What are the four access levels in Java and what does each one mean?
answer
- public > protected > package-private > private (open to closed)
- No keyword = package-private, NOT public
- protected = package + subclasses anywhere
- private = same class only
- Pick the most restrictive that works
basics
~20 sJava has four access levels: public (everywhere), private (only inside the same class), protected (same package plus subclasses), and default — written by adding no keyword — which allows access only inside the same package.
solid answer
~40 sJava controls who can see a class member with four access levels. From most open to most closed: public means any code anywhere can use it; protected means code in the same package and any subclass (even in another package) can use it; default (also called package-private, written by simply omitting the keyword) means only code in the same package can use it; private means only the same class can use it. You apply these to fields, methods, constructors, and nested types. The default is the trap: writing no modifier does not mean public — it means package-private. Choosing the most restrictive level that still works is the core of encapsulation: it shrinks the surface other code can depend on, so you can change internals safely later.
go deeper
Name the four levels and state correctly that omitting the keyword gives package-private, not public.
Explain the scope of each level precisely, including that protected adds cross-package subclass access on top of package access, and apply least-privilege.
Tie access levels to API design and encapsulation — choosing the minimal surface to preserve change-freedom — and know the member-vs-top-level-class restriction.
Frame access control as part of a module/dependency strategy (public API surface, binary compatibility, JPMS module exports) and the cost of over-exposing internals across teams.
## What is an access modifier? In Java, an **access modifier** is a keyword that controls **which other code is allowed to use** a thing — a class, a field (a variable that belongs to an object or class), a method (a function that belongs to a class), or a constructor (the special method that builds an object). "Use" means: read or write a field, call a method, create an object, or extend a class. Restricting access is the mechanism behind **encapsulation** — hiding the internals of a class so the outside world depends only on a small, stable surface. ## The four levels There are exactly four access levels. Listed from **most permissive** to **most restrictive**: 1. **`public`** — usable by **any** code, anywhere, in any package. (A *package* is Java's namespace/folder grouping of related classes.) 2. **`protected`** — usable by code in the **same package**, AND by **subclasses** even if they live in a different package. (A *subclass* is a class that `extends` another class to inherit its members.) 3. **default**, also called **package-private** — this is what you get when you write **no keyword at all**. Usable only by code in the **same package**. 4. **`private`** — usable only **inside the same class** (the exact same `.java` top-level class, including its nested classes). ### The critical gotcha: no keyword ≠ public Beginners often assume that omitting a modifier makes something public. It does **not**. Omitting the modifier gives **package-private** (default) access. There is no keyword literally spelled `default` for this — the absence of `public`/`protected`/`private` *is* the signal. (The `default` keyword exists in Java but for an unrelated purpose: `switch` labels and default methods in interfaces.) ## Example ```java package shop; public class Account { public String id; // anyone, anywhere protected int balance; // same package + subclasses int version; // package-private (no keyword) — same package only private String pin; // this class only } ``` From a class in a **different** package, only `id` is reachable directly; from a **subclass** in another package, `id` and `balance` are reachable; from a class in the **same** package `shop`, `id`, `balance`, and `version` are reachable; `pin` is reachable only inside `Account` itself. ## Why four, and why it matters The levels let you expose a deliberate **public API** while keeping helpers and state hidden. The guiding rule ("least privilege") is: **use the most restrictive level that still lets the code work.** Most fields should be `private`; you widen access only when a real collaborator needs it. The narrower the access, the more freedom you keep to change internals later without breaking callers — which is the entire point of encapsulation. ## Where they apply Access modifiers go on **members** (fields, methods, constructors) and on **nested classes**. **Top-level classes** (a class declared directly in a file, not inside another) accept only `public` or default — never `protected` or `private`.
- If you write a field with no access keyword, who can access it?Only code in the same package (package-private / default access) — not the whole world.
- Why prefer private fields over public ones?Encapsulation: private fields keep the internal state hidden so you can change representation, add validation, or refactor without breaking external callers.
saying these in an interview costs you the question
- Thinking 'no modifier' means public — it means package-private
- Confusing the package-private default with the 'default' keyword used in switch/interface default methods
- Claiming protected is 'subclasses only' — it also grants same-package access
- Defaulting fields to public out of habit instead of private