GitHub MCP server
Last verified: 2026-09
Repos, issues, PRs, and file contents on GitHub.
Official reference Developer tools Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code, VS Code
What it does
The original npm GitHub server: repos, issues, PRs, file contents, search. A classic PAT with repo scope can push code. For new installs, GitHub's own Go server (github-official) is the one GitHub maintains.
It sits in Developer tools: Split this category in two.
Good for
- List issues or PRs on one repo with a fine-grained PAT.
- Read a file from a repo you do not have cloned.
- Open a draft PR only after you have seen read tools work.
- Search code you do not want to clone just to grep.
Tools
- get_file_contents / create_or_update_file / push_files — Read and write repo files.
- create_issue / update_issue / add_issue_comment / list_issues — Issues.
- create_pull_request / create_branch / list_commits / fork_repository — PRs and history.
- search_repositories / search_code / search_issues / search_users — Search.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"github": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-github"
],
"env": {
"GITHUB_PERSONAL_ACCESS_TOKEN": "github_pat_..."
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y @modelcontextprotocol/server-github
Secrets it wants: GITHUB_PERSONAL_ACCESS_TOKEN
How to get started
- Create a fine-grained PAT: contents read (and write only if you want edits), issues, pull requests, on one repo.
- Put GITHUB_PERSONAL_ACCESS_TOKEN in env. Restart.
- Ask it to list issues on that repo before you let it open a PR.
Access risk
repo scope on a classic PAT is push access to every repo the account can write. Prefer fine-grained, one repo, no delete.
When to skip it
Skip the npm server if you can use GitHub official. Skip both if you only need local git (Git MCP) and no GitHub API.
Instead: GitHub official, Git, GitLab.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| GitHub | Yes | Yes | Repos, issues, PRs, and file contents on GitHub. |
| GitHub official | No | Yes | GitHub's own MCP server (Go), remote or local. |
| Git | Yes | No | Read a local git repo: log, diff, status. |
| GitLab | Yes | Yes | Projects, issues, and merge requests on GitLab. |
More in Developer tools
FAQ
npm GitHub or GitHub official?
For new setups, GitHub's Go server (github-official on this site). This npm @modelcontextprotocol/server-github is the older reference.
Which token?
Fine-grained PAT on one repo, read-only. Classic tokens with repo scope are too wide.
Git or GitHub?
Git for log/diff/status on disk. GitHub for issues, PRs, and other repos.
Can it push?
If the token can. Start without write.