GitHub github
Work with GitHub repositories, issues, pull requests, Actions and code search, using a personal access token you supply as a named secret.
- Homepage
- https://github.com/github/github-mcp-server
- License
- MIT
- Runtime
native, transportstdio- Categories
- developer-tools
Versions
| Version | Published | Runtime | Blobs |
|---|---|---|---|
| 1.12.2 | 2026-10-06T14:04:59Z | native |
linux/amd64
148d7be0373c272e7f00b316e5b9fd51ec092c9c53d495a439ef0d95070ebd15 8.2 MiB
curl -fsSLO https://library.pellum.ai/blobs/sha256/148d7be0373c272e7f00b316e5b9fd51ec092c9c53d495a439ef0d95070ebd15 |
Parameters
| Name | Type | Environment | Required | Secret | Description |
|---|---|---|---|---|---|
personal_access_token | string | GITHUB_PERSONAL_ACCESS_TOKEN | yes | yes | A GitHub personal access token; its scopes bound what the tools can do. |
toolsets | string | GITHUB_TOOLSETS | no | no | Comma-separated toolsets to enable, for example repos,issues,pull_requests. Unset means the server's defaults. |
read_only | bool | GITHUB_READ_ONLY | no | no | Register only read tools. |
Credentials
The server verifies no caller token. The executor's sandbox and listener are the controls on who may call it.
Egress
| Destination | Port | Reason |
|---|---|---|
api.github.com | default web ports | the GitHub REST and GraphQL API every tool calls |
raw.githubusercontent.com | default web ports | file contents for the file-reading tools |
A host of the form ${param.host} is the host of a URL the operator supplies, resolved by the gateway at claim time. The library never knows it.
Resource defaults
memory.max 256Mi, pids.max 128, cpu.max 100000 100000.
Verify a download
Against the library key, which is what a gateway checks:
curl -fsSLO https://library.pellum.ai/blobs/sha256/148d7be0373c272e7f00b316e5b9fd51ec092c9c53d495a439ef0d95070ebd15 curl -fsSLO https://library.pellum.ai/blobs/sha256/148d7be0373c272e7f00b316e5b9fd51ec092c9c53d495a439ef0d95070ebd15.sig curl -fsSLO https://library.pellum.ai/keys/library-v1.pub echo "148d7be0373c272e7f00b316e5b9fd51ec092c9c53d495a439ef0d95070ebd15 148d7be0373c272e7f00b316e5b9fd51ec092c9c53d495a439ef0d95070ebd15" | sha256sum -c - cosign verify-blob --insecure-ignore-tlog --key library-v1.pub --signature 148d7be0373c272e7f00b316e5b9fd51ec092c9c53d495a439ef0d95070ebd15.sig 148d7be0373c272e7f00b316e5b9fd51ec092c9c53d495a439ef0d95070ebd15