Search public open-source code, documentation, metadata, vulnerabilities, changelogs, and examples.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
The code context layer for AI coding agents.
Website Β· Documentation Β· Issues
GitHits connects AI coding agents to public open-source evidence across the full software development lifecycle: discovery, planning, research, implementation, debugging, and maintenance.
The CLI runs a local MCP server that your coding tool starts on demand. Agents can then search indexed package and repository source, read exact files and documentation pages, inspect package health, compare dependency upgrades, and find source-cited examples from real open-source projects when model knowledge and local repository context are not enough.
init signs you in, detects supported coding tools, and configures GitHits for
the tools you select. It uses the local stdio MCP except for Cursor, whose
direct setup uses the hosted remote MCP.
Automatic setup currently supports Claude Code, Cursor, Windsurf, VS Code / Copilot, Cline, Claude Desktop, Codex CLI, Pi, Gemini CLI, Google Antigravity, OpenCode, Hermes Agent, Zed, Junie, Qwen Code, Kiro, Kilo Code, Factory Droid, and Amazon Q CLI.
After setup, open your coding agent and work normally. Many agents call GitHits when they need source-backed context. If your agent starts guessing, prompt it directly:
GitHits is designed for the point where an agent needs evidence from the broader open-source ecosystem, not just model memory or local repo context:
| Capability | MCP tools | CLI commands |
|---|---|---|
| Code examples | get_example, search_language | githits example, githits languages |
| Code navigation | search, search_status, code_files, code_read, code_grep | githits search, githits search-status, githits code ... |
| Documentation access | docs_list, docs_read | githits docs ... |
| Package inspection | pkg_info, pkg_vulns, pkg_deps, pkg_changelog, pkg_upgrade_review | githits pkg ... |
| Feedback | feedback | githits feedback |
Use GitHits when your agent needs to:
Find prior art across open source:
Search indexed code, docs, and symbols for a dependency:
Read and grep dependency source without cloning:
Inspect package health and upgrade evidence:
Browse and read package documentation:
GitHits works with package and repository targets such as:
npm:react, npm:react@18.2.0, pypi:requests, crates:serdehttps://github.com/expressjs/express, github:expressjs/express#mainPackage inspection supports npm, PyPI, Hex, Crates, NuGet, Maven, Packagist, RubyGems, Go, Swift, vcpkg, and Zig. Advisory data is unavailable for vcpkg and Zig; dependency graph support varies by registry.
Code example search supports license filtering:
strict is the default and filters repositories with copyleft or undeclared licensescustom uses your account blocklist configured at githits.comyolo disables license filteringNormal local setup is handled by:
For manual login:
Browser OAuth is recommended for local development. Credentials are stored in the system keychain by default and refreshed automatically. Useful flags:
init --no-browser or login --no-browser prints the login URL instead of launching a browserinit --port <port> or login --port <port> fixes the loopback callback portlogin --force re-authenticates even if you are already logged inThe OAuth callback always listens on the machine where GitHits is running. When GitHits runs over SSH and the browser runs locally, forward the selected port from the browser machine:
With that tunnel open, run GitHits on the remote machine using the same port:
Open the URL printed by GitHits in the local browser. Replace
user@remote-host with the SSH destination you normally use. The same flags
work with githits login after setup.
Browser OAuth is interactive. For CI and other unattended environments, supply
GITHITS_API_TOKEN through the environment's secret manager.
GitHits uses the system keychain by default because OAuth credentials include a refresh token. On macOS this means Keychain Access; on Windows it means Credential Manager; on Linux it means the available Secret Service or keyring backend.
If macOS shows a prompt such as "githits wants to access ... in your keychain",
choose Always Allow when you trust the installed githits CLI. GitHits
cannot customize that operating-system prompt; it is generated by macOS.
GitHits also writes a small non-secret metadata file so recent startup checks do
not need to read the keychain. The keychain is only read when GitHits needs the
token, for example during a tool call, token refresh, githits auth status, or a
login check after metadata is stale or expired.
If your agent keeps showing keychain prompts even after Always Allow, switch OAuth storage to file mode:
The config directory may be empty until you create config.toml or GitHits
writes auth metadata. Older macOS installs may have used
~/Library/Application Support/githits; GitHits still reads that location for
migration, but new auth config and file storage use ~/.config/githits.
You can also opt in for one process:
File mode stores OAuth credentials as JSON files under the GitHits config directory. The files are written with private permissions where the platform supports it, but they are not encrypted. Any process that can read files as your operating-system user may be able to read the tokens.
Use file mode only on machines where you trust local user-account access. For CI
and automation, prefer GITHITS_API_TOKEN instead of browser OAuth.
Inspect auth and runtime state with:
See the authentication docs for keychain behavior, file storage mode, CI setup, and troubleshooting.
If your coding tool is not auto-configured by init, add GitHits to its MCP
configuration manually:
Your tool runs this command over stdio. No background daemon or global install is required.
To remove configuration written by init:
This removes GitHits MCP configuration and preserves stored credentials. Run
npx githits@latest logout separately to remove credentials.
For project-local MCP config, run:
Project setup is available only for tools with verified project-local MCP support. Project config contains no secrets, but it may be committed like other tooling configuration, so review generated files before adding them to source control.
Agent-safe non-interactive setup uses staged discovery and explicit install:
The repository and published package provide the plugin and extension assets
used by compatible hosts. Git-based installs also retain the context-file
symlinks (CLAUDE.md and GEMINI.md) to the canonical AGENTS.md:
.plugin/plugin.json.claude-plugin/plugin.json.claude-plugin/marketplace.json.codex-plugin/plugin.json.cursor-plugin/plugin.json.mcp.jsongemini-extension.jsonplugin.json (Google Antigravity)mcp_config.json (Google Antigravity)AGENTS.mdCLAUDE.mdGEMINI.mdskills/The root skill tree is shared by all supported hosts. Every plugin and extension
install uses the hosted remote MCP, including Claude, Codex, Cursor, Gemini CLI,
Google Antigravity, and VS Code/GitHub Copilot OpenPlugin. Direct githits init
setup is a separate path: it installs local stdio configurations for supported
tools except Cursor, which remains remote-only. The repository root is a native
Antigravity plugin through plugin.json, mcp_config.json, and the shared
skills/ tree. Generated manifests are refreshed with bun run plugins:generate
and validated with bun run plugins:check.
For Claude Code marketplace installs:
For Gemini CLI extension installs:
Full CLI reference: https://docs.githits.com/cli/commands
Most users do not need environment variables. These are the common overrides for CI, auth storage, and local diagnostics:
| Variable | Purpose | Default |
|---|---|---|
GITHITS_API_TOKEN | API token for authentication | unset |
GITHITS_AUTH_STORAGE | Override OAuth storage mode: keychain or file | keychain |
GITHITS_DISABLE_UPDATE_CHECK | Disable npm latest-version update notices | unset |
GITHITS_TELEMETRY | Emit local timing diagnostics to stderr | unset |
Full reference: https://docs.githits.com/cli/environment-variables
This repository contains the GitHits CLI and reusable MCP package:
src/ - CLI commands, local auth, setup flows, and local MCP stdio startuppackages/mcp/ - public @githits/mcp package for transport-neutral MCP
server APIs, tool registration, instructions, and smoke-test helperspackages/core-internal/ - shared workspace implementation used by the CLI
and MCP packagedocs/ - implementation notes and contributor guidelinesscripts/ - package validation, smoke tests, and development utilitiesRequirements:
^20.18.1 || >=22.13.0Common commands:
When changing MCP tools, CLI commands, shared formatters, auth/error envelopes, or MCP/CLI parity behavior, also run the relevant smoke suites:
CI also checks the built product without credentials or live backend calls. Run
the same checks locally after bun run build:
The harness remains on Bun, while product subprocesses execute dist/cli.js
with node from PATH. CI provisions that runtime from .node-version.
When changing MCP instructions, tool descriptions, or agent-facing behavior,
use the targeted agent evals described in eval/agentic/README.md:
Apache-2.0
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/githits)<a href="https://allmcps.com/mcp/githits"><img src="https://allmcps.com/api/badge/githits?style=directory" alt="GitHits on AllMCPs" /></a>