Odel
GitHub

GitHub

@github33kGoMITUpdated 3 days ago

Connect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language.

Server endpointStreamable HTTPOAuthProbed

This is the third-party server itself — Odel doesn't run it. Hitting this URL directly talks straight to the upstream server with no auth or proxying. Connect through Odel to front it with managed auth.

Go Report Card

GitHub MCP Server

The GitHub MCP Server connects AI tools directly to GitHub's platform. This gives AI agents, assistants, and chatbots the ability to read repositories and code files, manage issues and PRs, analyze code, and automate workflows. All through natural language interactions.

Use Cases

  • Repository Management: Browse and query code, search files, analyze commits, and understand project structure across any repository you have access to.
  • Issue & PR Automation: Create, update, and manage issues and pull requests. Let AI help triage bugs, review code changes, and maintain project boards.
  • CI/CD & Workflow Intelligence: Monitor GitHub Actions workflow runs, analyze build failures, manage releases, and get insights into your development pipeline.
  • Code Analysis: Examine security findings, review Dependabot alerts, understand code patterns, and get comprehensive insights into your codebase.
  • Team Collaboration: Access discussions, manage notifications, analyze team activity, and streamline processes for your team.

Built for developers who want to connect their AI tools to GitHub context and capabilities, from simple natural language queries to complex multi-step agent workflows.


Remote GitHub MCP Server

Install in VS Code Install in VS Code Insiders Install in Visual Studio

The remote GitHub MCP Server is hosted by GitHub and provides the easiest method for getting up and running. If your MCP host does not support remote MCP servers, don't worry! You can use the local version of the GitHub MCP Server instead.

Prerequisites

  1. A compatible MCP host with remote server support (VS Code 1.101+, Claude Desktop, Cursor, Windsurf, etc.)
  2. Any applicable policies enabled

Install in VS Code

For quick installation, use one of the one-click install buttons above. Once you complete that flow, toggle Agent mode (located by the Copilot Chat text input) and the server will start. Make sure you're using VS Code 1.101 or later for remote MCP and OAuth support.

Alternatively, to manually configure VS Code, choose the appropriate JSON block from the examples below and add it to your host configuration:

Using OAuthUsing a GitHub PAT
VS Code (version 1.101 or greater)
{
  "servers": {
    "github": {
      "type": "http",
      "url": "https://api.githubcopilot.com/mcp/"
    }
  }
}
{
  "servers": {
    "github": {
      "type": "http",
      "url": "https://api.githubcopilot.com/mcp/",
      "headers": {
        "Authorization": "Bearer ${input:github_mcp_pat}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "github_mcp_pat",
      "description": "GitHub Personal Access Token",
      "password": true
    }
  ]
}

Install in other MCP hosts

  • Copilot CLI - Installation guide for GitHub Copilot CLI
  • GitHub Copilot in other IDEs - Installation for JetBrains, Visual Studio, Eclipse, and Xcode with GitHub Copilot
  • Claude Applications - Installation guide for Claude Desktop and Claude Code CLI
  • Codex - Installation guide for OpenAI Codex
  • Cursor - Installation guide for Cursor IDE
  • OpenCode - Installation guide for the OpenCode terminal agent
  • Windsurf - Installation guide for Windsurf IDE
  • Zed - Installation guide for Zed editor
  • Rovo Dev CLI - Installation guide for Rovo Dev CLI

Note: Each MCP host application needs to configure a GitHub App or OAuth App to support remote access via OAuth. Any host application that supports remote MCP servers should support the remote GitHub server with PAT authentication. Configuration details and support levels vary by host. Make sure to refer to the host application's documentation for more info.

Configuration

Toolset configuration

See Remote Server Documentation for full details on remote server configuration, toolsets, headers, and advanced usage. This file provides comprehensive instructions and examples for connecting, customizing, and installing the remote GitHub MCP Server in VS Code and other MCP hosts.

When no toolsets are specified, default toolsets are used.

Insiders Mode

Try new features early! The remote server offers an insiders version with early access to new features and experimental tools.

Using URL PathUsing Header
{
  "servers": {
    "github": {
      "type": "http",
      "url": "https://api.githubcopilot.com/mcp/insiders"
    }
  }
}
{
  "servers": {
    "github": {
      "type": "http",
      "url": "https://api.githubcopilot.com/mcp/",
      "headers": {
        "X-MCP-Insiders": "true"
      }
    }
  }
}

See Remote Server Documentation for more details and examples, and Insiders Features for a full list of what's available.

GitHub Enterprise

GitHub Enterprise Cloud with data residency (ghe.com)

GitHub Enterprise Cloud can also make use of the remote server.

Example for https://octocorp.ghe.com with GitHub PAT token:

{
    ...
    "github-octocorp": {
      "type": "http",
      "url": "https://copilot-api.octocorp.ghe.com/mcp",
      "headers": {
        "Authorization": "Bearer ${input:github_mcp_pat}"
      }
    },
    ...
}

Note: When using OAuth with GitHub Enterprise with VS Code and GitHub Copilot, you also need to configure your VS Code settings to point to your GitHub Enterprise instance - see Authenticate from VS Code

GitHub Enterprise Server

GitHub Enterprise Server does not support remote server hosting. Please refer to GitHub Enterprise Server and Enterprise Cloud with data residency (ghe.com) from the local server configuration.


Local GitHub MCP Server

Install with Docker in VS Code Install with Docker in VS Code Insiders Install with Docker in Visual Studio

Prerequisites

  1. To run the server in a container, you will need to have Docker installed.

  2. Once Docker is installed, you will also need to ensure Docker is running. The Docker image is available at ghcr.io/github/github-mcp-server. The image is public; if you get errors on pull, you may have an expired token and need to docker logout ghcr.io.

  3. Authentication. On github.com you don't need to create anything up front — the one-click buttons above log you in with OAuth on first use (a browser-based flow; the token is kept in memory only). The Docker buttons publish a fixed callback port (127.0.0.1:8085) so the container's login callback is reachable. See Local Server OAuth Login for how it works, headless/device-code fallback, and bringing your own OAuth or GitHub App (required for GitHub Enterprise Server and ghe.com).

    Prefer a token? You can still authenticate with a GitHub Personal Access Token by setting GITHUB_PERSONAL_ACCESS_TOKEN instead (it takes precedence over OAuth). The MCP server can use many of the GitHub APIs, so enable the permissions that you feel comfortable granting your AI tools (to learn more about access tokens, please check out the documentation).

Handling PATs Securely

Environment Variables (Recommended)

To keep your GitHub PAT secure and reusable across different MCP hosts:

  1. Store your PAT in environment variables

    export GITHUB_PAT=your_token_here
    

    Or create a .env file:

    GITHUB_PAT=your_token_here
    
  2. Protect your .env file

    # Add to .gitignore to prevent accidental commits
    echo ".env" >> .gitignore
    
  3. Reference the token in configurations

    # CLI usage
    claude mcp add github -e GITHUB_PERSONAL_ACCESS_TOKEN=$GITHUB_PAT -- docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server
    
    # In config files (where supported)
    "env": {
      "GITHUB_PERSONAL_ACCESS_TOKEN": "$GITHUB_PAT"
    }
    

Note: Environment variable support varies by host app and IDE. Some applications (like Windsurf) require hardcoded tokens in config files.

Token Security Best Practices

  • Minimum scopes: Only grant necessary permissions

    • repo - Repository operations
    • read:packages - Docker image access
    • read:org - Organization team access
  • Separate tokens: Use different PATs for different projects/environments

  • Regular rotation: Update tokens periodically

  • Never commit: Keep tokens out of version control

  • File permissions: Restrict access to config files containing tokens

    chmod 600 ~/.your-app/config.json
    

GitHub Enterprise Server and Enterprise Cloud with data residency (ghe.com)

The flag --gh-host and the environment variable GITHUB_HOST can be used to set the hostname for GitHub Enterprise Server or GitHub Enterprise Cloud with data residency.

  • For GitHub Enterprise Server, prefix the hostname with the https:// URI scheme. HTTPS is required and enforced: non-HTTPS hosts are refused so that credentials are never sent over cleartext (the only exception is a loopback host such as http://localhost for local development).
  • For GitHub Enterprise Cloud with data residency, use https://YOURSUBDOMAIN.ghe.com as the hostname.
"github": {
    "command": "docker",
    "args": [
    "run",
    "-i",
    "--rm",
    "-e",
    "GITHUB_PERSONAL_ACCESS_TOKEN",
    "-e",
    "GITHUB_HOST",
    "ghcr.io/github/github-mcp-server"
    ],
    "env": {
        "GITHUB_PERSONAL_ACCESS_TOKEN": "${input:github_token}",
        "GITHUB_HOST": "https://<your GHES or ghe.com domain name>"
    }
}

Installation

Install in GitHub Copilot on VS Code

For quick installation, use one of the one-click install buttons above. Once you complete that flow, toggle Agent mode (located by the Copilot Chat text input) and the server will start.

More about using MCP server tools in VS Code's agent mode documentation.

Install in GitHub Copilot on other IDEs (JetBrains, Visual Studio, Eclipse, etc.)

Add one of the following JSON blocks to your IDE's MCP settings.

Log in with OAuth (no token to create or store). On github.com the official image already includes the app credentials, so you provide none yourself: it runs a browser-based login on first use and keeps the resulting token in memory only. In Docker this needs a fixed callback port published to loopback so the container's login callback is reachable:

{
  "mcp": {
    "servers": {
      "github": {
        "command": "docker",
        "args": [
          "run",
          "-i",
          "--rm",
          "-p",
          "127.0.0.1:8085:8085",
          "-e",
          "GITHUB_OAUTH_CALLBACK_PORT",
          "ghcr.io/github/github-mcp-server"
        ],
        "env": {
          "GITHUB_OAUTH_CALLBACK_PORT": "8085"
        }
      }
    }
  }
}

See Local Server OAuth Login for the native-binary flow (no fixed port needed), the headless/device-code fallback, GitHub Enterprise Server / ghe.com, and bringing your own OAuth or GitHub App.

For non-interactive stdio deployments, see GitHub App Authentication.

Or authenticate with a Personal Access Token. Set GITHUB_PERSONAL_ACCESS_TOKEN instead (it takes precedence over OAuth):

{
  "mcp": {
    "inputs": [
      {
        "type": "promptString",
        "id": "github_token",
        "description": "GitHub Personal Access Token",
        "password": true
      }
    ],
    "servers": {
      "github": {
        "command": "docker",
        "args": [
          "run",
          "-i",
          "--rm",
          "-e",
          "GITHUB_PERSONAL_ACCESS_TOKEN",
          "ghcr.io/github/github-mcp-server"
        ],
        "env": {
          "GITHUB_PERSONAL_ACCESS_TOKEN": "${input:github_token}"
        }
      }
    }
  }
}

Optionally, you can add a similar example (i.e. without the mcp key) to a file called .vscode/mcp.json in your workspace. This will allow you to share the configuration with other host applications that accept the same format.

Example JSON block without the MCP key included
{
  "inputs": [
    {
      "type": "promptString",
      "id": "github_token",
      "description": "GitHub Personal Access Token",
      "password": true
    }
  ],
  "servers": {
    "github": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-e",
        "GITHUB_PERSONAL_ACCESS_TOKEN",
        "ghcr.io/github/github-mcp-server"
      ],
      "env": {
        "GITHUB_PERSONAL_ACCESS_TOKEN": "${input:github_token}"
      }
    }
  }
}

Install in Other MCP Hosts

For other MCP host applications, please refer to our installation guides:

For a complete overview of all installation options, see our Installation Guides Index.

Note: Any host application that supports local MCP servers should be able to access the local GitHub MCP server. However, the specific configuration process, syntax and stability of the integration will vary by host application. While many may follow a similar format to the examples above, this is not guaranteed. Please refer to your host application's documentation for the correct MCP configuration syntax and setup process.

Build from source

If you don't have Docker, you can use go build to build the binary in the cmd/github-mcp-server directory, and use the github-mcp-server stdio command with the GITHUB_PERSONAL_ACCESS_TOKEN environment variable set to your token. To specify the output location of the build, use the -o flag. You should configure your server to use the built executable as its command. For example:

{
  "mcp": {
    "servers": {
      "github": {
        "command": "/path/to/github-mcp-server",
        "args": ["stdio"],
        "env": {
          "GITHUB_PERSONAL_ACCESS_TOKEN": "<YOUR_TOKEN>"
        }
      }
    }
  }
}

Tool Configuration

The GitHub MCP Server supports enabling or disabling specific groups of functionalities via the --toolsets flag. This allows you to control which GitHub API capabilities are available to your AI tools. Enabling only the toolsets that you need can help the LLM with tool choice and reduce the context size.

Toolsets are not limited to Tools. Relevant MCP Resources and Prompts are also included where applicable.

When no toolsets are specified, default toolsets are used.

Looking for examples? See the Server Configuration Guide for common recipes like minimal setups, read-only mode, and combining tools with toolsets.

Specifying Toolsets

To specify toolsets you want available to the LLM, you can pass an allow-list in two ways:

  1. Using Command Line Argument:

    github-mcp-server --toolsets repos,issues,pull_requests,actions,code_security
    
  2. Using Environment Variable:

    GITHUB_TOOLSETS="repos,issues,pull_requests,actions,code_security" ./github-mcp-server
    

The environment variable GITHUB_TOOLSETS takes precedence over the command line argument if both are provided.

Specifying Individual Tools

You can also configure specific tools using the --tools flag. Tools can be used independently or combined with toolsets for fine-grained control.

  1. Using Command Line Argument:

    github-mcp-server --tools get_file_contents,issue_read,create_pull_request
    
  2. Using Environment Variable:

    GITHUB_TOOLS="get_file_contents,issue_read,create_pull_request" ./github-mcp-server
    
  3. Combining with Toolsets (additive):

    github-mcp-server --toolsets repos,issues --tools get_gist
    

    This registers all tools from repos and issues toolsets, plus get_gist.

Important Notes:

  • Tools and toolsets can be used together
  • Read-only mode takes priority: write tools are skipped if --read-only is set, even if explicitly requested via --tools
  • Tool names must match exactly (e.g., get_file_contents, not getFileContents). Invalid tool names will cause the server to fail at startup with an error message
  • When tools are renamed, old names are preserved as aliases for backward compatibility. See Tool Renaming for details.

Using Toolsets With Docker

When using Docker, you can pass the toolsets as environment variables:

docker run -i --rm \
  -e GITHUB_PERSONAL_ACCESS_TOKEN=<your-token> \
  -e GITHUB_TOOLSETS="repos,issues,pull_requests,actions,code_security" \
  ghcr.io/github/github-mcp-server

Using Tools With Docker

When using Docker, you can pass specific tools as environment variables. You can also combine tools with toolsets:

# Tools only
docker run -i --rm \
  -e GITHUB_PERSONAL_ACCESS_TOKEN=<your-token> \
  -e GITHUB_TOOLS="get_file_contents,issue_read,create_pull_request" \
  ghcr.io/github/github-mcp-server

# Tools combined with toolsets (additive)
docker run -i --rm \
  -e GITHUB_PERSONAL_ACCESS_TOKEN=<your-token> \
  -e GITHUB_TOOLSETS="repos,issues" \
  -e GITHUB_TOOLS="get_gist" \
  ghcr.io/github/github-mcp-server

Special toolsets

"all" toolset

The special toolset all can be provided to enable all available toolsets regardless of any other configuration:

./github-mcp-server --toolsets all

Or using the environment variable:

GITHUB_TOOLSETS="all" ./github-mcp-server

"default" toolset

The default toolset default is the configuration that gets passed to the server if no toolsets are specified.

The default configuration is:

  • context
  • repos
  • issues
  • pull_requests
  • users

To keep the default configuration and add additional toolsets:

GITHUB_TOOLSETS="default,stargazers" ./github-mcp-server

Insiders Mode

The local GitHub MCP Server offers an insiders version with early access to new features and experimental tools.

  1. Using Command Line Argument:

    ./github-mcp-server --insiders
    
  2. Using Environment Variable:

    GITHUB_INSIDERS=true ./github-mcp-server
    

When using Docker:

docker run -i --rm \
  -e GITHUB_PERSONAL_ACCESS_TOKEN=<your-token> \
  -e GITHUB_INSIDERS=true \
  ghcr.io/github/github-mcp-server

Available Toolsets

The following sets of tools are available:

ToolsetDescription
personcontextStrongly recommended: Tools that provide context about the current user and GitHub context you are operating in
workflowactionsGitHub Actions workflows and CI/CD operations
code-squarecode_qualityGitHub Code Quality related tools
codescancode_securityCode security related tools, such as GitHub Code Scanning
copilotcopilotCopilot related tools
copilotcopilot_issue_intentsOpt-in Copilot issue assignment tools that carry intent metadata (rationale, confidence, suggestion)
dependabotdependabotDependabot tools
comment-discussiondiscussionsGitHub Discussions related tools
logo-gistgistsGitHub Gist related tools
git-branchgitGitHub Git API related tools for low-level Git operations
lawgovernanceRepository governance tools for managing rulesets and custom properties at the repository, organization, and enterprise levels
issue-openedissuesGitHub Issues related tools
taglabelsGitHub Labels related tools
bellnotificationsGitHub Notifications related tools
organizationorgsGitHub Organization related tools
projectprojectsGitHub Projects related tools
git-pull-requestpull_requestsGitHub Pull Request related tools
reporeposGitHub Repository related tools
shield-locksecret_protectionSecret protection related tools, such as GitHub Secret Scanning
shieldsecurity_advisoriesSecurity advisories related tools
starstargazersGitHub Stargazers related tools
peopleusersGitHub User related tools

Additional Toolsets in Remote GitHub MCP Server

ToolsetDescription
copilotCopilot related tools (e.g. Copilot Coding Agent)
copilot_spacesCopilot Spaces related tools
github_support_docs_searchSearch docs to answer GitHub product and support questions

Tools

workflow Actions
  • actions_get - Get details of GitHub Actions resources (workflows, workflow runs, jobs, and artifacts)

    • OAuth Challenge Scopes: repo
    • method: The method to execute (string, required)
    • owner: Repository owner (string, required)
    • repo: Repository name (string, required)
    • resource_id: The unique identifier of the resource. This will vary based on the "method" provided, so ensure you provide the correct ID:
      • Provide a workflow ID or workflow file name (e.g. ci.yaml) for 'get_workflow' method.
      • Provide a workflow run ID for 'get_workflow_run', 'get_workflow_run_usage', and 'get_workflow_run_logs_url' methods.
      • Provide an artifact ID for 'download_workflow_run_artifact' method.
      • Provide a job ID for 'get_workflow_job' method. (string, required)
  • actions_list - List GitHub Actions workflows in a repository

    • OAuth Challenge Scopes: repo
    • method: The action to perform (string, required)
    • owner: Repository owner (string, required)
    • page: Page number for pagination (default: 1) (number, optional)
    • perPage: Results per page for pagination (default: 30, max: 100) (number, optional)
    • repo: Repository name (string, required)
    • resource_id: The unique identifier of the resource. This will vary based on the "method" provided, so ensure you provide the correct ID:
      • Do not provide any resource ID for 'list_workflows' method.
      • Provide a workflow ID or workflow file name (e.g. ci.yaml) for 'list_workflow_runs' method, or omit to list all workflow runs in the repository.
      • Provide a workflow run ID for 'list_workflow_jobs' and 'list_workflow_run_artifacts' methods. (string, optional)
    • workflow_jobs_filter: Filters for workflow jobs. ONLY used when method is 'list_workflow_jobs' (object, optional)
    • workflow_runs_filter: Filters for workflow runs. ONLY used when method is 'list_workflow_runs' (object, optional)
  • actions_run_trigger - Trigger GitHub Actions workflow actions

    • OAuth Challenge Scopes: repo
    • inputs: Inputs the workflow accepts. Only used for 'run_workflow' method. (object, optional)
    • method: The method to execute (string, required)
    • owner: Repository owner (string, required)
    • ref: The git reference for the workflow. The reference can be a branch or tag name. Required for 'run_workflow' method. (string, optional)
    • repo: Repository name (string, required)
    • run_id: The ID of the workflow run. Required for all methods except 'run_workflow'. (number, optional)
    • workflow_id: The workflow ID (numeric) or workflow file name (e.g., main.yml, ci.yaml). Required for 'run_workflow' method. (string, optional)
  • get_job_logs - Get GitHub Actions workflow job logs

    • OAuth Challenge Scopes: repo
    • failed_only: When true, gets logs for all failed jobs in the workflow run specified by run_id. Requires run_id to be provided. (boolean, optional)
    • job_id: The unique identifier of the workflow job. Required when getting logs for a single job. (number, optional)
    • owner: Repository owner (string, required)
    • repo: Repository name (string, required)
    • return_content: Returns actual log content instead of URLs (boolean, optional)
    • run_id: The unique identifier of the workflow run. Required when failed_only is true to get logs for all failed jobs in the run. (number, optional)
    • tail_lines: Number of lines to return from the end of the log (number, optional)
code-square Code Quality
  • get_code_quality_finding - Get code quality finding
    • OAuth Challenge Scopes: repo
    • findingNumber: The number of the finding. (number, required)
    • owner: The owner of the repository. (string, required)
    • repo: The name of the repository. (string, required)
codescan Code Security
  • get_code_scanning_alert - Get code scanning alert

    • OAuth Challenge Scopes: security_events
    • alertNumber: The number of the alert. (number, required)
    • owner: The owner of the repository. (string, required)
    • repo: The name of the repository. (string, required)
  • list_code_scanning_alerts - List code scanning alerts

    • OAuth Challenge Scopes: security_events
    • owner: The owner of the repository. (string, required)
    • page: Page number for pagination (min 1) (number, optional)
    • perPage: Results per page for pagination (min 1, max 100) (number, optional)
    • ref: The Git reference for the results you want to list. (string, optional)
    • repo: The name of the repository. (string, required)
    • severity: Filter code scanning alerts by severity (string, optional)
    • state: Filter code scanning alerts by state. Defaults to open (string, optional)
    • tool_name: The name of the tool used for code scanning. (string, optional)
person Context
  • get_me - Get my user profile

    • No parameters required
  • get_team_members - Get team members

    • OAuth Challenge Scopes: read:org
    • org: Organization login (owner) that contains the team. (string, required)
    • team_slug: Team slug (string, required)
  • get_teams - Get teams

    • OAuth Challenge Scopes: read:org
    • user: Username to get teams for. If not provided, uses the authenticated user. (string, optional)
copilot Copilot
  • assign_copilot_to_issue - Assign Copilot to issue

    • OAuth Challenge Scopes: repo
    • base_ref: Git reference (e.g., branch) that the agent will start its work from. If not specified, defaults to the repository's default branch (string, optional)
    • custom_instructions: Optional custom instructions to guide the agent beyond the issue body. Use this to provide additional context, constraints, or guidance that is not captured in the issue description (string, optional)
    • issue_number: Issue number (number, required)
    • owner: Repository owner (string, required)
    • repo: Repository name (string, required)
  • request_copilot_review - Request Copilot review

    • OAuth Challenge Scopes: repo
    • owner: Repository owner (string, required)
    • pullNumber: Pull request number (number, required)
    • repo: Repository name (string, required)
copilot Copilot Issue Intents
  • assign_copilot_to_issue_with_intent - Assign Copilot to issue with intent
    • OAuth Challenge Scopes: repo
    • base_ref: Git reference (e.g., branch) that the agent will start its work from. If not specified, defaults to the repository's default branch. Ignored when is_suggestion is true (string, optional)
    • confidence: How confident you are in this choice. 'HIGH' for clear signal or explicit user request, 'MEDIUM' for reasonable inference with some ambiguity, 'LOW' for best guess with limited signal. (string, required)
    • custom_instructions: Optional custom instructions to guide the agent beyond the issue body. Ignored when is_suggestion is true (string, optional)
    • is_suggestion: If true, records a pending Copilot assignment intent rather than launching the agent. Approval later supplies the launch context; base_ref and custom_instructions are ignored in this case. (boolean, required)
    • issue_number: Issue number (number, required)
    • owner: Repository owner (string, required)
    • rationale: One concise sentence explaining what specifically about the issue led to choosing Copilot. State the concrete signal (e.g. 'Well-scoped task with clear acceptance criteria'). (string, required)
    • repo: Repository name (string, required)
dependabot Dependabot
  • get_dependabot_alert - Get dependabot alert

    • OAuth Challenge Scopes: security_events
    • alertNumber: The number of the alert. (number, required)
    • owner: The owner of the repository. (string, required)
    • repo: The name of the repository. (string, required)
  • list_dependabot_alerts - List dependabot alerts

    • OAuth Challenge Scopes: security_events
    • after: Cursor for pagination. Use the cursor from the previous response. (string, optional)
    • owner: The owner of the repository. (string, required)
    • perPage: Results per page for pagination (min 1, max 100) (number, optional)
    • repo: The name of the repository. (string, required)
    • severity: Filter dependabot alerts by severity (string, optional)
    • state: Filter dependabot alerts by state. Defaults to open (string, optional)
comment-discussion Discussions
  • discussion_comment_write - Manage discussion comments

    • OAuth Challenge Scopes: repo
    • body: Comment content (required for 'add', 'reply', and 'update' methods) (string, optional)
    • commentNodeID: The Node ID of the discussion comment (required for 'reply', 'update', 'delete', 'mark_answer', and 'unmark_answer' methods). For 'reply', this is the top-level comment to reply to; GitHub Discussions only support one level of nesting. (string, optional)
    • discussionNumber: Discussion number (required for 'add' and 'reply' methods) (number, optional)
    • method: Write operation to perform on a discussion comment. Options are:
      • 'add' - adds a new top-level comment to a discussion.
      • 'reply' - replies to a top-level discussion comment (GitHub Discussions only support one level of nesting).
      • 'update' - updates an existing discussion comment.
      • 'delete' - deletes a discussion comment.
      • 'mark_answer' - marks a discussion comment as the answer (Q&A only).
      • 'unmark_answer' - unmarks a discussion comment as the answer (Q&A only). (string, required)
    • owner: Repository owner (required for 'add' and 'reply' methods) (string, optional)
    • repo: Repository name (required for 'add' and 'reply' methods) (string, optional)
  • get_discussion - Get discussion

    • OAuth Challenge Scopes: repo
    • discussionNumber: Discussion Number (number, required)
    • owner: Repository owner (string, required)
    • repo: Repository name (string, required)
  • get_discussion_comments - Get discussion comments

    • OAuth Challenge Scopes: repo
    • after: Cursor for pagination. Use the cursor from the previous response. (string, optional)
    • discussionNumber: Discussion Number (number, required)
    • includeReplies: When true, each top-level comment will include its replies nested within it (up to 100 replies per comment, which is the GitHub API maximum). Defaults to false. (boolean, optional)
    • owner: Repository owner (string, required)
    • perPage: Results per page for pagination (min 1, max 100) (number, optional)
    • repo: Repository name (string, required)
  • list_discussion_categories - List discussion categories

    • OAuth Challenge Scopes: repo
    • owner: Repository owner (string, required)
    • repo: Repository name. If not provided, discussion categories will be queried at the organisation level. (string, optional)
  • list_discussions - List discussions

    • OAuth Challenge Scopes: repo
    • after: Cursor for pagination. Use the cursor from the previous response. (string, optional)
    • category: Optional filter by discussion category ID. If provided, only discussions with this category are listed. (string, optional)
    • direction: Order direction. (string, optional)
    • orderBy: Order discussions by field. If provided, the 'direction' also needs to be provided. (string, optional)
    • owner: Repository owner (string, required)
    • perPage: Results per page for pagination (min 1, max 100) (number, optional)
    • repo: Repository name. If not provided, discussions will be queried at the organisation level. (string, optional)
logo-gist Gists
  • create_gist - Create Gist

    • OAuth Challenge Scopes: gist
    • content: Content for simple single-file gist creation (string, required)
    • description: Description of the gist (string, optional)
    • filename: Filename for simple single-file gist creation (string, required)
    • public: Whether the gist is public (boolean, optional)
  • get_gist - Get Gist Content

    • gist_id: The ID of the gist (string, required)
  • list_gists - List Gists

    • page: Page number for pagination (min 1) (number, optional)
    • perPage: Results per page for pagination (min 1, max 100) (number, optional)
    • since: Only gists updated after this time (ISO 8601 timestamp) (string, optional)
    • username: GitHub username (omit for authenticated user's gists) (string, optional)
  • update_gist - Update Gist

    • OAuth Challenge Scopes: gist
    • content: Content for the file (string, required)
    • description: Updated description of the gist (string, optional)
    • filename: Filename to update or create (string, required)
    • gist_id: ID of the gist to update (string, required)
git-branch Git
  • get_repository_tree - Get repository tree
    • OAuth Challenge Scopes: repo
    • owner: Repository owner (username or organization) (string, required)
    • path_filter: Optional path prefix to filter the tree results (e.g., 'src/' to only show files in the src directory) (string, optional)
    • recursive: Setting this parameter to true returns the objects or subtrees referenced by the tree. Default is false (boolean, optional)
    • repo: Repository name (string, required)
    • tree_sha: The SHA1 value or ref (branch or tag) name of the tree. Defaults to the repository's default branch (string, optional)
law Governance
  • create_repository_ruleset - Create repository ruleset

    • OAuth Challenge Scopes: repo, admin:org, admin:enterprise
    • bypass_actors: The actors that can bypass the rules in this ruleset (object[], optional)
    • conditions: Conditions for when this ruleset applies, e.g. {"ref_name": {"include": ["refs/heads/main"], "exclude": []}} (object, optional)
    • enforcement: The enforcement level of the ruleset. 'evaluate' allows admins to test rules before enforcing them (string, required)
    • enterprise: Enterprise slug. Required when level is 'enterprise'. (string, optional)
    • level: The level at which the ruleset is configured:
      • 'repository': A ruleset on a single repository (requires 'owner' and 'repo').
      • 'organization': A ruleset covering repositories in an organization (requires 'org').
      • 'enterprise': A ruleset covering repositories across an enterprise (requires 'enterprise'). (string, required)
    • name: The name of the ruleset (string, required)
    • org: Organization name. Required when level is 'organization'. (string, optional)
    • owner: Repository owner. Required when level is 'repository'. (string, optional)
    • repo: Repository name. Required when level is 'repository'. (string, optional)
    • rules: An array of rules within the ruleset. Each rule is an object with a 'type' (e.g. 'creation', 'deletion', 'non_fast_forward', 'required_signatures', 'pull_request', 'required_status_checks') and, for rules that need configuration, a 'parameters' object (object[], required)
    • target: The target of the ruleset. Defaults to 'branch'. 'repository' is only valid for 'organization' and 'enterprise' level rulesets. (string, optional)
  • custom_properties_read - Read custom properties

    • OAuth Challenge Scopes: repo, read:org, read:enterprise
    • enterprise: Enterprise slug. Required when level is 'enterprise'. (string, optional)
    • level: The level at which custom properties are managed:
      • 'repository': The custom property VALUES assigned to a repository (requires 'owner' and 'repo').
      • 'organization': The custom property DEFINITIONS (schema) for an organization (requires 'org').
      • 'enterprise': The custom property DEFINITIONS (schema) for an enterprise (requires 'enterprise'). (string, required)
    • org: Organization name. Required when level is 'organization'. (string, optional)
    • owner: Repository owner. Required when level is 'repository'. (string, optional)
    • repo: Repository name. Required when level is 'repository'. (string, optional)
  • custom_properties_write - Set custom properties

    • OAuth Challenge Scopes: repo, admin:org, admin:enterprise
    • enterprise: Enterprise slug. Required when level is 'enterprise'. (string, optional)
    • level: The level at which custom properties are managed:
      • 'repository': The custom property VALUES assigned to a repository (requires 'owner' and 'repo').
      • 'organization': The custom property DEFINITIONS (schema) for an organization (requires 'org').
      • 'enterprise': The custom property DEFINITIONS (schema) for an enterprise (requires 'enterprise'). (string, required)
    • org: Organization name. Required when level is 'organization'. (string, optional)
    • owner: Repository owner. Required when level is 'repository'. (string, optional)
    • properties: The custom properties to create or update. At the repository level each item assigns a value ('property_name' and 'value'); at the organization and enterprise levels each item defines the schema ('property_name' and 'value_type', plus optional definition fields). (object[], required)
    • repo: Repository name. Required when level is 'repository'. (string, optional)
  • repository_ruleset_read - Read repository rulesets

    • OAuth Challenge Scopes: repo, read:org, read:enterprise
    • actor_name: The handle for the GitHub user account to filter rule suites on. Used by the 'list_rule_suites' method. (string, optional)
    • branch: Branch name. Required for the 'get_rules_for_branch' method. (string, optional)
    • enterprise: Enterprise slug. Required when level is 'enterprise'. (string, optional)
    • evaluate_status: Filter rule suites by ruleset evaluation mode. Used by the 'list_rule_suites' method. (string, optional)
    • includes_parents: Include rulesets configured at higher levels that also apply. Defaults to true. Used by the 'get' and 'list' methods at the repository level. (boolean, optional)
    • level: The level at which the ruleset is configured:
      • 'repository': A ruleset on a single repository (requires 'owner' and 'repo').
      • 'organization': A ruleset covering repositories in an organization (requires 'org').
      • 'enterprise': A ruleset covering repositories across an enterprise (requires 'enterprise'). (string, required)
    • method: Operation to perform:
      • 'get': Get a specific ruleset by ID (requires 'ruleset_id'). Supported at every level.
      • 'list': List all rulesets. Supported at every level.
      • 'get_rules_for_branch': Get all rules that apply to a branch (requires 'branch'). Repository level only.
      • 'list_rule_suites': List rule suites, the evaluations of rules against pushes. Repository and organization levels only.
      • 'get_rule_suite': Get a specific rule suite by ID (requires 'rule_suite_id'). Repository and organization levels only. (string, required)
    • org: Organization name. Required when level is 'organization'. (string, optional)
    • owner: Repository owner. Required when level is 'repository'. (string, optional)
    • page: Page number for pagination (min 1) (number, optional)
    • perPage: Results per page for pagination (min 1, max 100) (number, optional)
    • ref: The name of the ref (branch, tag, etc.) to filter rule suites by. Used by the 'list_rule_suites' method. (string, optional)
    • repo: Repository name. Required when level is 'repository'. (string, optional)
    • repository_name: Repository name to filter rule suites by. Used by the 'list_rule_suites' method at the organization level. (string, optional)
    • rule_suite_id: Rule suite ID. Required for the 'get_rule_suite' method. (number, optional)
    • rule_suite_result: The rule suite result to filter by. Used by the 'list_rule_suites' method. (string, optional)
    • ruleset_id: Ruleset ID. Required for the 'get' method. (number, optional)
    • time_period: The time period to filter rule suites by. Used by the 'list_rule_suites' method. (string, optional)
issue-opened Issues
  • add_issue_comment - Add comment to issue or pull request

    • OAuth Challenge Scopes: repo
    • body: Comment content. Required unless reaction is provided. (string, optional)
    • comment_id: The numeric ID of the issue or pull request comment to react to. Use this for reactions to comments; omit it to react to the issue or pull request itself. Cannot be combined with body. (integer, optional)
    • issue_number: Issue or pull request number to comment on or react to. (number, required)
    • owner: Repository owner (string, required)
    • reaction: Emoji reaction to add. Required unless body is provided. (string, optional)
    • repo: Repository name (string, required)
  • get_label - Get a specific label from a repository

    • OAuth Challenge Scopes: repo
    • name: Label name. (string, required)
    • owner: Repository owner (username or organization name) (string, required)
    • repo: Repository name (string, required)
  • issue_read - Get issue details

    • OAuth Challenge Scopes: repo
    • issue_number: The number of the issue (number, required)
    • method: The read operation to perform on a single issue. Options are:
      1. get - Get issue details. Also returns best-effort hierarchy flags (has_parent, has_children); parent and sub_issues_summary are optional relationship summaries, and closed_by_pull_requests summarizes the pull requests configured to close the issue as total_count plus up to 5 references.
      2. get_comments - Get issue comments.
      3. get_sub_issues - Get sub-issues (children) of the issue.
      4. get_parent - Get the parent issue, if this issue is a sub-issue of another.
      5. get_labels - Get labels assigned to the issue. (string, required)
    • owner: The owner of the repository (string, required)
    • page: Page number for pagination (min 1) (number, optional)
    • perPage: Results per page for pagination (min 1, max 100) (number, optional)
    • repo: The name of the repository (string, required)
  • issue_write - Create or update issue/pull request

    • OAuth Challenge Scopes: repo
    • assignees: Usernames to assign to this issue (string[], optional)
    • body: Issue body content (string, optional)
    • duplicate_of: Issue number that this issue is a duplicate of. Required when state_reason is 'duplicate'. (number, optional)
    • issue_fields: Issue field values to set or clear. Each item requires 'field_name' and exactly one of 'value', 'field_option_name', or 'delete: true'. (object[], optional)
    • issue_number: Issue number to update (number, optional)
    • labels: Labels to apply to this issue (string[], optional)
    • method: Write operation to perform on a single issue. Options are:
      • 'create' - creates a new issue.
      • 'update' - updates an existing issue. (string, required)
    • milestone: Milestone number (number, optional)
    • owner: Repository owner (string, required)
    • parent_issue_number: Issue number of the parent issue. Only used when method is 'create' and cannot be combined with issue_fields. The new issue is created and attached to this parent in the same operation. (number, optional)
    • parent_owner: Repository owner of the parent issue. Must be provided with parent_repo. Omit both to use owner and repo. Only used when method is 'create' and parent_issue_number is provided. (string, optional)
    • parent_repo: Repository name of the parent issue. Must be provided with parent_owner. Omit both to use owner and repo. Only used when method is 'create' and parent_issue_number is provided. (string, optional)
    • repo: Repository name (string, required)
    • state: New state (string, optional)
    • state_reason: Reason for the state change. Ignored unless state is changed. (string, optional)
    • title: Issue title (string, optional)
    • type: Type of this issue. For updates, pass null to remove the current type. Only use if issue types are enabled for this repository. Use list_issue_types to get valid type values for this repository or its owner organization. If the repository doesn't support issue types, omit this parameter. (string | null, optional)
  • list_issue_fields - List issue fields

    • OAuth Challenge Scopes: repo, read:org
    • owner: The account owner of the repository or organization. The name is not case sensitive. (string, required)
    • repo: The name of the repository. When provided, returns fields for this specific repository (inherited from its organization). When omitted, returns org-level fields directly. (string, optional)
  • list_issue_types - List available issue types

    • OAuth Challenge Scopes: repo, read:org
    • owner: The account owner of the repository or organization. (string, required)
    • repo: The name of the repository. When provided, returns issue types for this specific repository. When omitted, returns org-level issue types directly. (string, optional)
  • list_issues - List issues

    • OAuth Challenge Scopes: repo
    • after: Cursor for pagination. Use the cursor from the previous response. (string, optional)
    • direction: Order direction. If provided, the 'orderBy' also needs to be provided. (string, optional)
    • field_filters: Filter by custom issue field values. Each entry takes a field_name and a value; the server looks up the field and coerces the value to its type (single-select option name, text, number, or YYYY-MM-DD date). (object[], optional)
    • fields: Subset of fields to return for each issue. If omitted, all fields are returned. Use this to reduce response size when you only need specific fields; omitting 'body' and 'field_values' in particular drops the largest per-result data. (string[], optional)
    • labels: Filter by labels (string[], optional)
    • orderBy: Order issues by field. If provided, the 'direction' also needs to be provided. (string, optional)
    • owner: Repository owner (string, required)
    • perPage: Results per page for pagination (min 1, max 100) (number, optional)
    • repo: Repository name (string, required)
    • since: Filter by date (ISO 8601 timestamp) (string, optional)
    • state: Filter by state, by default both open and closed issues are returned when not provided (string, optional)
  • search_issues - Search issues

    • OAuth Challenge Scopes: repo
    • fields: Subset of fields to return for each issue result. If omitted, all fields are returned. Use this to reduce response size when you only need specific fields; omitting 'body', 'reactions', and 'labels' in particular drops the largest per-result data. (string[], optional)
    • order: Sort order (string, optional)
    • owner: Optional repository owner. If provided with repo, only issues for this repository are listed. (string, optional)
    • page: Page number for pagination (min 1) (number, optional)
    • perPage: Results per page for pagination (min 1, max 100) (number, optional)
    • query: The search query, as natural language. When the user gives alternative wordings, include them as plain words rather than joining them with OR. (string, required)
    • repo: Optional repository name. If provided with owner, only issues for this repository are listed. (string, optional)
    • sort: Sort field by number of matches of categories, defaults to best match (string, optional)
  • sub_issue_write - Change sub-issue

    • OAuth Challenge Scopes: repo
    • after_id: The ID of the sub-issue to be prioritized after (either after_id OR before_id should be specified) (number, optional)
    • before_id: The ID of the sub-issue to be prioritized before (either after_id OR before_id should be specified) (number, optional)
    • issue_number: The number of the parent issue (number, required)
    • method: The action to perform on a single sub-issue Options are:
      • 'add' - add a sub-issue to a parent issue in a GitHub repository.
      • 'remove' - remove a sub-issue from a parent issue in a GitHub repository.
      • 'reprioritize' - change the order of sub-issues within a parent issue in a GitHub repository. Use either 'after_id' or 'before_id' to specify the new position. Writes issue hierarchy. To move a sub-issue to a new parent, use add with replace_parent=true; there is no writable parent field. (string, required)
    • owner: Repository owner (string, required)
    • replace_parent: When true, replaces the sub-issue's current parent issue. Use with 'add' method only. (boolean, optional)
    • repo: Repository name (string, required)
    • sub_issue_id: The ID of the sub-issue to add. ID is not the same as issue number (number, required)
tag Labels
  • get_label - Get a specific label from a repository

    • OAuth Challenge Scopes: repo
    • name: Label name. (string, required)
    • owner: Repository owner (username or organization name) (string, required)
    • repo: Repository name (string, required)
  • label_write - Write operations on repository labels

    • OAuth Challenge Scopes: repo
    • color: Label color as 6-character hex code without '#' prefix (e.g., 'f29513'). Required for 'create', optional for 'update'. (string, optional)
    • description: Label description text. Optional for 'create' and 'update'. (string, optional)
    • `met