# GitHub MCP

```json
{
  "name": "GitHub MCP",
  "slug": "github_mcp",
  "url": "https://composio.dev/toolkits/github_mcp",
  "markdown_url": "https://composio.dev/toolkits/github_mcp.md",
  "logo_url": "https://logos.composio.dev/api/github_mcp",
  "categories": [
    "developer tools & devops"
  ],
  "is_composio_managed": false,
  "updated_at": "2026-09-24T15:41:48.338Z"
}
```

![GitHub MCP logo](https://logos.composio.dev/api/github_mcp)

## Description

Securely connect your AI agents and chatbots (Claude, ChatGPT, Cursor, etc) with GitHub MCP or direct API to manage repositories, create and triage issues, create pull requests, and run Actions workflows through natural language.

## Summary

GitHub MCP is GitHub's managed API surface for repositories, issues, pull requests, users, actions, projects, and notifications.
Use it to let AI agents interact with your code and project data securely and at scale.

## Categories

- developer tools & devops

## Toolkit Details

- Tools: 44

## Images

- Logo: https://logos.composio.dev/api/github_mcp

## Authentication

- **Api Key**
  - Type: `api_key`
  - Description: Api Key authentication for GitHub MCP.
  - Setup:
    - Configure Api Key credentials for GitHub MCP.
    - Use the credentials when creating an auth config in Composio.

## Suggested Prompts

- List all open issues assigned to me
- Create pull request from my branch
- Merge pull request after CI passes

## Supported Tools

| Tool slug | Name | Description |
|---|---|---|
| `GITHUB_MCP_ADD_COMMENT_TO_PENDING_REVIEW` | Add comment to pending review | Add review comment to the requester's latest pending pull request review. A pending review needs to already exist to call this (check with the user if not sure). |
| `GITHUB_MCP_ADD_ISSUE_COMMENT` | Add issue comment | Add a comment and/or reaction to a specific issue or issue comment in a GitHub repository. Use this tool with pull requests as well (in this case pass pull request number as issue_number), but only if user is not asking specifically to add or react to review comments. At least one of body or reaction is required. |
| `GITHUB_MCP_ADD_REPLY_TO_PULL_REQUEST_COMMENT` | Add reply to pull request comment | Add a reply and/or reaction to an existing pull request comment. This can create a new comment linked as a reply to the specified comment, add an emoji reaction to the specified comment, or do both. At least one of body or reaction is required. |
| `GITHUB_MCP_CREATE_BRANCH` | Create branch | Create a new branch in a GitHub repository |
| `GITHUB_MCP_CREATE_OR_UPDATE_FILE` | Create or update file | Create or update a single file in a GitHub repository. If updating, you should provide the SHA of the file you want to update. Use this tool to create or update a file in a GitHub repository remotely; do not use it for local file operations. In order to obtain the SHA of original file version before updating, use the following git command: git rev-parse : SHA MUST be provided for existing file updates. |
| `GITHUB_MCP_CREATE_PULL_REQUEST` | Create pull request | Create a new pull request in a GitHub repository. |
| `GITHUB_MCP_CREATE_REPOSITORY` | Create repository | Create a new GitHub repository in your account or specified organization |
| `GITHUB_MCP_DELETE_FILE` | Delete file | Delete a file from a GitHub repository |
| `GITHUB_MCP_FORK_REPOSITORY` | Fork repository | Fork a GitHub repository to your account or specified organization |
| `GITHUB_MCP_GET_COMMIT` | Get commit | Get details for a commit from a GitHub repository |
| `GITHUB_MCP_GET_FILE_CONTENTS` | Get file contents | Get the contents of a file or directory from a GitHub repository |
| `GITHUB_MCP_GET_LABEL` | Get label | Get a specific label from a repository. |
| `GITHUB_MCP_GET_LATEST_RELEASE` | Get latest release | Get the latest release in a GitHub repository |
| `GITHUB_MCP_GET_ME` | Get me | Get details of the authenticated GitHub user. Use this when a request is about the user's own profile for GitHub. Or when information is missing to build other tool calls. |
| `GITHUB_MCP_GET_RELEASE_BY_TAG` | Get release by tag | Get a specific release by its tag name in a GitHub repository |
| `GITHUB_MCP_GET_TAG` | Get tag | Get details about a specific git tag in a GitHub repository |
| `GITHUB_MCP_GET_TEAM_MEMBERS` | Get team members | Get member usernames of a specific team in an organization. Limited to organizations accessible with current credentials |
| `GITHUB_MCP_GET_TEAMS` | Get teams | Get details of the teams the user is a member of. Limited to organizations accessible with current credentials |
| `GITHUB_MCP_ISSUE_READ` | Issue read | Get information about a specific issue in a GitHub repository. |
| `GITHUB_MCP_ISSUE_WRITE` | Issue write | Create a new or update an existing issue in a GitHub repository. |
| `GITHUB_MCP_LIST_BRANCHES` | List branches | List branches in a GitHub repository |
| `GITHUB_MCP_LIST_COMMITS` | List commits | Get list of commits of a branch in a GitHub repository. Returns at least 30 results per page by default, but can return more if specified using the perPage parameter (up to 100). |
| `GITHUB_MCP_LIST_ISSUE_FIELDS` | List issue fields | List issue fields for a repository or organization. Returns field definitions including name, type (text, number, date, single_select), and for single_select fields the list of valid option names. When repo is omitted, returns org-level fields directly. |
| `GITHUB_MCP_LIST_ISSUES` | List issues | List issues in a GitHub repository. For pagination, use the 'endCursor' from the previous response's 'pageInfo' in the 'after' parameter. |
| `GITHUB_MCP_LIST_ISSUE_TYPES` | List issue types | List supported issue types for a repository or its owner organization. When repo is omitted, returns org-level issue types directly. |
| `GITHUB_MCP_LIST_PULL_REQUESTS` | List pull requests | List pull requests in a GitHub repository. If the user specifies an author, then DO NOT use this tool and use the search_pull_requests tool instead. |
| `GITHUB_MCP_LIST_RELEASES` | List releases | List releases in a GitHub repository |
| `GITHUB_MCP_LIST_REPOSITORY_COLLABORATORS` | List repository collaborators | List collaborators of a GitHub repository. Results are paginated; the response includes `nextPage`, `prevPage`, `firstPage`, and `lastPage` fields. To get the next page, use the `nextPage` value as the `page` parameter. |
| `GITHUB_MCP_LIST_TAGS` | List tags | List git tags in a GitHub repository |
| `GITHUB_MCP_MERGE_PULL_REQUEST` | Merge pull request | Merge a pull request in a GitHub repository. |
| `GITHUB_MCP_PULL_REQUEST_READ` | Pull request read | Get information on a specific pull request in GitHub repository. |
| `GITHUB_MCP_PULL_REQUEST_REVIEW_WRITE` | Pull request review write | Create and/or submit, delete review of a pull request. Available methods: - create: Create a new review of a pull request. If "event" parameter is provided, the review is submitted. If "event" is omitted, a pending review is created. - submit_pending: Submit an existing pending review of a pull request. This requires that a pending review exists for the current user on the specified pull request. The "body" and "event" parameters are used when submitting the review. - delete_pending: Delete an existing pending review of a pull request. This requires that a pending review exists for the current user on the specified pull request. - resolve_thread: Resolve a review thread. Requires only "threadId" parameter with the thread's node ID (e.g., PRRT_kwDOxxx). The owner, repo, and pullNumber parameters are not used for this method. Resolving an already-resolved thread is a no-op. - unresolve_thread: Unresolve a previously resolved review thread. Requires only "threadId" parameter. The owner, repo, and pullNumber parameters are not used for this method. Unresolving an already-unresolved thread is a no-op. |
| `GITHUB_MCP_PUSH_FILES` | Push files | Push multiple files to a GitHub repository in a single commit |
| `GITHUB_MCP_REQUEST_COPILOT_REVIEW` | Request copilot review | Request a GitHub Copilot code review for a pull request. Use this for automated feedback on pull requests, usually before requesting a human reviewer. |
| `GITHUB_MCP_RUN_SECRET_SCANNING` | Run secret scanning | Scan files, content, or recent changes for secrets such as API keys, passwords, tokens, and credentials. This tool is intended for targeted scans of specific files, snippets, or diffs provided directly as content. The files parameter accepts either a single string or an array of strings containing raw file contents or diff hunks, and returns detected secrets with their locations and related secret scanning metadata. Content must not be empty. For full repository scanning, other mechanisms are available. Caveats: - Only files within the codebase should be scanned. Files outside of the codebase should not be sent. - Files listed in .gitignore should be skipped. |
| `GITHUB_MCP_SEARCH_CODE` | Search code | Fast and precise code search across ALL GitHub repositories using GitHub's native search engine. Best for finding exact symbols, functions, classes, or specific code patterns. |
| `GITHUB_MCP_SEARCH_COMMITS` | Search commits | Search for commits across GitHub repositories using GitHub's commit search syntax. Useful for finding specific changes, authors, or messages across one or many repositories. Searches the default branch only. |
| `GITHUB_MCP_SEARCH_ISSUES` | Search issues | Search issues using natural-language semantic matching. Best for conceptual or paraphrased queries (e.g. "login fails after password reset"). Already scoped to is:issue. |
| `GITHUB_MCP_SEARCH_PULL_REQUESTS` | Search pull requests | Search for pull requests in GitHub repositories using issues search syntax already scoped to is:pr |
| `GITHUB_MCP_SEARCH_REPOSITORIES` | Search repositories | Find GitHub repositories by name, description, readme, topics, or other metadata. Perfect for discovering projects, finding examples, or locating specific repositories across GitHub. |
| `GITHUB_MCP_SEARCH_USERS` | Search users | Find GitHub users by username, real name, or other profile information. Useful for locating developers, contributors, or team members. |
| `GITHUB_MCP_SUB_ISSUE_WRITE` | Sub issue write | Add a sub-issue to a parent issue in a GitHub repository. |
| `GITHUB_MCP_UPDATE_PULL_REQUEST` | Update pull request | Update an existing pull request in a GitHub repository. |
| `GITHUB_MCP_UPDATE_PULL_REQUEST_BRANCH` | Update pull request branch | Update the branch of a pull request with the latest changes from the base branch. |

## Supported Triggers

None listed.

## Installation and MCP Setup

### Path 1: SDK Installation

#### Path 1, Step 1: Install Composio

Install the Composio SDK, the OpenAI provider, and the OpenAI SDK
```python
pip install composio composio_openai openai
```

```typescript
npm install @composio/core @composio/openai openai
```

#### Path 1, Step 2: Create a Composio session

Initialize Composio with the OpenAI Responses provider and create a session scoped to GitHub MCP
```python
import json
from openai import OpenAI
from composio import Composio
from composio_openai import OpenAIResponsesProvider

composio = Composio(provider=OpenAIResponsesProvider())
client = OpenAI()

session = composio.create(user_id="your-user-id", toolkits=["github_mcp"])
tools = session.tools()
```

```typescript
import OpenAI from "openai";
import { Composio } from "@composio/core";
import { OpenAIResponsesProvider } from "@composio/openai";

const composio = new Composio({ provider: new OpenAIResponsesProvider() });
const client = new OpenAI();

const session = await composio.create("your-user-id", { toolkits: ["github_mcp"] });
const tools = await session.tools();
```

#### Path 1, Step 3: Run GitHub MCP tools with your agent

Send a request, execute the GitHub MCP tool calls through the session, and print the final answer
```python
response = client.responses.create(
    model="gpt-5.6-sol",
    tools=tools,
    input=[{"role": "user", "content": "List all open issues assigned to me"}],
)

while True:
    tool_calls = [o for o in response.output if o.type == "function_call"]
    if not tool_calls:
        break
    results = composio.provider.handle_tool_calls(response=response, session=session)
    response = client.responses.create(
        model="gpt-5.6-sol",
        tools=tools,
        previous_response_id=response.id,
        input=[
            {"type": "function_call_output", "call_id": call.call_id, "output": json.dumps(results[i])}
            for i, call in enumerate(tool_calls)
        ],
    )

print(response.output_text)
```

```typescript
let response = await client.responses.create({
  model: "gpt-5.6-sol",
  tools,
  input: [{ role: "user", content: "List all open issues assigned to me" }],
});

while (response.output.some((o) => o.type === "function_call")) {
  const outputs = await composio.provider.handleToolCalls(session, response.output);
  response = await client.responses.create({
    model: "gpt-5.6-sol",
    tools,
    previous_response_id: response.id,
    input: outputs,
  });
}

console.log(response.output_text);
```

### Path 2: MCP Server Setup

#### Path 2, Step 1: Install Composio

Install the Composio SDK and your agent framework
```python
pip install composio claude-agent-sdk
```

```typescript
npm install @composio/core ai @ai-sdk/mcp @ai-sdk/openai
```

#### Path 2, Step 2: Create a session with MCP enabled

Create a session scoped to GitHub MCP and read its MCP URL and headers
```python
from composio import Composio

composio = Composio()
session = composio.create(user_id="your-user-id", toolkits=["github_mcp"], mcp=True)
```

```typescript
import { Composio } from "@composio/core";

const composio = new Composio();
const { mcp } = await composio.create("your-user-id", {
  toolkits: ["github_mcp"],
  mcp: true,
});
```

#### Path 2, Step 3: Connect your agent to the MCP server

Pass the session's MCP URL and headers to your agent and run a GitHub MCP request
```python
import asyncio
from claude_agent_sdk import ClaudeSDKClient, ClaudeAgentOptions, AssistantMessage, TextBlock

options = ClaudeAgentOptions(
    mcp_servers={
        "composio": {
            "type": "http",
            "url": session.mcp.url,
            "headers": session.mcp.headers,
        }
    },
    system_prompt="You are a helpful assistant with access to GitHub MCP tools.",
    tools=[],
    allowed_tools=["mcp__composio__*"],
)

async def main():
    async with ClaudeSDKClient(options=options) as client:
        await client.query("List all open issues assigned to me")
        async for message in client.receive_response():
            if isinstance(message, AssistantMessage):
                for block in message.content:
                    if isinstance(block, TextBlock):
                        print(block.text)

asyncio.run(main())
```

```typescript
import { createMCPClient } from "@ai-sdk/mcp";
import { openai } from "@ai-sdk/openai";
import { generateText, stepCountIs } from "ai";

const client = await createMCPClient({
  transport: { type: "http", url: mcp.url, headers: mcp.headers },
});

const { text } = await generateText({
  model: openai("gpt-5.6-sol"),
  tools: await client.tools(),
  prompt: "List all open issues assigned to me",
  stopWhen: stepCountIs(10),
});

console.log(text);
await client.close();
```

## Why Use Composio?

### 1. AI Native GitHub MCP Integration

- Supports both GitHub MCP and direct API based integrations
- Structured, LLM-friendly schemas for reliable tool execution
- Rich coverage for reading, writing, and querying your GitHub MCP data

### 2. Managed Auth

- Built-in OAuth handling with automatic token refresh and rotation
- Central place to manage, scope, and revoke GitHub MCP access
- Per user and per environment credentials instead of hard-coded keys

### 3. Agent Optimized Design

- Tools are tuned using real error and success rates to improve reliability over time
- Comprehensive execution logs so you always know what ran, when, and on whose behalf

### 4. Enterprise Grade Security

- Fine-grained RBAC so you control which agents and users can access GitHub MCP
- Scoped, least privilege access to GitHub MCP resources
- Full audit trail of agent actions to support review and compliance

## Use GitHub MCP with any AI Agent Framework

Choose a framework you want to connect GitHub MCP with:

- [ChatGPT](https://composio.dev/toolkits/github_mcp/framework/chatgpt)
- [Claude Cowork](https://composio.dev/toolkits/github_mcp/framework/claude-cowork)
- [Hermes](https://composio.dev/toolkits/github_mcp/framework/hermes-agent)
- [Atomic Agent](https://composio.dev/toolkits/github_mcp/framework/atomic-agent)

## Related Toolkits

- [Supabase](https://composio.dev/toolkits/supabase) - Supabase is an open-source backend platform offering scalable Postgres databases, authentication, storage, and real-time APIs. It lets developers build modern apps without managing infrastructure.
- [Codeinterpreter](https://composio.dev/toolkits/codeinterpreter) - Codeinterpreter is a Python-based coding environment with built-in data analysis and visualization. It lets you instantly run scripts, plot results, and prototype solutions inside supported platforms.
- [GitHub](https://composio.dev/toolkits/github) - GitHub is a code hosting platform for version control and collaborative software development. It streamlines project management, code review, and team workflows in one place.
- [1password](https://composio.dev/toolkits/_1password) - 1Password is a password manager and digital vault for storing logins, secrets, notes, and secure documents. It helps individuals and teams protect credentials, share access safely, and reduce password risk.
- [Ably](https://composio.dev/toolkits/ably) - Ably is a real-time messaging platform for live chat and data sync in modern apps. It offers global scale and rock-solid reliability for seamless, instant experiences.
- [Abuselpdb](https://composio.dev/toolkits/abuselpdb) - Abuselpdb is a central database for reporting and checking IPs linked to malicious online activity. Use it to quickly identify and report suspicious or abusive IP addresses.
- [Alchemy](https://composio.dev/toolkits/alchemy) - Alchemy is a blockchain development platform offering APIs and tools for Ethereum apps. It simplifies building and scaling Web3 projects with robust infrastructure.
- [Algolia](https://composio.dev/toolkits/algolia) - Algolia is a hosted search API that powers lightning-fast, relevant search experiences for web and mobile apps. It helps developers deliver instant, typo-tolerant, and scalable search without complex infrastructure.
- [Anchor browser](https://composio.dev/toolkits/anchor_browser) - Anchor browser is a developer platform for AI-powered web automation. It transforms complex browser actions into easy API endpoints for streamlined web interaction.
- [Apiflash](https://composio.dev/toolkits/apiflash) - Apiflash is a website screenshot API for programmatically capturing web pages. It delivers high-quality screenshots on demand for automation, monitoring, or reporting.
- [Apiverve](https://composio.dev/toolkits/apiverve) - Apiverve delivers a suite of powerful APIs that simplify integration for developers. It's designed for reliability and scalability so you can build faster, smarter applications without the integration headache.
- [Appcircle](https://composio.dev/toolkits/appcircle) - Appcircle is an enterprise-grade mobile CI/CD platform for building, testing, and publishing mobile apps. It streamlines mobile DevOps so teams ship faster and with more confidence.
- [Appdrag](https://composio.dev/toolkits/appdrag) - Appdrag is a cloud platform for building websites, APIs, and databases with drag-and-drop tools and code editing. It accelerates development and iteration by combining hosting, database management, and low-code features in one place.
- [Appveyor](https://composio.dev/toolkits/appveyor) - AppVeyor is a cloud-based continuous integration service for building, testing, and deploying applications. It helps developers automate and streamline their software delivery pipelines.
- [Authyo](https://composio.dev/toolkits/authyo) - Authyo is a REST API service for passwordless authentication, OTP verification, session management, and transactional notifications. Use it to add secure login flows and user verification without building auth infrastructure from scratch.
- [AWS Marketplace MCP](https://composio.dev/toolkits/aws_marketplace_mcp) - AWS Marketplace MCP provides MCP access to AWS Marketplace's cloud software, data, and services catalog. Use it to discover, compare, and evaluate 30K+ AWS Marketplace listings faster.
- [Azure Monitor Activity Log](https://composio.dev/toolkits/azure_monitor_activity_log) - Azure Monitor Activity Log is Azure's service that records management and control-plane events for a subscription. Use it to audit changes, troubleshoot issues, and track resource operations across your Azure resources.
- [Backendless](https://composio.dev/toolkits/backendless) - Backendless is a backend-as-a-service platform for mobile and web apps, offering database, file storage, user authentication, and APIs. It helps developers ship scalable applications faster without managing server infrastructure.
- [Baserow](https://composio.dev/toolkits/baserow) - Baserow is an open-source no-code database platform for building collaborative data apps. It makes it easy for teams to organize data and automate workflows without writing code.
- [Bench](https://composio.dev/toolkits/bench) - Bench is a benchmarking tool for automated performance measurement and analysis. It helps you quickly evaluate, compare, and track your systems or workflows.

## Frequently Asked Questions

### Do I need my own developer credentials to use GitHub MCP with Composio?

Yes, GitHub MCP requires you to configure your own API key credentials. Once set up, Composio handles secure credential storage and API request handling for you.

### Can I use multiple toolkits together?

Yes! Composio's Tool Router enables agents to use multiple toolkits. [Learn more](https://docs.composio.dev/tool-router/overview).

### Is Composio secure?

Composio is SOC 2 and ISO 27001 compliant with all data encrypted in transit and at rest. [Learn more](https://trust.composio.dev).

### What if the API changes?

Composio maintains and updates all toolkit integrations automatically, so your agents always work with the latest API versions.

---
[See all toolkits](https://composio.dev/toolkits) · [Composio docs](https://docs.composio.dev/llms.txt)
