Frequently asked questions
Straight answers to common questions
How to get started, how to sign in, what happens when you push and where your data lives. Everything here is what the platform does today.
Getting started
-
What is CodeQuay?
CodeQuay is a platform for hosting git repositories, built in Italy by arimaslab srl and running in data centers in the European Union. You use the git you already know (clone, branch, push and tag over HTTPS or SSH), and the web console lets you browse code, history, blame and comparisons.
The difference is that the server enforces the rules: protected branches, immutable tags, secret blocking at push time and an append-only audit log apply to everyone, owners and admins included.
-
How do I get an account?
Sign-up is open: anyone can create an account at git.codequay.it/signup and start on the Free plan, then upgrade online to Team or Business whenever they like.
If someone invites your email address to an organization, a project or a repository, you can also create your account from the invitation link: the address counts as already verified.
-
Can I have personal repositories as well as company ones?
Yes. Every account comes with a personal space for experiments, notes and side projects: repositories you create there are visible only to you and the people you invite. Instance administrators can't see their code unless you invite them; all they see is how many repositories you have.
Work code belongs in company organizations, where members get access based on their role and administrators keep full control.
-
How do I invite a colleague?
Owners of an organization or project open Members and click Invite; for a single repository, being a maintainer is enough, from Settings → Collaborators. Enter your colleague's email, or their username if they already have an account, and a role such as reader, developer or maintainer. You can't grant a role higher than your own.
Invitations are valid for 7 days and, while pending, can be resent or revoked. The invitee accepts from the link in the email or from the console.
-
What language is CodeQuay in?
English and Italian. Everyone picks their language in their profile settings: the console, emails and git messages (such as the explanation of a rejected push) follow it. The messages for a push follow the language of whoever pushed.
Sign-in and security
-
What is a passkey, and how do I use one on CodeQuay?
A passkey is a credential that replaces your password: it lives on your device or in your password manager and is unlocked with your fingerprint, face or PIN. It's bound to the site it was created for, so a look-alike page can't use it, which makes it the strongest protection against phishing.
On CodeQuay you add one after your first sign-in, from Settings → Security. From then on you sign in by picking the passkey, with no password and no codes: a passkey unlocked with your fingerprint, face or PIN already counts as strong authentication.
You can register more than one, for example on your laptop and your phone. Passkeys synced by iCloud Keychain, Google Password Manager or a password manager are available on all your devices, and hardware security keys work too.
-
Is two-factor authentication required?
It depends on the instance: administrators can make it mandatory, in which case anyone who hasn't set it up can't make changes until they do. Even when it's optional, we recommend it for everyone.
As a second factor you can use an authenticator app, set up with a QR code and backed by recovery codes you keep safe, or a passkey. If you lose both your phone and your recovery codes, an administrator can reset your two-factor authentication.
-
Can I sign in with Google, Microsoft, Apple or my company SSO?
Yes. CodeQuay supports signing in with Google, Apple, Microsoft 365 and any company identity provider compatible with OpenID Connect (OIDC). The buttons on the sign-in page depend on the providers your instance administrators have configured.
You can link several sign-in methods to one account; the last one can't be unlinked, so you never lock yourself out.
-
How do I clone and push?
With the git you already use, over HTTPS or SSH. Every repository has a Clone button that shows the right address for both.
- HTTPS: create a personal access token under Settings → Access tokens with the
git:readandgit:writescopes, and use it as your password when git asks for one. - SSH: add your public key under Settings → SSH keys (don't have one?
ssh-keygen -t ed25519) and use the repository's SSH address.
The rules are the same for both protocols: protections, secret blocking and the audit log always apply.
- HTTPS: create a personal access token under Settings → Access tokens with the
-
Do access tokens expire?
Yes, always: an expiry date is mandatory, up to one year. Each token has separate scopes for git and for the API, so a script only gets the permissions it needs, and you can revoke a token at any time with immediate effect.
A token is shown only once, when you create it: CodeQuay stores a cryptographic fingerprint of it, never the value.
Git and migration
-
What happens if I force-push to main?
If main is a protected branch, the server rejects the push before accepting it and tells you in your terminal which rule stopped it and what to do next, usually integrating the remote changes with fetch and merge or rebase. Deleting a protected branch is blocked too, and the rule applies to owners and admins as well. The attempt is recorded in the audit log.
Protections are set by pattern, such as
mainorrelease/*, choosing the minimum role allowed to push for each one. In imported repositories the default branch is already protected. -
What if I accidentally commit a key or a token?
The push is rejected. CodeQuay scans the new files in every push and stops any that contain recognizable credentials: private keys, AWS access keys, Google API keys, live Stripe keys, GitHub tokens, Slack tokens and CodeQuay personal tokens. The message points to the file and line and shows only the start of the value; the audit log records the rule that was broken, never the secret.
To move on, remove the secret from the history (a later commit that deletes it isn't enough) and revoke the credential. If the secret was already in the history of an imported repository, the import scan flags it: in that case it needs to be rotated.
-
Can I move or delete a release tag?
Not if the tag matches an immutable tag pattern, such as
v*: once created,v2.4.0always points to the same code and can't be moved or deleted, not even by an administrator. To ship a fix, you publish a new version. -
Can I migrate from GitHub and keep my full history?
Yes. You authorize the instance key as a deploy key on the GitHub repository and start the import: it copies every branch and every tag with the full history (pull requests aren't imported), protects the default branch and scans the entire history for secrets, reporting type, file, line and commit without ever showing the value. If it's interrupted, just run it again and it picks up where it left off.
Developers only need to change the remote URL in their existing clones: commits, hashes, branches and tags stay the same. Coming from another git platform? Use
git clone --mirrorandgit push --mirror. -
Can I migrate from GitLab, Bitbucket or another git server?
Yes, with standard git: create an empty repository on CodeQuay, run
git clone --mirroragainst the source server andgit push --mirrorto CodeQuay. Branches, tags and history arrive unchanged, with the same hashes. That push goes through the server's rules too: protections and secret blocking apply just as they do to any other push.Issues, merge requests and pipelines aren't part of the git repository and aren't copied. The guided import, with a secret scan of the full history, is available for GitHub repositories.
-
Will my GitHub Actions CI keep working?
Yes. After the import you turn on mirroring to GitHub: every push CodeQuay accepts is replicated to the GitHub repository within seconds, and the replicated pushes trigger your
on: pushworkflows just like today. Secrets and environments stay on GitHub.From then on, everyone pushes to CodeQuay only and GitHub becomes a copy. If GitHub doesn't respond, CodeQuay retries with increasing delays and alerts administrators, without slowing down developers' pushes.
Alternatively, your workflows can move to CodeQuay Actions, which uses the same syntax: at that point you no longer need the mirror to GitHub.
-
Does CodeQuay have built-in CI/CD?
Yes, CodeQuay Actions. Workflows in
.github/workflowsuse GitHub Actions syntax and run on CodeQuay runners: pushes to branches and tags, manual runs with inputs, scheduled runs and reusable workflows. Secrets and variables are encrypted per organization, project, repository and environment, and an environment can require approval before a deployment.Public actions such as
actions/checkoutare served from a mirror on CodeQuay: runs don't depend on github.com. For most existing workflows, only the registry, secrets and runner labels change. -
How many CI minutes are included? Can I use my own runners?
CodeQuay Actions jobs run on Linux runners managed by us or on your own self-hosted runners. Every plan includes a monthly allowance of minutes on CodeQuay runners and a maximum number of self-hosted runners:
- Free: Minutes a month on CodeQuay runners: 2,000 · Self-hosted runners: 1
- Team: Minutes a month on CodeQuay runners: 3,000 · Self-hosted runners: 5
- Business: Minutes a month on CodeQuay runners: 25,000 · Self-hosted runners: Unlimited
- Sovereign: Minutes a month on CodeQuay runners: Custom · Self-hosted runners: Unlimited
On paid plans, minutes beyond the allowance are pay-as-you-go, within a spending cap set by the organization owner, and a dedicated runner managed by us is also available. Rates are on the Pricing page.
Data and compliance
-
Who can see my repositories?
Only their members: of the organization, of the project, or as a collaborator on that single repository, with inherited roles and per-user restrictions. For everyone else the repository doesn't exist: it doesn't appear in lists or searches, and its direct URL returns 404, just like a repository that doesn't exist. The same check applies to the console, the API and git, and a dedicated automated test suite verifies it.
In company organizations, instance administrators have full access; in personal spaces they don't, unless you invite them.
-
Where is my data stored?
Repositories, databases and backups stay in data centers in the European Union. CodeQuay is built in Italy by arimaslab srl, and neither the website nor the platform uses third-party tracking, analytics or advertising.
-
How does CodeQuay help with GDPR?
Data stays in data centers in the European Union, and neither the website nor the platform uses third-party tracking. Every plan includes a data processing agreement (DPA, GDPR art. 28): it is part of the terms you accept when you sign up or subscribe, it lists the sub-processors and the security measures, and we can send you a signed copy on request.
The append-only audit log records access and changes, denied attempts included: the record you need for GDPR and NIS2. On the higher plans, help with preparing documentation for NIS2 and GDPR audits is available as a service.
-
How do backups and restores work?
Every night there's a full backup: a database dump, a git bundle of every repository and SHA-256 checksum files to verify their integrity. Every week the latest backup is automatically restored in a separate environment and verified all the way to cloning the repositories and running
git fsck.Each test produces a report kept for 90 days; if a restore fails, administrators get an alert.
-
Is there an audit log? Can it be changed?
Yes, and no, it can't be changed. It records who did what, when, from which IP address and with what outcome: sign-ins, pushes, changes to roles, protections and policies, including denied attempts. It's append-only at the database level: rows can be added but never edited or deleted, not even by the application's own database user.
Administrators can review it for the whole instance, owners for their own organization or project. It's the record of access and changes you'll also need for GDPR and NIS2.
-
Can I leave CodeQuay without lock-in?
Yes. Your repositories stay in standard git format:
git clone --mirrortakes the whole history, branches and tags included, andgit push --mirrorputs it wherever you like. There's no proprietary format to convert.
Plans, payments and contact
-
How much does CodeQuay cost?
Prices are per user, excluding VAT, billed monthly or yearly (which costs less), and they're published on the Pricing page:
- Free: €0
- Team: €6 per user per month, or €60 per user per year (2 months free)
- Business: €18 per user per month, or €180 per user per year (2 months free)
- Sovereign: Custom quote
Protections, secret blocking at push, the audit log and tested backups are included in every plan; a dedicated instance, in the EU or on your premises, is quoted on request.
-
How do I buy a plan?
Online, with no need to talk to sales: on the Pricing page choose Free, Team or Business, create your account or sign in, and pay through Stripe Checkout. The plan is active as soon as the payment goes through. For the Sovereign plan, with a dedicated instance, request a quote through the contact form.
-
Which payment methods do you accept? Is paying online safe?
Card, PayPal, Apple Pay and Google Pay. Payments are handled by Stripe, a certified payment provider: CodeQuay never sees or stores your card details.
Business and annual customers can pay by invoice with a bank transfer to our Italian IBAN, on request.
-
Where do I find invoices? Do you issue Italian electronic invoices?
Every invoice is issued by Stripe and is available in the console under Settings → Plan and payments, where you can download it as a PDF. Italian electronic invoicing through SDI is coming soon.
-
Do prices include VAT?
No, prices are in euros and exclude VAT. VAT is added where due: enter your VAT number at checkout and it's applied as required by law, for example with the reverse charge for companies in another EU country with a valid VAT number.
-
How are users billed?
Per member of the space. When members are added or removed, the amount is prorated, so you pay only for the days each seat is in use.
-
How do I cancel a paid plan?
From Settings → Plan and payments → Manage payment and invoices in the console. The cancellation takes effect at the end of the period you've already paid for; then the space goes back to the Free plan, and your repositories stay intact.
-
Can I see CodeQuay in action before deciding?
Yes. The Free plan costs nothing and includes every security protection, so you can start right away. If you'd rather see it with us first, use the contact form: the people who build CodeQuay will reply by email and, if useful, show you protections, secret blocking and the audit log on scenarios close to yours.
-
What support is included?
It depends on the plan:
- Free: Documentation
- Team: Email
- Business: Priority
- Sovereign: Dedicated, with a named contact
To report a security issue, email security@codequay.it, whatever your plan.
-
How do I report a security issue?
Email security@codequay.it with a description of the issue and the steps to reproduce it. We'll confirm receipt and keep you posted on our analysis and the fix. Our contacts are also published in the standard
/.well-known/security.txtfile.
Didn't find your question?
Drop us a line: the people who build CodeQuay will get back to you. Or create your account and start free.