GitHub MCP server: remote or local setup, toolsets, and safe defaults

How to set up GitHub's official MCP server (github/github-mcp-server) in Claude Code, Cursor and VS Code: the remote endpoint at api.githubcopilot.com, the local Docker image, OAuth vs PAT, toolsets, read-only and lockdown mode, GitHub Enterprise, and the prompt injection risk in issue text.

Walma Engineering·Updated 5 October 2026·7 min read

The GitHub MCP server gives an agent direct access to your repositories, issues, pull requests, Actions runs and security alerts. In Claude Code, Cursor or VS Code that turns "go read issue 412, find the code it refers to and open a PR" into a single request. This guide covers GitHub's official server, which deployment to pick, how to scope it down, and the one security problem every team should understand before turning it on. For general client setup, see the guides for Claude Code and Cursor.

Which GitHub MCP server

GitHub maintains the server at github/github-mcp-server. It ships in two forms:

RemoteLocal
Where it runsHosted by GitHubYour machine, via Docker or a Go binary
Endpointhttps://api.githubcopilot.com/mcp/ghcr.io/github/github-mcp-server
AuthOAuth (default) or a PAT in a headerPAT in GITHUB_PERSONAL_ACCESS_TOKEN, or OAuth via a local callback port
GitHub Enterprise ServerNot supportedSupported with GITHUB_HOST
ConfigurationURL paths and X-MCP-* headersFlags and environment variables

If you find older tutorials using @modelcontextprotocol/server-github from npm, skip them. GitHub's docs say that package has not been supported since April 2025.

On cost: GitHub states the server is available to all GitHub users regardless of plan. Tools inherit the access rules of the feature they wrap, so a code scanning tool only works where code scanning is enabled. For Copilot Business and Enterprise members, an admin must enable the "MCP servers in Copilot" policy before Copilot can use it, and when that policy is disabled it blocks both the remote and local server in the editors it covers.

Setup in Claude Code

GitHub's own install guide for Claude Code (version 2.1.1 and newer) adds the remote server with a personal access token:

claude mcp add-json github '{"type":"http","url":"https://api.githubcopilot.com/mcp","headers":{"Authorization":"Bearer YOUR_GITHUB_PAT"}}'

For the local server, either pass a token:

claude mcp add github -e GITHUB_PERSONAL_ACCESS_TOKEN=$GITHUB_PAT -- docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server

or let the container run an OAuth login in your browser on first use, with the token held in memory only:

claude mcp add github -e GITHUB_OAUTH_CALLBACK_PORT=8085 -- docker run -i --rm -p 127.0.0.1:8085:8085 -e GITHUB_OAUTH_CALLBACK_PORT ghcr.io/github/github-mcp-server

Keep the token in an environment variable rather than pasting it into a shared .mcp.json. GitHub's guide also notes that Claude Desktop cannot currently use the remote server, because it requires OAuth through a registered GitHub App, so Desktop users run the Docker image instead.

Setup in Cursor

Cursor reads ~/.cursor/mcp.json (or a project .cursor/mcp.json). The remote server needs Cursor 0.48.0 or newer for Streamable HTTP:

{
  "mcpServers": {
    "github": {
      "url": "https://api.githubcopilot.com/mcp/",
      "headers": {
        "Authorization": "Bearer YOUR_GITHUB_PAT"
      }
    }
  }
}

The local Docker variant uses "command": "docker" with the same arguments as the Claude Code example above, and either GITHUB_PERSONAL_ACCESS_TOKEN or GITHUB_OAUTH_CALLBACK_PORT in env.

Setup in VS Code

VS Code (1.101 or newer) is the smoothest path, because the remote server's one-click OAuth works there without a token. Add it to your MCP config:

{
  "servers": {
    "github": {
      "type": "http",
      "url": "https://api.githubcopilot.com/mcp/"
    }
  }
}

Start the server, sign in when prompted, and switch Copilot Chat to Agent mode. The README also has one-click install buttons for both the remote and the local server. If you are still choosing an editor, our Cursor vs Claude Code comparison covers how they differ.

Toolsets: load only what the task needs

The server groups its tools into toolsets. With no configuration it enables five: context (including get_me, your own profile), repos, issues, pull_requests and users. Others include actions, code_security, dependabot, secret_protection, discussions, gists, notifications, orgs, projects and labels. The remote server adds two of its own: copilot_spaces and github_support_docs_search. The value all turns on everything.

Fewer toolsets is better for two reasons: the model chooses tools more reliably from a short list, and every tool you leave out is one an injected instruction cannot use.

Remote configuration lives in the URL or in headers:

  • https://api.githubcopilot.com/mcp/x/issues enables only the issues toolset.
  • X-MCP-Toolsets: repos,issues,pull_requests picks several.
  • X-MCP-Tools and X-MCP-Exclude-Tools add or remove single tools.

Local configuration uses flags or environment variables:

docker run -i --rm \
  -e GITHUB_PERSONAL_ACCESS_TOKEN \
  -e GITHUB_TOOLSETS="repos,issues,pull_requests,actions" \
  -e GITHUB_READ_ONLY=true \
  ghcr.io/github/github-mcp-server

The equivalent flags are --toolsets, --tools, --exclude-tools and --read-only. Excluded tools always win, even if their toolset is enabled. Tool names must match exactly in snake_case (list_issues, pull_request_read, create_pull_request, get_file_contents, search_code), and an invalid name stops the server from starting.

Read-only and lockdown mode

Read-only mode removes every write tool. GitHub describes it as a strict filter that overrides any other configuration, so a write tool stays off even if a toolset or tool list asks for it. Use /readonly on the remote URL (combinable, as in /x/issues/readonly), the X-MCP-Readonly header, or --read-only / GITHUB_READ_ONLY locally. It is the right default for code review assistants, triage and reporting.

Lockdown mode (X-MCP-Lockdown remotely, --lockdown-mode / GITHUB_LOCKDOWN_MODE locally) hides content in public repositories created by users without push access. That is aimed squarely at the attack described below.

GitHub Enterprise

For GitHub Enterprise Server, run the local server and set GITHUB_HOST (or --gh-host) to your hostname with https://. Non-HTTPS hosts are refused. The remote server does not support GHES.

For GitHub Enterprise Cloud with data residency, set GITHUB_HOST=https://YOURSUBDOMAIN.ghe.com on the local server, or use the remote endpoint https://copilot-api.YOURSUBDOMAIN.ghe.com/mcp.

Org controls still apply. OAuth connections to the remote server are governed by your OAuth App access policies, tokens by your PAT policies, and SSO enforcement sits on top of both. Enterprise Managed Users have PATs disabled by default unless an admin enables them.

Security: tokens and untrusted issue text

Token scope. OAuth on the remote server limits access to the scopes you approve at sign-in. A PAT gives the server whatever the token can do. GitHub's README advises minimum scopes, separate tokens per project or environment, regular rotation and never committing tokens. A classic token with full repo scope across every repository you can reach is the worst case: the agent can touch all of them.

Prompt injection from issues and PRs. This is the risk that makes GitHub different from most MCP servers. Issues, PR descriptions, comments and READMEs in public repositories are written by anyone. In May 2025 Invariant Labs showed how a malicious issue in a public repo could hijack an agent asked something harmless like "look at the open issues", pull data from the user's private repositories into context and leak it through a pull request in the public repo. The tools were not compromised. The agent simply followed instructions it read.

The controls that address it:

  • Read-only by default. An agent that cannot create PRs or comments cannot exfiltrate through GitHub.
  • Lockdown mode for any agent that reads public repositories.
  • One repository scope per session. Do not let an agent that reads untrusted public content also hold write access to private repos.
  • Human approval on writes. Auto-allow reads, require a click for create_pull_request, merge_pull_request, issue_write and anything in actions.
  • Narrow toolsets and tokens, as above.

These are the general rules from MCP security best practices applied to one server.

Running it for a team

On one laptop, the settings above are enough. Across a team they drift: one developer runs with all toolsets and a broad classic token, another has read-only on, nobody can tell which agent opened which PR. That is the problem an MCP gateway solves, with one place to decide which toolsets, which modes and which tokens are allowed, and one log of every tool call.

Walma AI Hub runs GitHub alongside the other approved servers behind that kind of shared policy, inside the customer's own Azure tenant in an EU region, with every model your developers use on the same gateway. If you are weighing GitHub against the other servers worth connecting, start with our list of the best MCP servers, or see how the hub works.

Frequently asked questions

Is there an official GitHub MCP server?+

Yes. GitHub maintains github/github-mcp-server. It runs as a hosted remote server at https://api.githubcopilot.com/mcp/ or locally from the Docker image ghcr.io/github/github-mcp-server. The older npm package @modelcontextprotocol/server-github is no longer supported.

Do I need a Copilot subscription to use the GitHub MCP server?+

No. GitHub's docs say the server is available to all GitHub users regardless of plan type. Individual tools inherit the requirements of the feature they touch, so tools for paid features need the paid plan. In organizations on Copilot Business or Enterprise, the 'MCP servers in Copilot' policy must be enabled to use it with Copilot.

How do I add the GitHub MCP server to Claude Code?+

GitHub's install guide uses claude mcp add-json github with an HTTP config pointing at https://api.githubcopilot.com/mcp and an Authorization: Bearer header carrying a personal access token. For the local server, run the Docker image through claude mcp add github -- docker run ...

How do I make the GitHub MCP server read-only?+

On the remote server, use the /readonly URL path (for example https://api.githubcopilot.com/mcp/readonly) or the X-MCP-Readonly header. Locally, pass --read-only or set GITHUB_READ_ONLY. Read-only mode removes write tools even if a toolset or tool list asks for them.

Does the GitHub MCP server work with GitHub Enterprise Server?+

Only the local server. Set GITHUB_HOST (or --gh-host) to your GHES hostname with https://. The remote server does not support GHES. GitHub Enterprise Cloud with data residency (ghe.com) can use the local server with GITHUB_HOST, or the remote endpoint at https://copilot-api.YOURSUBDOMAIN.ghe.com/mcp.

Walma AI Hub

The same tools, in your EU region, under your control

A 20-minute walkthrough with an engineer. We map it to your tools, your MCP servers and your budget model.

About AI Hub