Safety-first Git MCP server: rich read tools plus human-approved FluxGit operation proposals.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
mcp-name: io.github.fluxgit-hq/fluxgit-mcp-server
Safety-first Model Context Protocol (MCP) server for Git.
AI agents inspect. FluxGit keeps control.
A Rust MCP server with 38 contracts for AI code agents: 25 read-only tools and 13 human-gated operation tools (12 proposals plus cancellation of a pending proposal). The sidecar never executes a Git write; it bridges approved proposals to the FluxGit desktop application.

For context-budget comparisons, see the public Git context token benchmark. It publishes the fixture, raw outputs, scripts and checksums, including both the broad CLI sweep and a smaller hand-tuned counterexample.
AI coding agents are increasingly asked to navigate real repositories: explain branch state, summarize diffs, find lost commits, recommend safe next steps. To do this well, an agent needs Git context that is richer than git status and structured enough to reason over. To do this safely, an agent must never be able to silently mutate refs, force-push, discard work, or apply patches without a human approving the consequence.
Other MCP Git servers face a choice: stay strictly read-only (limited utility) or expose write tools directly (dangerous — agents hallucinate, prompts can be poisoned, mistakes are destructive). This sidecar chooses neither. Inspection is schema-validated and bounded; operations go through a write-with-UI-handshake: the agent proposes, FluxGit shows the preview, the user approves in the app, and FluxGit executes through its safety pipeline with restore points and audit.
| Tool | Purpose |
|---|---|
repo.brief | One-call situational awareness — branch, ahead/behind, in-progress operation, working-tree summary, stashes, aggregated submodule drift, recent commits, detected conventions and next-step hints. The recommended first call of an agent session; replaces 6-10 raw git calls and is token-budgeted by design |
repo.scope | Monorepo scoping — one subtree's working-tree changes, recent commits, churn (commits + authors over a window) and CODEOWNERS owners in a single call |
repo.status | Working tree, current branch, dirty paths |
repo.refs | Branches, tags, remotes, stashes |
repo.branchStack | Current branch vs upstream / base / related |
repo.history | Paginated commit history |
repo.reflog | Movement timeline with recovery hints |
repo.conflictPreflight | Predict merge/rebase outcome before running |
conflict.read | Active conflict as structured data — in-progress operation, ours/theirs producing commits, per-file stage classification, base/ours/theirs contents (size-capped, binary-flagged) and marker region line ranges. No more parsing <<<<<<< soup |
commit.details | Single commit metadata + changed files |
worktree.changes | Per-path working tree change summary |
worktree.list | All worktrees (main + linked) with branch/detached, HEAD SHA and locked/prunable flags — the read-only base for parallel agent worktrees |
submodule.status | Submodule list and state |
diff.text | Standard text patch (git diff compatible) |
diff.semantic | Capability-negotiated semantic explanation |
diff.semanticFallbacks | Paths that fell back from semantic to text |
fleet.radar | Multi-repo attention queue |
fleet.digest | What changed across the fleet since a time — HEAD and local-branch reflog moves of many repositories, newest first, bounded by maxEvents (default 200, max 1000). repoPaths, or FluxGit's registered repositories inside the allowed roots when omitted. identity is exactly what Git recorded (the configured identity, not proof of a person or an agent); rewrote flags moves that dropped the previous tip (reset, amend, rebase, forced moves). Reads reflog files only; nothing is fetched or written |
agents.presence | Which other coding agents are working in this repository — from local sources only (running agent processes and their children, the agents' own session stores, files they keep in the repository, editors with built-in agents, and FluxGit MCP presence records). Per agent: state (working/open/recent), sources, branch, last tool and repository-relative files when known. Names are what each tool or MCP client declares about itself. Your own MCP record is excluded; findings that are probably your own session are marked likelyCaller. Never returns prompts, messages or file contents |
safety.timeline | Synthesized safety events from restore points + reflog |
safety.eventDetails | Drill-down into one timeline event |
flux.latestRestorePoint | Newest FluxGit restore point |
flux.restorePoints | List of restore points |
flux.restorePointDetails | One restore point with before/after refs |
operation.status | Authoritative asynchronous status by previewId; poll after a preview returns accepted: true and do not report a Git outcome before it becomes terminal |
All 12 operation.preview.* proposals dispatch through the FluxGit gateway when
configured. The sidecar POSTs the proposal, performs one bounded status read,
and normally returns immediately with accepted: true, the canonical
previewId, current status and nextAction.tool: "operation.status". The
FluxGit app renders a “Requested by AI agent” approval card while human review
continues asynchronously. Code 10003 is reserved for a bridge that is absent,
invalid or unreachable; it is not a human-approval timeout.
All 12 preview schemas accept an optional bounded idempotencyKey. Reuse it
only when retrying the same logical intent; the sidecar scopes it to the
operation type so that retry resolves to the existing gateway proposal. Omit
it for a new intent—even when the other arguments match—and the sidecar sends
a fresh UUID-backed key. Preview tools therefore continue to advertise
idempotentHint: false.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/fluxgit-mcp-server)<a href="https://allmcps.com/mcp/fluxgit-mcp-server"><img src="https://allmcps.com/api/badge/fluxgit-mcp-server?style=directory" alt="Fluxgit MCP Server on AllMCPs" /></a>