Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

protected lets the class that declares a member and its subclasses access it; private limits typed access to the declaring class. Both are TypeScript access modifiers, not runtime security barriers. If you need runtime-enforced privacy, consider ECMAScript #private fields.

How private and protected differ

Both modifiers keep a member out of the class’s ordinary public API. The difference is whether a derived class may use it: it cannot use a base class’s private member, but it can use an accessible protected member.

class Base {
  private cacheKey = "base";

  protected format(value: string) {
    return `[${value}]`;
  }
}

class Child extends Base {
  render() {
    return this.format("hello"); // allowed
    // return this.cacheKey;      // error: private in Base
  }
}

const child = new Child();
// child.format("hello");        // error: protected

The subclass can call format from its own implementation, but code using a Child instance cannot call it as a public method. The TypeScript Classes handbook documents these visibility rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When to choose each modifier

Choose private for class-local implementation

Use private when a member should be available only to the class that declares it. This prevents subclasses from depending on or overriding that implementation through normal typed access.

Choose protected for an intentional subclass extension point

Use protected when derived classes are meant to use a member as part of their implementation. A protected member becomes part of the inheritance API: subclasses may come to depend on its behavior, so changing it can affect them even though ordinary callers cannot access it.

Neither modifier provides runtime privacy

The handbook states: “Like other aspects of the type system, private and protected are only enforced during type checking.” The modifiers do not make ordinary emitted JavaScript properties inaccessible at runtime. TypeScript also permits bracket notation to access a private member, such as instance["cacheKey"], though this does not make that member part of the supported public API.

Rank #2
TypeScript Programming Language - Software Engineer & Coder T-Shirt
  • TypeScript implements a superset of syntax for strictly typed development, facilitating deep static analysis and enhanced development environment integration. The compiler translates source into standard script formats, ensuring parity across any runtime.
  • TypeScript is ideal for front-end developers, full-stack engineers, and software architects who build large-scale web applications. It serves those looking to improve code excellence, reduce bugs through static checking, and maintain complex projects more.
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Do not use either modifier to store a secret or enforce a security boundary. They express and check intended access in TypeScript code; they do not prevent runtime property lookup. See the Classes handbook for the runtime caveat.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How ECMAScript #private fields compare

ECMAScript private fields use a hash-prefixed name, such as #secret. Unlike TypeScript’s private and protected modifiers, a #private field is enforced at runtime and cannot be accessed using ordinary bracket lookup. It is private to the class that declares it, not an inheritance-accessible alternative to protected.

TypeScript’s 3.8 release notes explain the runtime distinction and state that TypeScript’s downlevel implementation of #private requires an ES2015/ES6 target or higher. Check the project’s compiler target and supported runtimes before using it. The 4.3 release notes cover support for private methods and accessors as well as fields.

Question private protected ECMAScript #private
Declaring class can access? Yes Yes Yes
Subclass can access? No Yes, subject to hierarchy rules No; the private name belongs to its declaring class
Ordinary external typed access? Rejected Rejected Rejected
Runtime privacy? No; modifier is erased No; modifier is erased Yes
Ordinary bracket lookup? TypeScript permits bracket access as an escape hatch Emitted ordinary properties can still be reached at runtime No; obj["#secret"] is not the private name
Typical reason to choose Keep a member out of the subclass API Expose an intentional inheritance extension point Require runtime-enforced encapsulation

Inheritance details that can affect your code

  • A subclass may use a base class’s protected member from its own implementation, but protected access is hierarchy-sensitive. TypeScript rejects access through an instance of a sibling subclass.
  • A subclass cannot make a base class’s private member accessible by redeclaring a member with the same name.
  • Inside a class body, code may access a private member on another instance of that same class.
  • Private and protected members affect type compatibility. For corresponding members to satisfy compatibility, they must originate from the same declaration; similarly shaped classes from unrelated hierarchies may not be assignable. See the Type Compatibility handbook.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Other visibility rules worth knowing

Class members are public by default, so writing public is optional for ordinary members. Visibility modifiers can also be used on parameter properties. A protected constructor prevents direct construction while allowing subclassing; a private constructor also prevents extension. These are constructor visibility rules, distinct from the member-level choice between private and protected.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.