GitHub MCP Server

GitHub's official MCP server, from the github/github-mcp-server repository. Remote and local install commands, authentication options and the toolsets it ships with, read from the project README on 2 September 2026.

Interactive examples · No account is connected on this page

Updated

GitHub MCP Server is GitHub's own Model Context Protocol server. It connects an MCP client to repositories, issues, pull requests, Actions and security alerts. GitHub hosts a remote version at https://api.githubcopilot.com/mcp/, and the same server runs locally from the ghcr.io/github/github-mcp-server Docker image. Its tools are grouped into toolsets, and only context, repos, issues, pull_requests and users load by default.

Try a GitHub MCP task

Pick an example to see which GitHub MCP tools a task would call and what the result looks like. Examples are illustrative; nothing on this page connects to GitHub.

GitHub

Install GitHub MCP Server

GitHub MCP Server installs two ways. The remote server at https://api.githubcopilot.com/mcp/ needs nothing installed and uses OAuth in hosts that support it, or a personal access token in a header. The local server runs from the ghcr.io/github/github-mcp-server Docker image or a release binary. Pick toolsets before tools, and add --read-only when the agent should not write.

Decide between the remote and the local server

The README calls the remote server the easiest way to get running: GitHub hosts it, so there is nothing to install. It needs an MCP host with remote server support, and the README names VS Code 1.101 or later, Claude Desktop, Cursor and Windsurf. If your host cannot talk to a remote server, or you are on GitHub Enterprise Server, use the local server instead. GitHub Enterprise Server does not support remote server hosting.

https://api.githubcopilot.com/mcp/

Point VS Code at the remote server

VS Code 1.101 or later handles OAuth for you, so the config is just a type and a URL. The README also publishes a personal-access-token variant that sends an Authorization header and prompts for the token with an inputs entry, which is the pattern to copy for any host that has no OAuth support.

{
  "servers": {
    "github": {
      "type": "http",
      "url": "https://api.githubcopilot.com/mcp/"
    }
  }
}

Choose toolsets before you choose tools

With no toolsets specified the server loads the default set: context, repos, issues, pull_requests and users. Add more by name, keep the defaults by listing default first, or pass the special all toolset to enable everything. The GITHUB_TOOLSETS environment variable takes precedence over the command-line argument when both are present.

GITHUB_TOOLSETS="default,stargazers" ./github-mcp-server

GITHUB_TOOLSETS="repos,issues,pull_requests,actions,code_security" ./github-mcp-server

Lock it to read-only if the agent should not write

The --read-only flag offers only read tools, so nothing can modify repositories, issues or pull requests. Under Docker the same switch is the GITHUB_READ_ONLY environment variable. The README is explicit that read-only wins over an explicit --tools request: write tools are skipped even if you name them.

./github-mcp-server --read-only

docker run -i --rm -e GITHUB_READ_ONLY=1 ghcr.io/github/github-mcp-server

Official documentation: Read the README on GitHub.

Remote server, Docker, or a local binary

The remote server, the Docker image and the local binary expose the same tools but differ in what you install, how you authenticate and where they work. Only the local options support GitHub Enterprise Server, through GITHUB_HOST or --gh-host. Docker also needs its OAuth callback port published to loopback, which the remote server and the native binary do not.

What differsRemote serverLocal DockerLocal binary
What the client points athttps://api.githubcopilot.com/mcp/docker run -i --rm ghcr.io/github/github-mcp-server./github-mcp-server
What you have to installNothing; GitHub hosts itDocker, runningA release binary, or a build from source
AuthenticationOAuth in hosts that support it, or a PAT in an Authorization: Bearer headerBrowser OAuth on first use, or GITHUB_PERSONAL_ACCESS_TOKEN, which takes precedenceSame two options; the native binary flow needs no fixed callback port
OAuth callback portHandled by the hostMust be published to loopback, e.g. -p 127.0.0.1:8085:8085Not needed
GitHub Enterprise ServerNot supported; GHES has no remote server hostingSupported via GITHUB_HOST or --gh-host, HTTPS enforcedSupported via GITHUB_HOST or --gh-host, HTTPS enforced
Early-access buildURL path /mcp/insiders, or the X-MCP-Insiders: true header-e GITHUB_INSIDERS=true--insiders, or GITHUB_INSIDERS=true

Commands and flags transcribed from the github/github-mcp-server README and its Claude and Cursor installation guides, read 2026-09-02. Flags change between releases, so check the README before relying on any of them.

What the toolsets cover

GitHub MCP Server groups its tools into toolsets rather than one flat list. Five load by default: context, repos, issues, pull_requests and users. Others, including actions, code_security, dependabot and secret_protection, are switched on by name. The groups below show which tools each covers, from file reads and pull request merges to CI job logs and security alerts.

Toolsets, not one flat tool list

Tools arrive in named groups you switch on and off: context, repos, issues, pull_requests, users, actions, code_quality, code_security, copilot, dependabot, discussions, gists, git, labels, notifications, orgs, projects, secret_protection, security_advisories and stargazers. The remote server adds copilot_spaces and github_support_docs_search on top.

Repository reads and writes

The repos toolset carries get_file_contents, list_commits, list_branches, create_branch, create_or_update_file, push_files, delete_file, fork_repository, search_code and search_repositories, plus release and tag lookups.

Issues and pull requests

issue_read, issue_write, list_issues, add_issue_comment and search_issues cover issues. Pull requests get pull_request_read, create_pull_request, update_pull_request, merge_pull_request, pull_request_review_write and update_pull_request_branch.

CI and build failures

The actions toolset exposes actions_get, actions_list, actions_run_trigger and get_job_logs, which is how an agent inspects a failing workflow run rather than guessing from the diff.

Security findings

Separate toolsets keep security reads apart from everything else: list_code_scanning_alerts, list_dependabot_alerts, list_secret_scanning_alerts and the global and repository security-advisory listings.

Context first

The README marks the context toolset strongly recommended. It holds get_me, get_teams and get_team_members, so the model knows who it is acting as before it starts calling anything that writes.

What is the GitHub MCP Server?

GitHub MCP Server is GitHub’s official Model Context Protocol server. It lets an MCP client such as VS Code, Claude Code or Cursor read and act on repositories, issues, pull requests, Actions runs and security alerts with the permissions of the account that authorised it.

You can use the hosted remote server at https://api.githubcopilot.com/mcp/ or run the same server locally from the ghcr.io/github/github-mcp-server image. Tools are grouped into toolsets; only context, repos, issues, pull_requests and users load by default, and --read-only removes every write tool.

How to connect GitHub MCP

  1. Choose remote or local

    The remote server needs nothing installed; GitHub Enterprise Server and hosts without remote support use the Docker image or binary.

  2. Authenticate

    OAuth where the host supports it, or a personal access token in a header or the GITHUB_PERSONAL_ACCESS_TOKEN variable.

  3. Pick toolsets, then test a read

    Enable only the toolsets the task needs and start with a read such as get_me before allowing writes.

See the full GitHub MCP setup

GitHub MCP use cases

Triage a failing build

Enable the actions toolset, let the agent find the failed run and read the job logs, then decide whether the fix belongs in code or in the workflow file.

Prepare a pull request end to end

With repos and pull_requests enabled the agent can create a branch, push files and open a pull request — keep --read-only on until you trust that loop.

Review security findings across a repository

The code_security, dependabot and secret_protection toolsets list alerts without exposing write tools, which suits a read-only security review.

Ground the agent in who it is acting as

Keep the context toolset on: get_me and get_teams tell the model which account and teams it is using before it calls anything that writes.

GitHub MCP Server questions

These answers cover the questions that decide a GitHub MCP setup: whether you need a personal access token, which toolsets are enabled by default, how to stop an agent writing to repositories, how GitHub Enterprise Cloud and Enterprise Server differ, how the server compares with the gh CLI, and how to confirm you are running GitHub's official server.

Do I need a personal access token for GitHub MCP Server?

Not always. On the remote server, hosts with OAuth support log you in without a token; the README's VS Code OAuth config is just a type and a url. The local server on github.com ships with the app credentials in the official image and opens a browser login on first use, keeping the token in memory only. A PAT is the fallback, and where it is set as GITHUB_PERSONAL_ACCESS_TOKEN the README says it takes precedence over OAuth. Cursor is the exception worth knowing about: GitHub's Cursor guide says the GitHub server currently requires a PAT there.

Which tools are enabled by default?

Five toolsets: context, repos, issues, pull_requests and users. Everything else — Actions, Dependabot, code scanning, discussions, gists, projects, notifications, stargazers and the rest — is off until you name it. Keep the defaults and add one with GITHUB_TOOLSETS="default,stargazers", or enable everything with the special all toolset. If both the environment variable and the command-line argument are set, the environment variable wins.

How do I stop an agent from writing to my repositories?

Run the server with --read-only, or set GITHUB_READ_ONLY=1 under Docker. It offers only read tools, so no issue, pull request or repository can be modified. The README notes that read-only takes priority over explicit tool selection: write tools are skipped even when you request them by name with --tools.

Does GitHub MCP Server work with GitHub Enterprise?

It depends which product. GitHub Enterprise Cloud with data residency can use a remote server on its own subdomain, in the shape https://copilot-api.YOURSUBDOMAIN.ghe.com/mcp. GitHub Enterprise Server has no remote server hosting at all, so it needs the local server with --gh-host or the GITHUB_HOST environment variable. HTTPS is enforced on that host: the README says non-HTTPS hosts are refused so credentials are never sent in cleartext, with a loopback address the only exception.

What is the difference between GitHub MCP Server and the gh CLI?

The gh CLI is a command you run. GitHub MCP Server is a protocol server that publishes those capabilities as MCP tools, so a model can choose and call them itself, with the toolset and read-only switches as the boundary on what it may reach. They cover overlapping GitHub APIs; the difference is who decides which call happens next.

Is this the official GitHub MCP server?

It is published in the github/github-mcp-server repository, the remote endpoint is on GitHub's own api.githubcopilot.com domain, and the container image is served from ghcr.io/github/github-mcp-server. This page is a third-party write-up of that project, read on 2 September 2026; treat the README as the source of truth for current flags and toolsets.

One server is rarely the whole agent

A GitHub server gets an agent into your repositories. Deciding what it does with issues, releases and reviews across the rest of your stack is a separate design problem: which events trigger a run, which changes it may push on its own, and which ones still need a maintainer to approve before they land.