GitLab MCP Server
Official GitLab MCP server in beta: projects, issues, merge requests, pipelines, and code reviews directly in your AI coding client.
- Skill Road
- GitLab MCP Server
Description
The GitLab MCP Server is GitLab's official Model Context Protocol server, giving AI coding agents secure and structured access to a GitLab instance. According to the provider, the server is in beta status and is available for all GitLab tiers (Free, Premium, Ultimate) on GitLab.com, self-managed, and GitLab Dedicated. It is built directly into the GitLab application and accessible at the endpoint https://<gitlab-instance>/api/v4/mcp. No separate public repository exists; the implementation is part of the GitLab monorepo.
What is the GitLab MCP Server
The GitLab MCP Server enables AI clients such as Claude Desktop, Claude Code, Cursor, GitHub Copilot in VS Code, Gemini Code Assist, Gemini CLI, and Kiro IDE to connect to a GitLab instance via OAuth 2.0 Dynamic Client Registration. After authorization, the assistant can read GitLab data, create or update issues and merge requests, add commits, retrieve pipeline results, write code reviews, and manage Duo Agent Platform sessions. According to the provider, two transport types are supported: HTTP transport (recommended, no additional dependencies) and stdio transport via mcp-remote (requires Node.js 20 or higher as a bridge).
Available tools
The server provides an extensive set of tools according to the official tool documentation (as of 2026-09-08), organized into several categories:
Project queries: get_project returns metadata such as project ID, default branch, visibility, and web URL. get_mcp_server_version reports the current server version.
File and code operations: add_commit adds commits with one or more file actions (create, update, delete, move, chmod) to a branch in a single call, supporting both full file content and targeted text replacements (old_str/new_str). This feature warrants special security consideration, as it requires write access to the code.
Issues: create_issue creates new issues with title, description, assignments, milestones, labels, confidentiality settings, and epics. get_issue retrieves details for a single issue. list_issues and search allow filtering and searching issues by author, assignee, labels, state, and time range.
Merge requests: save_merge_request creates or updates merge requests including branch, description, labels, assignees, reviewers, squash settings, and state transitions. get_merge_request returns the full merge request record and can optionally include diffs, commits, notes, pipelines, or discussions. get_merge_request_diffs, get_merge_request_commits, get_merge_request_notes, and get_merge_request_pipelines are also available as separate queries. list_merge_requests filters by author, assignee, reviewer, state, milestone, and labels.
Reviews and comments: save_note adds comments to merge requests or work items and can reply to existing discussion threads. save_merge_request_review writes review artifacts: new comments, replies, diff comments, discussion resolution, a combined submit_review with multiple diff comments and a summary, and explicit approval or disapproval of a merge request. get_merge_request_notes paginates all notes including discussion IDs.
Search: The search tool supports multiple scopes according to the documentation (projects, issues, merge_requests, milestones, users, blobs, commits, notes, wiki_blobs, snippet_titles) and returns optimized short metadata for each type.
Members and teams: list_project_members lists members with their role and access level.
GitLab Duo Agent Platform: list_duo_sessions and get_duo_session allow managing existing Duo agent sessions and retrieving their status.
Setup for different clients
For HTTP transport (recommended), the MCP client configuration file includes the endpoint https://gitlab.com/api/v4/mcp (or the organization's own GitLab instance URL) as a remote server of type http. For Claude Code, the setup command is:
claude mcp add --transport http GitLab https://gitlab.com/api/v4/mcp
For Cursor, a new MCP server with the URL is added under Settings > Cursor Settings > Tools & MCP. For GitHub Copilot in VS Code, the setup uses MCP: Add Server in the Command Palette with type HTTP and the same URL. For Claude Desktop and clients without native HTTP transport, the stdio path via mcp-remote is used: { "command": "npx", "args": ["-y", "mcp-remote", "https://gitlab.com/api/v4/mcp"] }. Node.js 20 or higher is required for this. According to the documentation, an OAuth 2.0 sign-in dialog opens automatically in the browser on first connection.
Optionally, the header X-Gitlab-Mcp-Server-Tool-Name-Prefix can be set to add a prefix to tool names (maximum 32 characters), to avoid naming conflicts when using multiple MCP servers or GitLab instances simultaneously.
Security and data access
The GitLab MCP Server uses OAuth 2.0 Dynamic Client Registration as its authentication mechanism. According to the provider, on first connection the AI client registers itself automatically as an OAuth application, requests authorization, and receives an access token for API access. This token has access to all data for which the authenticated GitLab user has read permission.
The most important security consideration is write access: through add_commit, the agent can write code directly to a branch; through save_merge_request, it can open and modify merge requests; and through save_merge_request_review, it can submit reviews and approve merge requests. These tools always act with the full permissions of the authenticated user — including push rights to all accessible repositories. According to the provider, users should actively consider prompt injection: requests in issue descriptions, merge request titles, or code content can influence the agent's instructions. The documentation explicitly recommends using MCP tools only on GitLab objects you trust.
To minimize risk, a dedicated GitLab account or a service account with minimal project access rights is recommended. GitLab.com instances can restrict MCP server access at the group and instance level. On self-managed instances, administrators control access via instance configuration.
The data path runs from the GitLab MCP Server through the connected AI client (e.g. Claude, Cursor) to the language model of the respective provider. GitLab data returned as tool results may be embedded in the client's model context requests. Which data is forwarded to the model is decided by the client, not the GitLab MCP Server.
Availability and license
The GitLab MCP Server is available for all GitLab tiers according to the provider: Free, Premium, and Ultimate — on GitLab.com as well as on self-managed and GitLab Dedicated instances. The status is beta; the provider notes that the feature set may still change. Since the server is integrated into the GitLab application and no separate repository has been published, there is no independent GitHub star counter or external open-source license for this specific service. GitLab itself is licensed under the MIT Expat license (Community Edition). Before production use, teams should review token lifetimes, OAuth application registrations, audit logs in GitLab, and the classification of their repositories.
FAQ
Does the GitLab MCP Server work with a self-hosted GitLab instance? Yes. According to the provider, the server supports GitLab.com, self-managed, and GitLab Dedicated. In the client configuration, only the own instance URL needs to be entered instead of gitlab.com.
Is a paid GitLab plan required? No. According to the provider, the MCP server is available for all tier levels (Free, Premium, Ultimate). Certain GitLab features accessed by the tools may require higher plans, but the server itself does not.
How does the GitLab MCP Server differ from the GitHub MCP Server? Both are official MCP servers for their respective platforms. The GitHub MCP Server is focused on GitHub.com and supports GitHub-specific concepts (pull requests, GitHub Actions). The GitLab MCP Server targets GitLab users and supports GitLab-specific concepts (merge requests, GitLab Pipelines, Duo Agent Platform, GitLab Dedicated). Teams with self-managed GitLab instances typically have more control over network boundaries and access restrictions with the GitLab MCP Server.
Is there a public repository for the server? No. The GitLab MCP Server is integrated into the main GitLab application (endpoint /api/v4/mcp) and is not published as a separate package. Source code and issues can be viewed through the official GitLab project at gitlab.com/gitlab-org/gitlab.
Requirements
GitLab account (Free, Premium, or Ultimate); MCP client with HTTP transport support (recommended) or Node.js ≥20 for stdio via mcp-remote. MCP access must be allowed at group or instance level.
Installation instructions
HTTP transport (recommended): Set type "http" and URL https://gitlab.com/api/v4/mcp (or own instance) in the client configuration. Claude Code: claude mcp add --transport http GitLab https://gitlab.com/api/v4/mcp. An OAuth browser dialog opens on first connection.
claude mcp add --transport http GitLab https://gitlab.com/api/v4/mcp
Authentication
OAuth 2.0 Dynamic Client Registration. On first connection, the client registers itself automatically and opens a browser login dialog for authorization.
Required access permissions
Read and write access to all GitLab resources for which the authenticated user has permissions. Write tools (commits, merge requests, reviews, approvals) act with the user's full rights.
Transmitted or stored data
GitLab data is returned as tool results and embedded by the connected AI client in model context requests. The GitLab server itself does not forward data directly to language models.
Security risks
Write access to code (add_commit), merge requests, and approvals with full user rights. Prompt injection possible via issue/MR content. According to the provider, only use with trusted GitLab objects. A dedicated service account with minimal permissions is recommended.
License and costs
- License
- Not recorded yet.
- Cost
- free
According to the provider, free to use for all GitLab tiers (Free, Premium, Ultimate). Costs arise only from the chosen GitLab plan and the AI client in use. Current pricing at gitlab.com/pricing.
Alternatives
Not recorded yet.
At a glance
- Provider
- GitLab
- Status
- Official server
- Deployment
- Remote
- Current version
- Not recorded yet.
- Last reviewed
- 08.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026
Installing a Claude Code plugin
Installing a plugin from the official Anthropic marketplace – using the Code Review plugin as an example.
24.09.2026