Overview
What GitHub MCP Server does
GitHub's server turns common repository and collaboration operations into MCP tools. Teams can keep the default repository, issue, pull-request, user, and context toolsets, or expose a narrower selection for a specific workflow. It can run locally from GitHub's container or binary and also supports GitHub's hosted endpoint, making it useful for both desktop agents and centrally managed environments.
Best for
- Investigating repository context without leaving an agent
- Triage and maintenance across issues and pull requests
- Automating repeatable GitHub workflows with explicit tool boundaries
Not ideal for
- Unauthenticated browsing of arbitrary public GitHub content
- Workflows that cannot tolerate an agent receiving repository metadata
- Replacing organization-level review and branch protection policies
Capabilities
What an agent can do
- 01
Repository content and branch operations
- 02
Issue and pull-request workflows
- 03
Actions and workflow visibility
- 04
Code and secret security findings
- 05
Toolset-level and individual-tool configuration
- 06
Read-only and public-content lockdown modes
Representative tools and operations
get_file_contentssearch_codeissue_readissue_writepull_request_readcreate_pull_requestlist_workflow_runsget_code_scanning_alert
Installation
Connect GitHub MCP Server
Use the publisher’s current instructions as the source of truth. The examples below were checked on .
Claude CodeRun the official container over stdio
claude mcp add github -e GITHUB_PERSONAL_ACCESS_TOKEN=$GITHUB_PAT -- docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server
Set GITHUB_PAT outside the MCP configuration and grant only the scopes required by the enabled toolsets.
Generic MCP clientUse a locally built binary
github-mcp-server stdio
{"command":"/path/to/github-mcp-server","args":["stdio"],"env":{"GITHUB_PERSONAL_ACCESS_TOKEN":"${GITHUB_PAT}"}}
Trust and access
Authentication and security notes
Authentication: OAuth for supported hosted/local flows, or a GitHub personal access token supplied as GITHUB_PERSONAL_ACCESS_TOKEN. Effective access is limited by the signed-in account or token scopes.
Review before connecting
- Start with --read-only when write access is unnecessary.
- Enable only the toolsets or individual tools required for the task.
- Keep tokens out of committed configuration and rotate them regularly.
- Consider lockdown mode when public issue or pull-request content could contain prompt injection.
Known limitations
- Large toolsets consume more model context and may reduce tool-selection accuracy.
- Operations remain subject to GitHub API permissions, policies, and rate limits.
- Configuration syntax and environment-variable expansion differ between MCP clients.
Evidence
Sources used for this guide
Facts were checked against primary publisher material. Descriptions and guidance are original Graphify summaries.
FAQ
Questions about GitHub MCP Server
Can GitHub MCP Server be restricted to read operations?
Yes. Run the server in read-only mode and combine that with a narrowly scoped token and a limited toolset.
Do I need every GitHub tool enabled?
No. Toolsets and individual tool names can be allow-listed so an agent sees only the GitHub surface relevant to its job.