GitHub MCP Server Explained: Setup, Tools, and Auth
The GitHub MCP server is GitHub's official Model Context Protocol (MCP) server. It lets an AI app like Claude Code, Cursor or VS Code read and manage your issues, pull requests, Actions runs and code, without you writing any API code. You can use GitHub's hosted endpoint, or run the server yourself in Docker.
What can you ask it to do?
Say you're in Claude Code and type: "Summarize the open pull requests on my repo and tell me which ones have failing checks."
With the GitHub MCP server connected, Claude lists the pull requests, looks at their check runs, and gives you the summary. It calls the server's tools instead of guessing. You can also ask it to comment on an issue, search code, or open a pull request, if you've switched those tools on.
The source is public at github/github-mcp-server. If you're new to the idea, an MCP server is just a program that offers tools to AI apps through a shared protocol.
Remote or local: which should you pick?
As of September 2026, GitHub offers two ways to run it.
| Mode | Setup | Auth | Use it when |
|---|---|---|---|
| Remote, hosted by GitHub | https://api.githubcopilot.com/mcp/, nothing to install | OAuth where your app supports it, or a personal access token (PAT) in the Authorization header | You use github.com. GitHub's docs recommend this for most people. |
| Local, run by you | Docker image ghcr.io/github/github-mcp-server, or build the Go binary | A PAT in the GITHUB_PERSONAL_ACCESS_TOKEN env var | You use GitHub Enterprise Server (set GITHUB_HOST), run in CI, or want the process under your control. |
Start with the remote endpoint. It's one URL and no maintenance. Reach for the local server when you need Enterprise Server or full control over where it runs.
Connect it to your AI app
The remote URL is the same everywhere. Each app just wants it in a different place.
Claude Code
claude mcp add --transport http github https://api.githubcopilot.com/mcp/ \
--header "Authorization: Bearer YOUR_GITHUB_PAT"
For the general mechanics, including scopes and troubleshooting, see the guide to adding an MCP server to Claude Code.
Cursor
Cursor has no GitHub-specific snippet in its docs, so you adapt the remote URL into .cursor/mcp.json for a project, or Cursor's global mcp.json:
{
"mcpServers": {
"github": {
"url": "https://api.githubcopilot.com/mcp/",
"headers": {
"Authorization": "Bearer YOUR_GITHUB_PAT"
}
}
}
}
More on this file shape in the guide to adding an MCP server to Cursor.
VS Code and GitHub Copilot
GitHub's docs have one-click install buttons. To do it by hand, add this to .vscode/mcp.json for the OAuth remote endpoint:
{
"servers": {
"github": {
"type": "http",
"url": "https://api.githubcopilot.com/mcp/"
}
}
}
For the local server, the entry becomes a command, args and env block that runs the Docker image with your PAT set.
Which tools does it expose?
The server groups its tools into toolsets instead of one long list. The repository documents toolsets such as Actions, Code Security, Dependabot, Discussions, Gists, Issues, Notifications, Organizations, Projects, Pull Requests, Repositories and Users.
On the local server, two environment variables control what your AI app sees:
GITHUB_TOOLSETSis a comma-separated list of toolsets to enable. An app that only needs Issues and Pull Requests never sees the Actions tools.GITHUB_TOOLSadds individual tools on top of the selected toolsets. It doesn't remove anything, so check the resulting tool list.
The remote endpoint uses headers or URL options instead, described in GitHub's remote-server docs.
OAuth or personal access token?
Use OAuth when your app supports it, since you sign in and there's no token to store. Use a PAT when it doesn't, or when you run the local server.
Either way, the AI can only do what that credential can do. Limit a PAT to the repositories and permissions the task needs, and set an expiry. Narrowing the tool list helps, but it never gives the credential more access than it already has.
How do you check it's set up safely?
Try it on a test repository first.
- Ask the AI to read one issue you know, and compare its answer with GitHub.
- Ask it to read a repository outside the intended scope, and confirm it's refused.
- For writes, give it one explicit task, like commenting on a test issue. Review what it proposes, then check on GitHub which account made the change.
Keep real tokens out of source control, and recheck access whenever you change a token, an organization policy or the toolsets. The same habits are covered in the MCP security guide.
Where MCPifex fits
GitHub runs its own hosted server, so you connect to it through GitHub, not through us. MCPifex hosts other servers, such as PostgreSQL and Google Trends. You save their credentials in the portal, choose which tools are enabled, and connect any MCP client with one API key. See the marketplace for what's available.
Key takeaways
- The GitHub MCP server is GitHub's official server for issues, pull requests, Actions and code search.
- Use the remote endpoint for github.com. Use the local Docker server for GitHub Enterprise Server or CI.
- Claude Code, Cursor and VS Code use the same URL but different config files.
- Your token's permissions set the real limit, so scope it to the repositories the task needs.
Sources
- github/github-mcp-server, official repository: Docker image, toolsets, environment variables.
- GitHub Docs, "Use the GitHub MCP server".
- GitHub Docs, "Set up the GitHub MCP server": remote URL, OAuth and PAT configuration.
- Claude Code Docs, "Model Context Protocol (MCP)":
claude mcp add, transports, config scopes. - Cursor Docs, "Model Context Protocol":
.cursor/mcp.jsonshape.
Ready to try it?
Host any MCP server behind one endpoint and control exactly what your agents can reach.