Skip to content
anavem.com

MCP server

GitHub MCP Server

Official GitHub server that lets MCP clients inspect repositories, issues, pull requests, actions, security alerts and other enabled GitHub resources.

Maintainer
GitHub, Inc.
Licence
MIT
Last release
GitHub latest release: v1.14.0 (checked 2026-10-04)
Last verified Jump to what it can access ↓

GitHub MCP Server is GitHub’s official bridge between MCP clients and GitHub APIs. It can expose read and write operations across repositories and collaboration features, so its real authority is determined by both the enabled toolsets and the GitHub token or OAuth session.

Key takeaways

  • Official server maintained by GitHub.
  • Toolsets can narrow the exposed product areas.
  • Repository and organization permissions still come from the authenticated GitHub identity.

What is GitHub MCP Server?

Official GitHub server that lets MCP clients inspect repositories, issues, pull requests, actions, security alerts and other enabled GitHub resources. MCP standardizes how a compatible client discovers and invokes tools, but it does not make those tools safe automatically. The client, server, credentials and upstream service remain separate trust boundaries.

What tools does it expose?

  • Search and inspect repositories, code, commits and branches.
  • Work with issues, pull requests, reviews and discussions.
  • Inspect Actions, Dependabot and security information when authorized.
  • Create or modify GitHub resources through enabled write tools.

The exact catalog can change by release, account, enabled feature or server configuration. Inspect the live tool list and JSON schemas before enabling it. A descriptive tool name is not an authorization control, and a read-sounding operation can still reveal sensitive metadata.

What is a safe first test?

Connect a read-only token to one disposable repository and ask for open issues plus the latest workflow status. Do not enable push, merge, issue creation or repository administration during the first test.

Use a test account or project, allow only the required tools and record the client configuration, server version and arguments. Verify the result directly in the upstream service. Add write tools only after read-only behavior, authentication expiry, error handling and audit logs have been reviewed.

What data and credentials can it access?

The server can access GitHub data available to the authenticated account and token scopes, including private repository content when granted. Write tools can change repositories and collaboration records.

Credentials should be supplied through the documented OAuth flow, a secret manager or a restricted environment variable, never pasted into prompts or committed to source. The upstream account should expose only the resources required for the pilot.

Which permissions should you grant?

  • A fine-grained token or OAuth grant limited to selected repositories.
  • Read-only metadata and contents permissions for the initial pilot.
  • Additional issue, pull-request, workflow or administration scopes only for a proven need.

Prefer project-scoped, read-only or restricted tokens. Where the server offers tool filters, combine them with upstream authorization rather than treating filtering as the only control. Separate development and production identities and rotate test credentials after the evaluation.

What should a security review cover?

  • Restrict toolsets as well as token scopes.
  • Protect private code and secret scanning results from model logs.
  • Require review before merges, pushes or permission changes.

Assume tool results can contain prompt injection or hostile content. Keep approval gates in application code for financial, administrative, destructive or public actions. Apply network restrictions, timeouts, output-size limits and audit logging at the host or gateway layer.

What are the main limitations?

  • Available tools vary by version and configuration.
  • GitHub API rate limits and enterprise policy apply.
  • A broad token can expose many private repositories even if the prompt mentions only one.

This is a documentation-based profile checked on 2026-10-04; Anavem did not connect the server or test it against a live account. Tool catalogs, transport support, pricing, licensing and authentication methods can change. Verify the current first-party documentation before installation.

What it can access

An MCP server gives an AI application a set of capabilities, and it can do only what its code and the credentials you give it allow. This is what the listing states, based on the sources below. Anavem does not rate it safe or unsafe: check it against what you plan to use it for.

Permissions it asks for

  • A fine-grained token or OAuth grant limited to selected repositories.
  • Read-only metadata and contents permissions for the initial pilot.
  • Additional issue, pull-request, workflow or administration scopes only for a proven need.

Data it can reach

The server can access GitHub data available to the authenticated account and token scopes, including private repository content when granted. Write tools can change repositories and collaboration records.

How it is installed or connected

Use the official remote or local setup documented in the repository and authenticate with the narrowest supported GitHub identity.

After connecting, enumerate the tools from the MCP client and disable everything outside the pilot. Test with non-production data, confirm how credentials are stored, and keep a documented removal or revocation procedure.

Limitations

  • Available tools vary by version and configuration.
  • GitHub API rate limits and enterprise policy apply.
  • A broad token can expose many private repositories even if the prompt mentions only one.
  • Anavem reviewed public documentation but did not connect, authorize or benchmark this server.

Not sure what to look for? Read what to check before installing.

Quick answers

Who maintains this MCP server?
GitHub, Inc.
What can it access?
It asks for: A fine-grained token or OAuth grant limited to selected repositories., Read-only metadata and contents permissions for the initial pilot., Additional issue, pull-request, workflow or administration scopes only for a proven need.. The server can access GitHub data available to the authenticated account and token scopes, including private repository content when granted. Write tools can change repositories and collaboration records. We do not label anything safe or unsafe; read the official sources before you install.
What licence does it use?
MIT. Check the terms if you plan to use it commercially.
What are its limitations?
Available tools vary by version and configuration. GitHub API rate limits and enterprise policy apply. A broad token can expose many private repositories even if the prompt mentions only one. Anavem reviewed public documentation but did not connect, authorize or benchmark this server.
When was it last released?
GitHub latest release: v1.14.0 (checked 2026-10-04). Verified Oct 4, 2026.

Sources

Other listings in the same category.

All MCP servers →

AI tools in AI Coding & App Builders

Verified tool profiles in the same category.

See category →