MCP server for the GitHub CLI (gh). Read-only by default; single Go binary.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
A single static Go binary that speaks the Model Context Protocol
and lets an agent run GitHub CLI commands: any gh <command> <subcommand>
invocation β repo, issue, pr, release, gist, workflow, run,
secret, variable, project, ruleset, codespace, extension, api,
and more β with a read-only-by-default safety gate on anything that
changes state on GitHub.
No Python, no uv, no runtime dependency to install β just a binary and
an .mcp.json. It shells out to the gh binary already installed and
authenticated on the host (gh auth login, stored in the OS keychain, or
GH_TOKEN/GITHUB_TOKEN) instead of reimplementing a GitHub API client,
so it gets the full breadth of the CLI for free rather than a hand-curated
subset of endpoints.
Note: this is a sibling of github-mcp-connector, not a replacement. That one talks to the GitHub REST API directly via
google/go-githubwith a curated set of 18 tools. This one shells out to theghCLI itself β same trade-off asaws-mcp-connectorvs. a hand-written AWS SDK client: broader coverage (gh extensions, gh's own filters/formatting, workflow/run/codespace/project/ruleset management) through a singleghcli_execescape hatch, instead of a curated surface.
An agent that only has a narrow, hand-picked set of GitHub tools hits a wall the moment you need something outside that set. This connector instead wraps the
ghCLI itself, so an agent can rungh pr list,gh issue create,gh workflow run,gh api repos/owner/repo/issuesβ anything the CLI can do β without waiting on a new tool to be written for it. State-changing commands are blocked by default and require both a server-level opt-in and a per-callconfirm=true, so exploring/ reading is safe out of the box.
| Tool | What it does | Write? |
|---|---|---|
ghcli_exec | Run any gh <command> <subcommand> ... command. Read-only by default β commands that change GitHub state need GHCLI_MCP_ALLOW_WRITE=true on the server and confirm=true on the call. | β (gated) |
ghcli_help | Show gh <command> [subcommand] --help text β always safe, use it to check exact syntax before calling ghcli_exec. | |
ghcli_whoami | Show the GitHub identity (login, name, profile URL) the configured auth resolves to. |
Every tool accepts an optional response_format: markdown (default,
readable for a chat UI) or json (for programmatic use).
This server has no working-directory git repo, so repo-scoped commands
need an explicit -R/--repo owner/repo rather than relying on gh's
cwd-based repo detection.
Fastest path: grab a prebuilt bundle from the latest release β
download ghcli-mcp-connector-plugin-<version>-<os>-<arch>.zip, unzip it,
and point Cowork/Claude at the plugin/ folder inside (see step 4 of
SETUP.md). No Go toolchain required.
From source:
Or make build β see the Makefile for every shortcut
(test, vet, fmt, lint, tidy).
Full walkthrough β including wiring this up as a Claude/Cowork plugin β is in SETUP.md.
Everything is environment variables, passed through by the plugin's
.mcp.json:
| Variable | Purpose | Default |
|---|---|---|
GH_TOKEN / GITHUB_TOKEN | gh CLI's own token env vars. Leave unset to use whatever gh auth login already configured. | unset (keychain auth) |
GH_HOST | Target a GitHub Enterprise hostname instead of github.com. | unset (github.com) |
GHCLI_MCP_ALLOW_WRITE | "true" to permit state-changing commands at all (still needs confirm=true per call). | false (read-only) |
GHCLI_MCP_ALLOWED_REPOS | Comma-separated allowlist of owner/repo values, e.g. "me/proj,me/other". Only enforced when a call passes an explicit -R/--repo flag. | unset (unrestricted) |
GHCLI_MCP_CLI_PATH | Path to the gh binary. | gh resolved via PATH |
This isn't a toy script β it's got the same checks you'd expect from a production Go service:
go test ./...)go vet + gofmt cleanAll of it runs in CI on every push and PR.
Versions follow semver and are cut automatically by
release-please from
Conventional Commits on main:
fix: ... β patch (v0.1.0 β v0.1.1)feat: ... β minor (v0.1.1 β v0.2.0)feat!: ... / BREAKING CHANGE: footer β major (v0.2.0 β v1.0.0)Every merged PR updates a standing "chore(main): release vX.Y.Z" PR with an auto-generated CHANGELOG.md. Merging that PR:
server.json from those exact assets (fresh version +
SHA-256 hashes) and publishes it to the
official MCP Registry via
mcp-publisher, authenticated with GitHub OIDC β no stored secretsSee .github/workflows/release-please.yml
and .github/workflows/publish-mcp-registry.yml
(also runnable by hand for an existing tag via workflow_dispatch).
PRs and issues are very welcome β see CONTRIBUTING.md for the full guide (setup, coding conventions, how to add a new tool) and the Code of Conduct.
main is protected: every change, including the maintainer's, lands via
pull request with CI green. PR titles must follow
Conventional Commits β that's what
drives the automatic versioning above.
Found a security issue? Please follow SECURITY.md instead of opening a public issue.
MIT Β© FerhatDundar
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/ghcli-mcp-connector)<a href="https://allmcps.com/mcp/ghcli-mcp-connector"><img src="https://allmcps.com/api/badge/ghcli-mcp-connector?style=directory" alt="Ghcli Mcp Connector on AllMCPs" /></a>