copy link
Copy Markdown

There's another situation:

sec   dsa3072/AAAAAAAAAAAAA 2010-05-05 [SC] [expires: 2030-05-05]
      BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
uid                 [ultimate] Author Name <author-email@domain.com>

While GitHub documentation operates with AAAAAAAAAAAAA in sections when you need to create and register the key in GPG, git requires BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB, i.e. git config --global user.signingkey BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB, instead of git config --global user.signingkey AAAAAAAAAAAAA

Hopefully, it helps someone.

It helped me, thanks!

@0xmovses

Copy link
Copy Markdown

worked for me thank you for this!

@pullsuzdesheloper

Copy link
Copy Markdown

Great! Thanks for your help!

@lucymonie

lucymonie commented Oct 24, 2022 •

Copy link
Copy Markdown

Thank you 🙏

@lnasc256

Copy link
Copy Markdown

thank you

@marionorthvolt

Copy link
Copy Markdown

I was trying to solve this for 2 days! thanks!

@Lippiece

Lippiece commented Dec 2, 2022 •

Copy link
Copy Markdown
  1. then use export GPG_TTY=$(tty)

It also helped to to set it permanently in ~/.profile on Ubuntu (to do so, append export GPG_TTY=$(tty) to the ~/.profile file).

@gcakir

gcakir commented Dec 12, 2022 •

Copy link
Copy Markdown

I had the same issue. The output of the command gpg --status-fd=2 -bsau was fine. It turns out my git config in the repo was the problematic. I deleted the [user] and [gpg] entries in .git/config, and then I reconfigured the pgp globally via git config --global gpg.program gpg and git config --global user.signingkey "<my signing key>" once again. Then it worked.

@truemiller

Copy link
Copy Markdown

4. echo "test" | gpg --clearsign

this worked for me +1

@sankita15

Copy link
Copy Markdown

I just killed the gpg-agent and started again and it worked for me

killall gpg-agent
gpg-agent daemon

@0x61nas

0x61nas commented Jan 12, 2023

Copy link
Copy Markdown

thanks, @paolocarrasco

@Honglin-Lu

Copy link
Copy Markdown

There's another situation:

sec   dsa3072/AAAAAAAAAAAAA 2010-05-05 [SC] [expires: 2030-05-05]
      BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
uid                 [ultimate] Author Name <author-email@domain.com>

While GitHub documentation operates with AAAAAAAAAAAAA in sections when you need to create and register the key in GPG, git requires BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB, i.e. git config --global user.signingkey BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB, instead of git config --global user.signingkey AAAAAAAAAAAAA

Hopefully, it helps someone.

This solution also works for me. Thank you!

@lfbharat

Copy link
Copy Markdown

omg I just need to run export GPG_TTY=$(tty)

  1. then use export GPG_TTY=$(tty)

this one worked for me as well.

@LuciNyan

LuciNyan commented Feb 1, 2023

Copy link
Copy Markdown

3. then use export GPG_TTY=$(tty)

Thank you! it works for me!

@livaper

livaper commented Feb 15, 2023

Copy link
Copy Markdown

Thank You, @paolocarrasco

@rootsongjc

Copy link
Copy Markdown

It works. Thank you!

@rahulsaw2003

Copy link
Copy Markdown

gpg: skipped "D6F50106F5C8A98B": No secret key
gpg: signing failed: No secret key
error: gpg failed to sign the data
fatal: failed to write commit object

I am getting this error since few days, I have regenerated the gpg key many times. but still I am getting this error. What should I do to get rid of this error. Please help as soon as possible.

@rahulsaw2003

Copy link
Copy Markdown

@exostin
After struggling for hours, I finally get rid of this error.
Thanks man

@kennethsequeira

Copy link
Copy Markdown

@NirajanMahara lifesaver!
Your solution worked out for me.

@thyarles

thyarles commented Mar 8, 2023

Copy link
Copy Markdown

I you're on WSL2, maybe this can help:

  • Add those lines to ~/.gnupg/gpg.conf

    use-agent 
    pinentry-mode loopback
    
  • Add this line to ~/.gnupg/gpg-agent.conf

    allow-loopback-pinentry
    

@gauravk-io

gauravk-io commented Apr 4, 2023 •

Copy link
Copy Markdown

I was getting the error

gpg: skipped "29D277CEFE65F74E": No secret key
gpg: signing failed: No secret key
error: gpg failed to sign the data
fatal: failed to write commit object

I just need to set the

gpg.program="C:\Program Files (x86)\GnuPG\bin\gpg.exe"

to

gpg.program=gpg

THANKYOU @victorjatoba

@Riessarius

Copy link
Copy Markdown

This exactly solved my problem. Great thanks! @victorjatoba

@renjujv

renjujv commented Apr 24, 2023

Copy link
Copy Markdown

@pro-akim

pro-akim commented May 2, 2023

Copy link
Copy Markdown

Thanks @paolocarrasco, you are awesome

@igorsobot

Copy link
Copy Markdown

I just killed the gpg-agent and started again and it worked for me

killall gpg-agent
gpg-agent daemon

Yes, sometimes pinentry-mac update brakes gpg-agent

@T410

T410 commented May 12, 2023

Copy link
Copy Markdown

Additionally, if you are using a mac and you are experiencing an issue, try step number 8: https://docs.github.com/en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key?platform=mac

$ brew install pinentry-mac
$ echo "pinentry-program $(which pinentry-mac)" >> ~/.gnupg/gpg-agent.conf
$ killall gpg-agent

basically, it allows/forces your device to ask the password of the key

@DejavuMoe

Copy link
Copy Markdown

Super useful, thank you very much!

@ghdcksgml1

Copy link
Copy Markdown

Thanks :) @T410

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment