Your Code. Your Rules.

Visibility

Every repository is either public or private, and that setting controls who can read it without signing in.

Public Repositories

A public repository allows anonymous, read-only access to the file tree, file viewer, blame, branch list, and tag pages - no sign-in required.

Private Repositories

A private repository requires an explicit read grant for any of the pages above - being the owner, holding an access right on the repository, or an organization/team grant. Anyone without one of those gets the same not-found response as a repository that does not exist, so a private repository's existence is never disclosed.

Deep Pages Always Require Sign-In

Summary

PagePublic repo, anonymousPublic repo, signed inPrivate repo
File tree, file viewer, blame, branches, tagsOpenOpenRequires read access
Commit log, commit detail, ref-to-ref diffRedirected to sign inOpenRequires read access