What you are trying to accomplish
Most people looking for a way to share a private GitHub repository want one person to inspect a specific piece of work without making the repository public or setting up a lasting collaboration. The practical question is what the recipient needs to do: browse selected files, make authenticated GitHub requests, or contribute changes.
A collaborator invitation is for repository access. A personal access token is for authenticating a person or integration to GitHub. A RepoView link is for browser-based review of the repository and ref you authorize. These approaches are not interchangeable.
Three ways to share private GitHub code
| Method | Use it when | What the recipient gets |
|---|---|---|
| GitHub collaborator | They need ongoing repository access or must work in GitHub. | Access through GitHub, subject to the repository and organization permissions you grant. |
| Fine-grained PAT | An authorized user or integration needs GitHub API or HTTPS Git access. | A credential for its creator—not a share link and not a way to grant another person new access. |
| RepoView review link | Someone needs to browse approved code without joining the repository. | A browser view of the authorized repository, ref, and visible paths; no RepoView or GitHub viewer account is required. |
GitHub collaborators: for ongoing repository work
Invite a person through GitHub when they need repository-level access—for example, to clone or fetch the code, use GitHub's collaboration tools, or contribute through the workflow your repository allows. The invitation and permission level are managed in GitHub, and the person accepts the invitation there. Organization rules may also control who can be invited and what access they receive. See GitHub's guide to inviting collaborators to a personal repository.
This can be inappropriate for a recruiter, prospective client, or one-time reviewer who only needs to inspect a project. It creates a GitHub access relationship and an invitation to manage, even when the actual task is just to read a selected snapshot of work. If the repository belongs to an employer or client, the owner may also be subject to access policies or confidentiality terms that do not permit adding an outside reviewer.
Fine-grained personal access tokens: for API or Git operations
A fine-grained personal access token (PAT) authenticates its creator to GitHub. GitHub lets the creator limit a token to a resource owner, selected repositories, specific permissions, and an expiry where available. A token cannot grant access beyond what its creator can already access. GitHub describes PATs as credentials and recommends treating them like passwords; see its guides to managing personal access tokens and fine-grained token permissions.
A PAT can be relevant when an authorized account needs a script or integration to call GitHub, but it is not a good way to send repository access to a recruiter. Do not put your own token in an email, document, or share link. If another person needs direct GitHub access, grant that person access through GitHub and let them use their own approved credentials.
A scoped review link: for browser-based read-only review
RepoView is designed for the narrower case where a reviewer needs to browse code, not join the GitHub repository. The owner connects a GitHub App installation with read-only Contents access, chooses a registered repository and ref, and creates a share. The repository remains private on GitHub; RepoView serves the content allowed by the repository and share visibility rules. The recipient opens the link in a browser without a RepoView or GitHub account.
This is a fit for a read-only review, not for cloning, pushing changes, or opening a pull request as a contributor. If the recipient needs those GitHub workflows, invite them through GitHub under the permissions and policies that apply to the repository.