---
title: "How to import a private repository"
description: "An organization owner adds a read-only token for the Git host under Integrations → Code hosts. Then anyone who builds screens can import from it."
updated: 2026-10-06
canonical: https://kendor.io/docs/repo-import/private-repositories
---

# How to import a private repository
To import a private repository, an organization owner saves a read-only access token for its Git host under **Integrations**, in the **Code hosts** section. Kendor then uses that token whenever someone in the organization checks or imports a repository from that host. There is one token per host, shared by the whole organization.

> **Before you start**
>
> - Only **Owners** can add, replace or remove tokens. Editors and Viewers can open the page and see which hosts are connected, but not change them.
> - Editors and Owners can import private repositories once a token is saved. They never see the token itself.

## Add a token for GitHub, GitLab or Bitbucket

1. Open **Integrations** in the sidebar.
2. In **Code hosts**, choose **Connect** on the **GitHub**, **GitLab** or **Bitbucket** card.
3. Create a token on the host (see the table below) and paste it into **Read-only token**.
4. Choose **Save**.

Kendor checks GitHub and GitLab tokens with the host when you save, and refuses one the host rejects. Bitbucket has no check that works for every token type, so a Bitbucket token is first tested by your next import.

Once saved, the page shows **Connected**, the token's last four characters, the date it was added and who added it.

## Which token to create

Kendor only reads repositories, so use a token that can't push. The hint under the token field on each host's page says the same:

| Host | Token | Permission |
|---|---|---|
| GitHub | Fine-grained personal access token, with **Repository access** set to the repositories you import (not "Public repositories", the default) | **Contents: Read-only** |
| GitHub (alternative) | Classic token | `repo` scope. It works, but it can also write to every repository you can. |
| GitLab | Personal, group or project access token | `read_repository` |
| Bitbucket | Repository, project or workspace access token | **Repositories: Read** |

For a Bitbucket Atlassian API token, also fill in **Account email (Atlassian API tokens only)** with the email of the Atlassian account the token belongs to. Leave it empty for repository, project and workspace access tokens.

> **Tip.** A GitHub token also helps with public github.com repositories: imports go through your token's own rate limit instead of the shared one.

## Add a self-hosted server

GitHub Enterprise Server, GitLab self-managed, Gitea and Forgejo servers are added on the **Self-hosted servers** card. Kendor only imports from a server your organization has added, and each server has its own token.

1. In **Code hosts**, choose **Connect** on **Self-hosted servers**.
2. Pick the **Server type**: **GitLab (self-managed)**, **GitHub Enterprise Server** or **Gitea or Forgejo**.
3. Enter the **Server name**, such as `git.example.com`. Enter just the name: no port, path or IP address.
4. Paste a **Read-only token** with the same permissions as for the cloud version of that host.
5. Choose **Add server**.

Kendor checks the token with the server before saving. If the server answers but isn't the type you picked, you'll see a message that it doesn't look like that kind of server.

> **Note.** The server must be reachable from the internet over HTTPS on the standard port. Kendor refuses addresses on private networks, so a server only available inside your company network or over a VPN can't be used. Bitbucket Data Center isn't supported.

## How tokens are stored

- Tokens are encrypted before they are stored, and are only used to download the repository you import.
- Kendor never shows a token again after you save it. The page shows only the last four characters, the date it was added and who added it.
- A token is only ever sent to the host it was saved for.

## Replace or remove a token

On the host's page, choose **Replace** to paste a new token, or **Remove** to delete it. Removing asks you to confirm first.

After a token is removed:

- Challenges you already imported keep their code. Nothing in your screens or live coding interviews changes.
- New imports of private repositories from that host stop working until someone adds a token again. Public repositories on github.com, gitlab.com and bitbucket.org still import.
- For a self-hosted server, removing its token removes the server too. Links to it are then treated as an unknown host.

## Errors that mean a token is missing or wrong

When a token would fix a failed check, the error has a **Connect it in Integrations settings** link that opens in a new tab. The common messages:

- **Repository or ref not found … If it's private, connect a GitHub token.** Git hosts answer "not found" for private repositories when no token is sent. Check the spelling of the link and the branch, then add a token.
- **Repository or ref not found … or the organization's token can't read it.** A token is saved, but it doesn't cover this repository. For a fine-grained GitHub token, add the repository to its repository access list.
- **… rejected the organization's token.** The token has expired or been revoked. Replace it.
- **… isn't connected. Add it under Settings → Integrations to import from it.** The link points at a server your organization hasn't added. Add it as a self-hosted server.

After fixing the token, go back and choose **Check** again.
