GitHub MCP

Live

OAUTH 2.1

DEVELOPER TOOLS

Developer Tools

Every repository, issue, pull request, and file your coding agent needs to manage lives in GitHub MCP. GitHub MCP gives your agent OAuth 2.1 access to GitHub with fine-grained per-user permissions and full auditability.

  • Acts as the user: Repository access and write actions stay tied to the GitHub account that authorized the agent.
  • Credentials stay vaulted: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: User permissions enforced. 90-day audit trail.
GitHub MCP
agent · Acme Q3
Run
List all open PRs in the main repo waiting for review more than 2 days and summarize their changes.
S
github_mcp_pr_get
87ms
Engineering agent
4 PRs waiting 2+ days: #412 (auth refactor, 3d, +240/-180), #408 (rate limit fix, 2d 6h, +45/-12), #401 (webhook handler, 4d, +320/-0), #397 (cache layer, 5d, +180/-90).
Sources: GitHub MCP, open PRs
githubmcp
4
18:29
Message Claude...

Tools your agent reaches for on GitHub MCP, scoped per user.

CALL ANY TOOL
Manage repos, issues, pull requests, branches, and files via GitHub MCP's OAuth 2.1 interface. Same toolkit, every framework, no auth plumbing.
githubmcp_add_comment_to_pending_review
Add Comment To Pending Review
Add a review comment to the requester's latest pending pull request review.
Parameters
Name
Type
Required
Description
body
string
Required
The text content of the comment, review, or description.
owner
string
Required
The GitHub repository owner (username or organization name).
path
string
Required
The file path within the repository.
pullNumber
number
Required
The pull request number.
repo
string
Required
The GitHub repository name.
subjectType
string
Required
The subject type for the review comment: line or file.
line
number
Optional
The line number in the file the comment applies to.
side
string
Optional
The side of the diff the comment applies to: LEFT or RIGHT.
startLine
number
Optional
The first line of a multi-line comment range.
startSide
string
Optional
The side of the diff for the start of a multi-line comment: LEFT or RIGHT.
githubmcp_add_issue_comment
Add Issue Comment
githubmcp_add_reply_to_pull_request_comment
Add Reply To Pull Request Comment
githubmcp_create_branch
Create Branch
githubmcp_create_or_update_file
Create Or Update File
githubmcp_create_pull_request
Create Pull Request
githubmcp_create_repository
Create Repository
githubmcp_delete_file
Delete File
githubmcp_fork_repository
Fork Repository
githubmcp_get_commit
Get Commit
githubmcp_get_file_contents
Get File Contents
githubmcp_get_label
Get Label
githubmcp_get_latest_release
Get Latest Release
githubmcp_get_me
Get Me
githubmcp_get_release_by_tag
Get Release By Tag
githubmcp_get_tag
Get Tag
githubmcp_get_team_members
Get Team Members
githubmcp_get_teams
Get Teams
githubmcp_issue_read
Read issue
githubmcp_issue_write
Write issue
githubmcp_list_branches
List Branches
githubmcp_list_commits
List Commits
githubmcp_list_issue_types
List Issue Types
githubmcp_list_issues
List Issues
githubmcp_list_pull_requests
List Pull Requests
githubmcp_list_releases
List Releases
githubmcp_list_repository_collaborators
List Repository Collaborators
githubmcp_list_tags
List Tags
githubmcp_merge_pull_request
Merge Pull Request
githubmcp_pull_request_read
Read pull request

For more tools, view docs.

Build your Agent
Drop the toolkit in, point it at the user, and your agent can manage GitHub repos, issues, and PRs via GitHub MCP from the first run.
Python · LlamaIndex
import { ScalekitClient } from "@scalekit-sdk/node";
import { DynamicStructuredTool } from "@langchain/core/tools";
import { createReactAgent } from "@langchain/langgraph/prebuilt";
import { z } from "zod";

const sk = new ScalekitClient(envUrl, clientId, clientSecret);

const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["githubmcp"], toolNames: ["github_mcp_repos_list", "github_mcp_issue_create", "github_mcp_pr_get"] },
pageSize: 100,
});

const lcTools = tools.map((t) => new DynamicStructuredTool({
name: t.tool.definition.name,
description: t.tool.definition.description,
schema: z.object({}).passthrough(),
func: async (args) => {
const { data } = await sk.tools.executeTool({
toolName: t.tool.definition.name,
identifier: "user_123",
params: args,
});
return JSON.stringify(data);
},
}));

const agent = createReactAgent({ llm, tools: lcTools });
import { ScalekitClient } from "@scalekit-sdk/node";
import OpenAI from "openai";

const sk = new ScalekitClient(envUrl, clientId, clientSecret);
const openai = new OpenAI();

const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["githubmcp"], toolNames: ["github_mcp_repos_list", "github_mcp_issue_create", "github_mcp_pr_get"] },
pageSize: 100,
});

const llmTools = tools.map((t) => ({
type: "function",
function: {
name: t.tool.definition.name,
description: t.tool.definition.description,
parameters: t.tool.definition.input_schema,
},
}));

const resp = await openai.responses.create({
model: "gpt-4o", input: prompt, tools: llmTools,
});
import { ScalekitClient } from "@scalekit-sdk/node";
import Anthropic from "@anthropic-ai/sdk";

const sk = new ScalekitClient(envUrl, clientId, clientSecret);
const anthropic = new Anthropic();

const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["githubmcp"], toolNames: ["github_mcp_repos_list", "github_mcp_issue_create", "github_mcp_pr_get"] },
pageSize: 100,
});

const llmTools = tools.map((t) => ({
name: t.tool.definition.name,
description: t.tool.definition.description,
input_schema: t.tool.definition.input_schema,
}));

const msg = await anthropic.messages.create({
model: "claude-sonnet-4-6", max_tokens: 1024,
tools: llmTools,
messages: [{ role: "user", content: prompt }],
});
import { Agent } from "@google/adk/agents";
import {
MCPToolset, StreamableHTTPConnectionParams,
} from "@google/adk/tools/mcp";

const toolset = new MCPToolset({
connectionParams: new StreamableHTTPConnectionParams({
url: "https://mcp.scalekit.com/githubmcp",
headers: { Authorization: `Bearer ${userScopedToken}` },
}),
});

const agent = new Agent({
name: "agent", model: "gemini-2.0-flash",
tools: await toolset.getTools(),
});
Try these prompts
Paste any prompt into your engineering agent to start managing GitHub workflows via GitHub MCP.
Search & recall
Copy the prompt
Copied
List all open PRs in [repo] waiting for review more than [N] days.
Copy the prompt
Copied
Get the content of [file path] from the [branch] branch.
Copy the prompt
Copied
List all open issues labeled [bug] in [repo].
Action & create
Copy the prompt
Copied
Create an issue in [repo]: [title] with labels [labels].
Copy the prompt
Copied
Create a new branch [branch name] from main in [repo].
Copy the prompt
Copied
Get the full diff and review status for PR #[number] in [repo].
SEE HOW AUTH WORKS
Users authorize GitHub MCP once. Their GitHub credentials stay vaulted, every repository action runs under their permissions, and every call is logged.
1
Authorize
Your user connects
GitHub MCP
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
GitHub MCP
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
GitHub MCP
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
GitHub MCP
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
Same per-user auth pattern across other developer tool and collaboration connectors.
ENGINEERING
DevOps assistant agent
Triage GitHub incidents, open Linear tickets, and notify the on-call channel in Slack with context already attached.
ENGINEERING
Auto-release notes agent
Group merged GitHub PRs by feature, fix, or chore and publish release notes per tag. No manual changelog grooming.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
Other connector libraries treat auth as a demo afterthought. Scalekit starts with user identity, scope enforcement, and audit.
01.
Shared tokens break per-user analytics
A shared token looks fine in a demo. In production every call looks like a service account. Scalekit resolves the real user credential so attribution, audit, and scope stay accurate.
// shared token
 audit → bot_service_account
 user_filter → broken

 // scalekit
 audit → user_abc
 scope → enforced ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
GitHub MCP today. Others tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions
How does GitHub MCP differ from the standard GitHub connector?
GitHub MCP uses OAuth 2.1 with dynamic client registration — the same protocol as Scalekit's MCP auth stack — giving finer-grained token scoping and DCR-compatible tooling.
Does the agent access GitHub as the user or a shared token?
As the user. Each developer authorizes once and Scalekit resolves their credential. All commits, issues, and PRs are attributed to that user.
Where is the GitHub OAuth token stored?
In Scalekit's AES-256 vault, namespaced per tenant. Tokens never appear in prompts or LLM context.
Can I restrict the agent to read-only repository access?
Yes. Use listScopedTools to allow file reads and issue listing without granting branch creation or PR management.
What happens when a developer revokes GitHub MCP access?
The connection is invalidated on the next tool call. Subsequent requests fail closed. Other developers remain unaffected.
Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""githubmcp"": {
""url"": ""https://mcp.scalekit.com/githubmcp"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.githubmcp]
url = ""https://mcp.scalekit.com/githubmcp""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""githubmcp"": {
""url"": ""https://mcp.scalekit.com/githubmcp"",
""type"": ""http""
}
}
}