Visibility
Every repository is either public or private, and that setting controls who can read it without signing in.
Public Repositories
A public repository allows anonymous, read-only access to the file tree, file viewer, blame, branch list, and tag pages - no sign-in required.
Private Repositories
A private repository requires an explicit read grant for any of the pages above - being the owner, holding an access right on the repository, or an organization/team grant. Anyone without one of those gets the same not-found response as a repository that does not exist, so a private repository's existence is never disclosed.
Deep Pages Always Require Sign-In
Note: the commit log, commit detail, and ref-to-ref diff pages require sign-in even on a public repository - an anonymous visitor is redirected to log in first instead of seeing the page. This applies only to those three pages; the file tree, file viewer, blame, branches, and tags stay open to anonymous visitors on a public repository.
Summary
| Page | Public repo, anonymous | Public repo, signed in | Private repo |
|---|---|---|---|
| File tree, file viewer, blame, branches, tags | Open | Open | Requires read access |
| Commit log, commit detail, ref-to-ref diff | Redirected to sign in | Open | Requires read access |