GitHub MCP Server

Official GitHub MCP server for repositories, issues, pull requests, Actions and more – local or as GitHub's hosted remote server.

Description

The GitHub MCP Server is GitHub's official MCP server, maintained in the github/github-mcp-server repository. It exposes repositories, issues, pull requests, GitHub Actions and other GitHub features as MCP tools. License MIT.

Per the documentation, it runs in two modes: as GitHub's own hosted remote server at https://api.githubcopilot.com/mcp/ (with OAuth or personal-access-token login), or locally via a Docker image.

Its tools are organised into toolsets, including: Repositories (code, files, commits, branches), Issues, Pull Requests (reviews, merges, diffs, checks), Actions (workflows, runs, artifacts, job logs), Code Security (scanning alerts, Dependabot, secret protection), Discussions, Projects, Notifications, Organizations, plus Gists and user information. Per the documentation, the default toolsets are context, repos, issues, pull_requests and users.

Authentication is via OAuth (browser-based login, token kept in memory only) or a personal access token through the GITHUB_PERSONAL_ACCESS_TOKEN environment variable. A GitHub App login is also available for non-interactive deployments. GitHub Enterprise Server and ghe.com are supported via the GITHUB_HOST variable.

Local start via Docker:

docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server

Registered in an MCP client:

{
  "mcpServers": {
    "github": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "-e", "GITHUB_PERSONAL_ACCESS_TOKEN", "ghcr.io/github/github-mcp-server"]
    }
  }
}

Alternatively it can be built from source: go build -o github-mcp-server ./cmd/github-mcp-server, run via ./github-mcp-server stdio.

Hosted vs. local operation

The hosted remote server is the simpler entry point for most cases: just add the URL to the client and complete the OAuth login in a browser, without running Docker or your own runtime environment. GitHub handles operating and updating the server. Local operation via Docker or a self-built binary pays off when stricter control over network access, logging, or toolset selection is needed, or when GitHub Enterprise Server or ghe.com are in use, for which, per the documentation, only local mode is available.

Scoping toolsets deliberately

Because the GitHub MCP Server potentially carries broad permissions over repositories, Actions, and organization data, the documentation recommends enabling only the toolsets actually needed instead of unlocking every available feature group. Read-only mode disables all write tools and suits research or reporting tasks where no changes to code or issues are required. An additional lockdown mode further restricts processing of untrusted content, reducing the risk that instructions hidden in issues or pull request comments get executed unintentionally.

Who the GitHub MCP Server fits

Teams that want to connect an AI agent directly to their development workflow benefit the most: automated triage of new issues, drafting pull requests from a task description, summarizing Actions failures, or searching security alerts from code scanning and Dependabot. For individual developers who only occasionally search a repository or check an issue status, a minimally scoped token combined with read-only mode is often enough.

Frequently asked questions

Do I need Docker to use the server? No, the hosted remote server needs neither Docker nor a local installation. Does the server work with GitHub Enterprise Server? Yes, via the GITHUB_HOST environment variable, though per the documentation only in local operation. Can the agent accidentally delete code? Only if correspondingly broad write permissions were granted; read-only mode, lockdown mode, and minimally scoped tokens prevent that.

Requirements

The hosted remote server requires a GitHub account, a client that supports remote MCP, and any approvals required by the organization. Local operation requires Docker or a self-built Go binary. GitHub Enterprise Server supports local operation only.

Installation instructions

For GitHub's hosted server, configure https://api.githubcopilot.com/mcp/ as the HTTP MCP URL in the client and complete the OAuth flow. If the client does not support OAuth, a personal access token can be sent as a Bearer header.

For local operation, run the public ghcr.io/github/github-mcp-server image with Docker. Browser-based OAuth is available on first run; alternatively, supply GITHUB_PERSONAL_ACCESS_TOKEN through the environment. Without Docker, build the Go binary from the repository and start it with the stdio subcommand.

docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server

Authentication

Supports OAuth, fine-grained or classic personal access tokens, and GitHub App authentication for non-interactive local deployments. During local OAuth, the token is kept in memory only according to the documentation. A configured GITHUB_PERSONAL_ACCESS_TOKEN takes precedence over OAuth.

Required access permissions

Effective permissions match those of the authenticated GitHub user or the token scopes. Depending on enabled toolsets, read and write access may include repositories, issues, pull requests, Actions, organizations, and security features. Grant minimal token scopes; use --read-only, selected toolsets, and lockdown mode to limit capabilities.

Transmitted or stored data

Requests and tool parameters are sent to the GitHub API or hosted remote server. Responses may include source code, commits, issues, pull requests, Actions logs, organization data, and security alerts, and are passed to the MCP client and its language model. Write tools persist changes on GitHub. Local OAuth keeps the access token in memory; a PAT resides in the client or process environment.

Security risks

An overprivileged or exposed token enables broad GitHub actions. Write tools can modify files, branches, issues, and pull requests; some capabilities can even delete repositories or files. Repository content may contain prompt injection. Use separate least-privilege tokens, never commit secrets, begin with read-only and lockdown modes, and require human review for changes.

License and costs

License
MIT
Cost
free

The server and source code are free under the MIT license. A GitHub account is required; available features, quotas, and potential costs depend on the GitHub plan and API limits in use.

Alternatives

At a glance

Provider
GitHub
Status
Official server
Deployment
Local and remote
Current version
1.12.0
Last reviewed
07.09.2026

Repository and documentation

Categories

Supported clients