GitHub MCP Server
Official GitHub MCP server for repositories, issues, pull requests, Actions and more – local or as GitHub's hosted remote server.
- Skill Road
- GitHub MCP Server
Categories
Description
The GitHub MCP Server is GitHub's official MCP server, maintained in the github/github-mcp-server repository. It exposes repositories, issues, pull requests, GitHub Actions and other GitHub features as MCP tools. License MIT.
Per the documentation, it runs in two modes: as GitHub's own hosted remote server at https://api.githubcopilot.com/mcp/ (with OAuth or personal-access-token login), or locally via a Docker image.
Its tools are organised into toolsets, including: Repositories (code, files, commits, branches), Issues, Pull Requests (reviews, merges, diffs, checks), Actions (workflows, runs, artifacts, job logs), Code Security (scanning alerts, Dependabot, secret protection), Discussions, Projects, Notifications, Organizations, plus Gists and user information. Per the documentation, the default toolsets are context, repos, issues, pull_requests and users.
Authentication is via OAuth (browser-based login, token kept in memory only) or a personal access token through the GITHUB_PERSONAL_ACCESS_TOKEN environment variable. A GitHub App login is also available for non-interactive deployments. GitHub Enterprise Server and ghe.com are supported via the GITHUB_HOST variable.
Local start via Docker:
docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server
Registered in an MCP client:
{
"mcpServers": {
"github": {
"command": "docker",
"args": ["run", "-i", "--rm", "-e", "GITHUB_PERSONAL_ACCESS_TOKEN", "ghcr.io/github/github-mcp-server"]
}
}
}
Alternatively it can be built from source: go build -o github-mcp-server ./cmd/github-mcp-server, run via ./github-mcp-server stdio.
Hosted vs. local operation
The hosted remote server is the simpler entry point for most cases: just add the URL to the client and complete the OAuth login in a browser, without running Docker or your own runtime environment. GitHub handles operating and updating the server. Local operation via Docker or a self-built binary pays off when stricter control over network access, logging, or toolset selection is needed, or when GitHub Enterprise Server or ghe.com are in use, for which, per the documentation, only local mode is available.
Scoping toolsets deliberately
Because the GitHub MCP Server potentially carries broad permissions over repositories, Actions, and organization data, the documentation recommends enabling only the toolsets actually needed instead of unlocking every available feature group. Read-only mode disables all write tools and suits research or reporting tasks where no changes to code or issues are required. An additional lockdown mode further restricts processing of untrusted content, reducing the risk that instructions hidden in issues or pull request comments get executed unintentionally.
Who the GitHub MCP Server fits
Teams that want to connect an AI agent directly to their development workflow benefit the most: automated triage of new issues, drafting pull requests from a task description, summarizing Actions failures, or searching security alerts from code scanning and Dependabot. For individual developers who only occasionally search a repository or check an issue status, a minimally scoped token combined with read-only mode is often enough.
Frequently asked questions
Do I need Docker to use the server? No, the hosted remote server needs neither Docker nor a local installation. Does the server work with GitHub Enterprise Server? Yes, via the GITHUB_HOST environment variable, though per the documentation only in local operation. Can the agent accidentally delete code? Only if correspondingly broad write permissions were granted; read-only mode, lockdown mode, and minimally scoped tokens prevent that.
Requirements
The hosted remote server requires a GitHub account, a client that supports remote MCP, and any approvals required by the organization. Local operation requires Docker or a self-built Go binary. GitHub Enterprise Server supports local operation only.
Installation instructions
For GitHub's hosted server, configure https://api.githubcopilot.com/mcp/ as the HTTP MCP URL in the client and complete the OAuth flow. If the client does not support OAuth, a personal access token can be sent as a Bearer header.
For local operation, run the public ghcr.io/github/github-mcp-server image with Docker. Browser-based OAuth is available on first run; alternatively, supply GITHUB_PERSONAL_ACCESS_TOKEN through the environment. Without Docker, build the Go binary from the repository and start it with the stdio subcommand.
docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server
Authentication
Supports OAuth, fine-grained or classic personal access tokens, and GitHub App authentication for non-interactive local deployments. During local OAuth, the token is kept in memory only according to the documentation. A configured GITHUB_PERSONAL_ACCESS_TOKEN takes precedence over OAuth.
Required access permissions
Effective permissions match those of the authenticated GitHub user or the token scopes. Depending on enabled toolsets, read and write access may include repositories, issues, pull requests, Actions, organizations, and security features. Grant minimal token scopes; use --read-only, selected toolsets, and lockdown mode to limit capabilities.
Transmitted or stored data
Requests and tool parameters are sent to the GitHub API or hosted remote server. Responses may include source code, commits, issues, pull requests, Actions logs, organization data, and security alerts, and are passed to the MCP client and its language model. Write tools persist changes on GitHub. Local OAuth keeps the access token in memory; a PAT resides in the client or process environment.
Security risks
An overprivileged or exposed token enables broad GitHub actions. Write tools can modify files, branches, issues, and pull requests; some capabilities can even delete repositories or files. Repository content may contain prompt injection. Use separate least-privilege tokens, never commit secrets, begin with read-only and lockdown modes, and require human review for changes.
License and costs
- License
- MIT
- Cost
- free
The server and source code are free under the MIT license. A GitHub account is required; available features, quotas, and potential costs depend on the GitHub plan and API limits in use.
Alternatives
At a glance
- Provider
- GitHub
- Status
- Official server
- Deployment
- Local and remote
- Current version
- 1.12.0
- Last reviewed
- 07.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026
Installing a Claude Code plugin
Installing a plugin from the official Anthropic marketplace – using the Code Review plugin as an example.
24.09.2026