The GitHub MCP Server: Setup With Claude Code and What It Can Do
GitHub's official MCP server lets AI tools read and act on your repositories: issues, pull requests, Actions runs, code search and security alerts. How to connect it to Claude Code (remote or Docker), choose toolsets, use read-only mode, and keep your token safe.
The GitHub MCP server is GitHub's official way to give AI tools access to your repositories. With it connected, you can ask Claude Code things like "summarise the open issues labelled bug", "why did the last Actions run fail?" or "open a PR for this branch with a good description".
What it can do
The server groups its abilities into toolsets:
- repos — browse files, branches, commits; search code
- issues — read, create, comment on, label issues
- pull_requests — read, create, review and comment on PRs
- actions — list workflow runs, read logs, re-run jobs
- code_security — read code scanning alerts
- …and others (discussions, notifications, gists)
By default a sensible set is enabled. You can narrow it.
Option 1: GitHub's hosted server (easiest)
GitHub runs the server for you at https://api.githubcopilot.com/mcp/. You need a personal access token (create one here) — a fine-grained token limited to the repositories and permissions you need.
Store the token in an environment variable rather than typing it into commands that end up in your shell history, then:
claude mcp add-json github '{"type":"http","url":"https://api.githubcopilot.com/mcp","headers":{"Authorization":"Bearer '"$GITHUB_PAT"'"}}'
Restart Claude Code and check with claude mcp list or /mcp.
Option 2: run it locally with Docker
If you'd rather the server run on your machine:
claude mcp add github -e GITHUB_PERSONAL_ACCESS_TOKEN=$GITHUB_PAT -- docker run -i --rm -e GITHUB_PERSONAL_ACCESS_TOKEN ghcr.io/github/github-mcp-server
This needs Docker running. (What is Docker?)
Choosing toolsets
Fewer tools means less context used and fewer wrong choices. For the local server:
GITHUB_TOOLSETS="repos,issues,pull_requests,actions"
There's also a read-only mode that removes every tool that changes anything — a good default while you're getting comfortable.
Do you even need it?
If you have the gh command-line tool installed and logged in, Claude Code can already do a lot through it: gh pr create, gh issue list, gh run view --log-failed. Many people find that's enough.
The MCP server shines when:
- you want structured access without installing
gh, - you're using an AI tool that can't run shell commands (like a chat app),
- you want fine-grained toolset and read-only controls.
Keeping it safe
- Use a fine-grained token, scoped to specific repositories, with the minimum permissions. Not a classic token with full
repoaccess to everything. - Don't commit the token. If you share the config through
.mcp.json, reference an environment variable. Add.envto.gitignore. (.gitignore explained) - Beware of instructions in issues and PRs. Anyone can write an issue on a public repo. Text in it could try to tell the AI to do something harmful. Keep write actions behind approvals. (Prompt injection in coding agents)
- Rotate the token if it ever leaks. (I leaked an API key)
Useful prompts
List open PRs waiting for my review and summarise each in one line.
The last CI run on main failed. Read the logs, find the cause, and fix it on a new branch.
Turn issue #42 into a plan, implement it, and open a PR that references the issue.
EasySpawn runs Claude Code on a persistent server with your repository checked out and your GitHub connection already set up, so these prompts work from your phone or browser too. See how it works or join the waitlist.
Related: Connecting MCP Servers to Claude Code · Claude Code GitHub Actions · The Best MCP Servers for Coding · Using Git With Claude Code
Keep reading
The Best MCP Servers for Coding (and How to Choose Safely)
The MCP servers worth installing for everyday coding with Claude Code, Cursor or VS Code: GitHub, Playwright, your database, docs lookup, error monitoring and more. What each is for, how to add one, and the safety rules that matter more than the list.
AGENTS.md vs CLAUDE.md: Which One Do You Need?
AGENTS.md is the shared instruction file many AI coding agents read; CLAUDE.md is Claude Code's own. When Claude Code reads AGENTS.md, why it ignores it if a CLAUDE.md exists, and the simple setup that keeps one file for every tool.