Setting up GitHub MCP securely
Configure the remote or local GitHub MCP Server with OAuth, least privilege, and read-only mode.
- Skill Road
- Setting up GitHub MCP securely
Published on 03.09.2026
The official GitHub MCP Server can read source code and, depending on enabled tools, modify repositories, issues, and pull requests. Begin with the smallest required permission set.
Setting up GitHub MCP as a remote server
Configure this URL in a client that supports remote MCP:
https://api.githubcopilot.com/mcp/
If the client supports GitHub's OAuth flow, no manually created token is required. Otherwise, use a fine-grained personal access token as a Bearer token. Limit its repository selection and permissions precisely to the task.
Setting up GitHub MCP locally
docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server
Pass the token through the client's protected environment management and never as plain text in a committed configuration file. Browser-based OAuth is also available locally.
Limiting GitHub MCP capabilities
Start in read-only mode whenever possible and enable only required toolsets. Lockdown mode further limits access to repositories where the authenticated user is a contributor. Enable write access only after a test run and with human confirmation.
Verifying the setup
First test get_me and a read-only operation on a selected repository. Then review token or OAuth permissions in GitHub and revoke access that is no longer needed.
Choosing toolsets deliberately
The GitHub MCP Server organizes its functionality into toolsets such as repositories, issues, pull requests, Actions, and code security. Instead of enabling every group, only turn on the ones actually needed for the task at hand — anyone who just wants to search issues doesn't need access to Actions workflows or code security alerts. A smaller toolset selection reduces not only the security risk but also the number of tool definitions in the language model's context.
Differences between OAuth and a personal access token
OAuth is usually the more convenient choice for interactive use, since no token has to be manually generated and managed; per the documentation, the token stays in memory only. For non-interactive automation, such as a CI/CD pipeline, a fine-grained personal access token or a GitHub App login is more practical, since no browser window can be opened there. In both cases, the rule holds: the narrower the permissions, the less damage a compromised client can do.
What to do if you suspect misuse
If the audit log shows unusual activity, such as commits or pull-request comments at unusual times, revoke the affected token or OAuth authorization immediately and replace it with a new, more narrowly scoped one. It's also worth reviewing the agent's most recent actions to identify and undo any unauthorized changes.
Treat this review as a routine step whenever an agent is given write access for the first time, not only after something looks suspicious.
Source: official github/github-mcp-server repository, checked on 2026-09-03.
Frequently asked questions
Remote server or local server?
The remote server at `https://api.githubcopilot.com/mcp/` needs no self-created token with OAuth-capable clients. The local server (`ghcr.io/github/github-mcp-server` via Docker) keeps everything on your own machine but requires a token or a browser-based OAuth login.
OAuth or a personal access token?
If the client supports GitHub's OAuth flow, that is the simpler and easily revocable choice. Otherwise use a fine-grained personal access token as a bearer token, with its repository selection and permissions scoped exactly to the task.
How do I limit what the server can do?
Start in read-only mode where possible and enable only the toolsets you need. Lockdown mode additionally restricts access to repositories the signed-in user contributes to. Enable write permissions only after a test run and with human confirmation.
Where does the access token belong?
In the client's protected environment management, never as plain text in a checked-in configuration file. Revoke tokens and OAuth grants you no longer need in your GitHub settings.
How do I test the setup safely?
With `get_me` and a read-only access to a selected repository. Then review the token or OAuth permissions actually granted in GitHub. Source: github.com/github/github-mcp-server