GitHub MCP Server: repos, issues and PRs for your agent
GitHub's official MCP server lets agents browse repos, work issues and pull requests, and dig into failed Actions runs. Hosted with OAuth, or local via Docker.
Project and installation docs
View projecthttps://github.com/github/github-mcp-server
Once a coding agent finishes a change, the next steps usually happen on github.com: open the PR, answer the issue, figure out why CI went red. GitHub MCP Server turns that work into tools: reading files, searching code, managing issues and pull requests, and inspecting Actions runs. GitHub maintains it, offers a hosted remote endpoint, and ships a Docker image for running it locally. It had about 33k stars as of 2026-10-06.
What it does
- Repos and code: browse files, search code and read commit history across every repository your account can reach.
- Issues and PRs: create, update and comment on issues and pull requests, triage bugs and review changes.
- CI debugging: the
actionstoolset reads GitHub Actions runs, analyzes build failures and manages releases. - Security findings: the
code_securityanddependabottoolsets surface code scanning results and Dependabot alerts. - Load only what you need: the default is five toolsets (
context,repos,issues,pull_requests,users).--toolsetsadds or drops groups and--toolspicks individual tools, which keeps the tool list small.
Who it’s for
- Developers in Claude Code, Cursor or VS Code Copilot who want the agent to open the PR and respond to review comments itself.
- Open source maintainers sorting through a daily pile of issues and failed builds.
Setup
Clients with remote MCP support (VS Code 1.101+, Claude Desktop, Cursor and others) connect to the hosted endpoint and sign in with OAuth on first use:
{
"servers": {
"github": {
"type": "http",
"url": "https://api.githubcopilot.com/mcp/"
}
}
}
To run it locally you need Docker, plus either OAuth or a personal access token:
claude mcp add github -e GITHUB_PERSONAL_ACCESS_TOKEN=$GITHUB_PAT -- docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server
Our take
There are plenty of community GitHub servers; the official one should be the default. It has the widest API coverage, a hosted version with nothing to deploy, and toolsets designed with context size in mind. Mind the write access: it can create and edit issues and PRs, so the agent can do whatever your token allows, and the README advises granting only scopes you’re comfortable with. For look-but-don’t-touch, add --read-only. Public issues and comments can also carry prompt injection. --lockdown-mode filters content from authors without push access, but GitHub states plainly that it’s a best-effort filter, not an authorization boundary. GitHub Enterprise Server can’t use the hosted endpoint and needs a local install. Licensed MIT.