Sign-in Passkeys, authenticator apps and company accounts
The safe harbor for your code.
The European git platform where the server enforces the rules, for everyone: no force-pushes to protected branches, no secrets in your history, an audit log nobody can rewrite. You focus on the code.
A local hook can be switched off, a convention can be forgotten. Here the check runs on every push, and the rejection is explained right in the terminal of whoever tried it, in their own language.
No force-push on protected branches
Immutable release tags
Owners and admins included
~/next-platform
Example: a force-push to the protected main branch is rejected by the server, which explains why and suggests integrating the remote changes with fetch plus merge or rebase.
$git push --force origin main
Enumerating objects: 9, done.
Writing objects: 100% (5/5), 1.12 KiB | 1.12 MiB/s, done.
remote:
remote: CodeQuay: push REJECTED
remote: - branch 'main' is protected: force-push not allowed
remote: - integrate the remote changes with fetch + merge or rebase
remote:
! [remote rejected] main -> main (pre-receive hook declined)$
Sign-up is open: anyone can create an account at git.codequay.it/signup and start on the Free plan, then upgrade online to Team or Business whenever they like.
If someone invites your email address to an organization, a project or a repository, you can also create your account from the invitation link: the address counts as already verified.
What is a passkey, and how do I use one on CodeQuay?
A passkey is a credential that replaces your password: it lives on your device or in your password manager and is unlocked with your fingerprint, face or PIN. It's bound to the site it was created for, so a look-alike page can't use it, which makes it the strongest protection against phishing.
On CodeQuay you add one after your first sign-in, from Settings → Security. From then on you sign in by picking the passkey, with no password and no codes: a passkey unlocked with your fingerprint, face or PIN already counts as strong authentication.
You can register more than one, for example on your laptop and your phone. Passkeys synced by iCloud Keychain, Google Password Manager or a password manager are available on all your devices, and hardware security keys work too.
The push is rejected. CodeQuay scans the new files in every push and stops any that contain recognizable credentials: private keys, AWS access keys, Google API keys, live Stripe keys, GitHub tokens, Slack tokens and CodeQuay personal tokens. The message points to the file and line and shows only the start of the value; the audit log records the rule that was broken, never the secret.
To move on, remove the secret from the history (a later commit that deletes it isn't enough) and revoke the credential. If the secret was already in the history of an imported repository, the import scan flags it: in that case it needs to be rotated.
Can I migrate from GitHub and keep my full history?
Yes. You authorize the instance key as a deploy key on the GitHub repository and start the import: it copies every branch and every tag with the full history (pull requests aren't imported), protects the default branch and scans the entire history for secrets, reporting type, file, line and commit without ever showing the value. If it's interrupted, just run it again and it picks up where it left off.
Developers only need to change the remote URL in their existing clones: commits, hashes, branches and tags stay the same. Coming from another git platform? Use git clone --mirror and git push --mirror.
Repositories, databases and backups stay in data centers in the European Union. CodeQuay is built in Italy by arimaslab srl, and neither the website nor the platform uses third-party tracking, analytics or advertising.
Prices are per user, excluding VAT, billed monthly or yearly (which costs less), and they're published on the Pricing page:
Free: €0
Team: €6 per user per month, or €60 per user per year (2 months free)
Business: €18 per user per month, or €180 per user per year (2 months free)
Sovereign: Custom quote
Protections, secret blocking at push, the audit log and tested backups are included in every plan; a dedicated instance, in the EU or on your premises, is quoted on request.