GitLab MCP server
Last verified: 2026-09
Projects, issues, and merge requests on GitLab.
Official reference Developer tools Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code, VS Code
What it does
GitLab's counterpart to the GitHub server: projects, issues, merge requests, on gitlab.com or a self-hosted instance.
It sits in Developer tools: Split this category in two.
Good for
- List projects the PAT can see on gitlab.com or self-hosted.
- Read issues and merge requests without opening the UI.
- Open an MR only with write_repository on a bot user.
- Point GITLAB_API_URL at your instance, not gitlab.com, if you are self-hosted.
Tools
- project / issue / merge request tools — Create and inspect MRs and issues. Exact names follow the GitLab API.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"gitlab": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-gitlab"
],
"env": {
"GITLAB_PERSONAL_ACCESS_TOKEN": "glpat-...",
"GITLAB_API_URL": "https://gitlab.com/api/v4"
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y @modelcontextprotocol/server-gitlab
Secrets it wants: GITLAB_PERSONAL_ACCESS_TOKEN, GITLAB_API_URL
How to get started
- Create a PAT with read_api (add write_repository only if you want pushes).
- Set GITLAB_PERSONAL_ACCESS_TOKEN and GITLAB_API_URL (https://gitlab.com/api/v4 or your host).
- Restart and ask it to list projects the token can see.
Access risk
A self-hosted token can see internal projects. Scope it to a group.
When to skip it
Skip it if the code is on GitHub or only on disk (Git).
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| GitLab | Yes | Yes | Projects, issues, and merge requests on GitLab. |
| GitHub | Yes | Yes | Repos, issues, PRs, and file contents on GitHub. |
| Git | Yes | No | Read a local git repo: log, diff, status. |
More in Developer tools
FAQ
Self-hosted?
Set GITLAB_API_URL to https://your.host/api/v4. A self-hosted token can see internal projects — scope it to a group.
GitLab or GitHub?
Match the forge you use. Do not install both write tokens.
Which token scopes?
read_api to start. write_repository only if you want pushes/MRs.
Official?
Anthropic reference server, not GitLab Inc.'s product.