DocuGate

Can a GitHub Pages site be private?

Only on GitHub Enterprise Cloud. What private Pages means, and the other ways to keep docs published from a repository readable by the right people only.

By ·

The short answer

Only on GitHub Enterprise Cloud. As of October 2026, GitHub lets an organisation restrict a Pages site to people who can read its repository, but only on Enterprise Cloud. On every other plan a Pages site is public to anyone with the URL, even when the repository behind it is private.

The short answer

GitHub Pages publishes static files, and for nearly every account those files are public. As of October 2026, the only way to make GitHub itself check who is reading is to own the repository in an organisation on GitHub Enterprise Cloud, where a site's visibility can be set to private. A private site is then readable only by people with read access to the repository. On any other plan, if the site needs to be private, the gate has to come from somewhere else.

What "private" means on Enterprise Cloud

With private visibility, GitHub asks the reader to sign in and checks that their account can read the repository. That is a good fit for internal engineering docs, because the people who should read them are usually the people who already have the code.

It is a poor fit for anyone outside that group. A customer, a contractor or a support agent has to be given repository access to read a page, which also gives them the code and its history.

The options

OptionWho decides accessCost, as of October 2026Good for
GitHub Enterprise Cloud, private PagesRepository read accessEnterprise Cloud pricingOrganisations already on Enterprise Cloud
Move the built site to a host with password protectionThe host's settingsCheck your host's plan; often a paid tierA small team that shares one password
An identity proxy in front of the site (Cloudflare Access, oauth2-proxy)Rules you write in the proxyCloudflare Access has a free tier for small teams; oauth2-proxy is free to run on your own serverTeams comfortable running infrastructure
A platform that reads the repository and gates it, such as DocuGateRepository access, or a named listDocuGate Pro is $5/mo for private repositoriesDocs that should follow the repo, or go to named outsiders

None of these is wrong. The proxy route keeps your existing static site generator and costs only setup time. The platform route drops the build step and gives each reader a sign-in of their own.

Getting private-Pages behaviour without Enterprise Cloud

DocuGate reads the markdown folder from a GitHub repository and serves it as a documentation space, with no build step. Its Repo access mode makes the same decision private Pages does: the reader signs in with GitHub, and the server fetches the page with that reader's own token, so GitHub answers whether they may see it. Nothing is copied into a separate permission list.

  1. Sign up with GitHub at /sign-up and install the GitHub App on the repository.
  2. Open Dashboard → New space, choose the repository, the branch and the docs folder.
  3. Set access to Repo access and create the space.
  4. Push to the branch as usual. The next request reads the new commit.

If some readers should not have the repository, use Allowlist instead and list their GitHub logins or email addresses. See access control for how each mode decides, and pricing for the plans: Starter is free for one space from a public repository, and private repositories need Pro.

Questions people also ask

If my repository is private, is my GitHub Pages site private too?

No. Outside Enterprise Cloud, the visibility of the repository and the visibility of the site are separate. The source stays private; the published HTML is public to anyone who has or guesses the URL.

Does a noindex tag or robots.txt make a Pages site private?

No. It asks search engines not to list the site, and well-behaved ones comply. Anyone with the link can still read every page, and a link shared once can travel anywhere.

Can private Pages on Enterprise Cloud be shared with someone outside my organisation?

Only by giving them read access to the repository, because that is what the site checks. For a client or partner who should read the docs but not the code, you need a gate that is separate from repository access.

Is there a cheaper way to get the same behaviour as private Pages?

DocuGate's Repo access mode does the same check: a reader signs in with GitHub and can read the space only if GitHub says they can open the repository. Spaces from private repositories need Pro, which is $5 a month.

Read next

Get started with DocuGate, free.