Have done it just now. It does actually but not so simple. For example you can't not just add your password-protected repo to client using URL (or built-in generated QR) as you will fail with 401 and thtat's all.
Instead you should add it using CURL's form user:password@url than it will be accepted and moreover when you go inside the new repo, youll see some button "change password" there so that we can assume that there was at least some intention to use password-protected repo. This button doesn't work for me anyway - app just crashes, but at least I can use my password-protected repo ) Frankly speaking all the F-Droid stack seemd to me like extremelly half-baked, buggy and poor-documented in general but AFAIK there is no other such solution in the world so there's no choice unfortunatelly.
Sory for necro but if I was redirected here from google in my 2024 than there will be others so let they foud what they seeking.