The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the GitHits listing page.
The code context layer for AI coding agents.
Website · Documentation · Issues
GitHits connects AI coding agents to public open-source evidence across the full software development lifecycle: discovery, planning, research, implementation, debugging, and maintenance.
The CLI runs a local MCP server that your coding tool starts on demand. Agents can then search indexed package and repository source, read exact files and documentation pages, inspect package health, compare dependency upgrades, and find source-cited examples from real open-source projects when model knowledge and local repository context are not enough.
Want to use GitHits as part of your agent harness or software factory? Check out our public API documentation.
init signs you in, detects supported coding tools, and configures GitHits for
the tools you select. It uses the local stdio MCP except for Cursor, whose
direct setup uses the hosted remote MCP.
Automatic setup currently supports Claude Code, Cursor, Windsurf, VS Code / Copilot, Cline, Claude Desktop, Codex CLI, Pi, Gemini CLI, Google Antigravity, OpenCode, Hermes Agent, Zed, Junie, Qwen Code, Kiro, Kilo Code, Factory Droid, and Amazon Q CLI.
After setup, open your coding agent and work normally. Many agents call GitHits when they need source-backed context. If your agent starts guessing, prompt it directly:
GitHits is designed for the point where an agent needs evidence from the broader open-source ecosystem, not just model memory or local repo context:
| Capability | MCP tools | CLI commands |
|---|---|---|
| Tool orientation | quick_start | — |
| Code examples | get_example | githits example |
| Code navigation | search, search_status, code_files, code_grep | githits search, githits search-status, githits code ... |
| Documentation discovery | docs_list | githits docs list |
| Read source files or documentation sections | read | githits read <target> [path] |
| Package inspection | pkg_info, pkg_vulns, pkg_deps, pkg_changelog, pkg_upgrade_review | githits pkg ... |
Use GitHits when your agent needs to:
Find prior art across open source:
Search indexed code, docs, and symbols for a dependency:
Read and grep dependency source without cloning:
Inspect package health and upgrade evidence:
Browse and read package documentation:
GitHits 0.10 adds two opt-in local tools for early dogfooding:
resolve_target / githits resolve turns a fuzzy or ambiguous package,
repository, or documentation-site name into grouped canonical targets with
related project identities kept together.code_diff / githits code diff compares repository trees resolved from
exact package versions or public GitHub refs.They are hidden and disabled by default. They are available only through the
local githits CLI and local stdio MCP server; the hosted MCP and plugin or
extension installs keep the stable tool set. Enable them in the GitHits host
config, then restart the coding agent so it restarts the local MCP server:
See Experimental tools for platform-specific config discovery, CLI examples, limitations, and how to disable the tools.
GitHits works with package and repository targets such as:
npm:react, npm:react@18.2.0, pypi:requests, crates:serdehttps://github.com/expressjs/express, github:expressjs/express@mainPackage inspection supports npm, PyPI, Hex, Crates, NuGet, Maven, Packagist, RubyGems, Go, Swift, vcpkg, and Zig. Advisory data is unavailable for vcpkg and Zig; dependency graph support varies by registry.
Code example search supports license filtering:
strict is the default and filters repositories with copyleft or undeclared licensescustom uses your account blocklist configured at githits.comyolo disables license filteringNormal local setup is handled by:
For manual login:
Browser OAuth is recommended for local development. Credentials are stored in the system keychain by default and refreshed automatically. Useful flags:
init --no-browser or login --no-browser prints the login URL instead of launching a browserinit --port <port> or login --port <port> fixes the loopback callback portlogin --force re-authenticates even if you are already logged inThe OAuth callback always listens on the machine where GitHits is running. When GitHits runs over SSH and the browser runs locally, forward the selected port from the browser machine:
With that tunnel open, run GitHits on the remote machine using the same port:
Open the URL printed by GitHits in the local browser. Replace
user@remote-host with the SSH destination you normally use. The same flags
work with githits login after setup.
Browser OAuth is interactive. For CI and other unattended environments, supply
GITHITS_API_TOKEN through the environment's secret manager.
GitHits uses the system keychain by default because OAuth credentials include a refresh token. On macOS this means Keychain Access; on Windows it means Credential Manager; on Linux it means the available Secret Service or keyring backend.
If macOS shows a prompt such as "githits wants to access ... in your keychain",
choose Always Allow when you trust the installed githits CLI. GitHits
cannot customize that operating-system prompt; it is generated by macOS.
GitHits also writes a small non-secret metadata file so recent startup checks do
not need to read the keychain. The keychain is only read when GitHits needs the
token, for example during a tool call, token refresh, githits auth status, or a
login check after metadata is stale or expired.
If your agent keeps showing keychain prompts even after Always Allow, switch OAuth storage to file mode:
The config directory may be empty until you create config.toml or GitHits
writes auth metadata. Older macOS installs may have used
~/Library/Application Support/githits; GitHits still reads that location for
migration, but new auth config and file storage use ~/.config/githits.
You can also opt in for one process:
File mode stores OAuth credentials as JSON files under the GitHits config directory. The files are written with private permissions where the platform supports it, but they are not encrypted. Any process that can read files as your operating-system user may be able to read the tokens.
Use file mode only on machines where you trust local user-account access. For CI
and automation, prefer GITHITS_API_TOKEN instead of browser OAuth.
Inspect auth and runtime state with:
See the authentication docs for keychain behavior, file storage mode, CI setup, and troubleshooting.
If your coding tool is not auto-configured by init, add GitHits to its MCP
configuration manually:
Your tool runs this command over stdio. No background daemon or global install is required.
To remove configuration written by init:
This removes GitHits MCP configuration and guidance written by init, while
preserving stored credentials. Run npx githits@latest logout separately to
remove credentials. The compatibility form npx githits@latest init uninstall
accepts the same --yes, --project, and --keep-guidance options.
For project-local MCP config, run:
Project setup is available only for tools with verified project-local MCP support. Project config contains no secrets, but it may be committed like other tooling configuration, so review generated files before adding them to source control.
Agent-safe non-interactive setup uses staged discovery and explicit install:
The repository and published package provide the plugin and extension assets
used by compatible hosts. Git-based installs also retain the context-file
symlinks (CLAUDE.md and GEMINI.md) to the canonical AGENTS.md:
.plugin/plugin.json.claude-plugin/plugin.json.claude-plugin/marketplace.json.codex-plugin/plugin.json.cursor-plugin/plugin.json.mcp.jsongemini-extension.jsonplugin.json (Google Antigravity)mcp_config.json (Google Antigravity)AGENTS.mdCLAUDE.mdGEMINI.mdskills/The root skill tree is shared by all supported hosts. Every plugin and extension
install uses the hosted remote MCP, including Claude, Codex, Cursor, Gemini CLI,
Google Antigravity, and VS Code/GitHub Copilot OpenPlugin. Direct githits init
setup is a separate path: it installs local stdio configurations for supported
tools except Cursor, which remains remote-only. The repository root is a native
Antigravity plugin through plugin.json, mcp_config.json, and the shared
skills/ tree. Generated manifests are refreshed with bun run plugins:generate
and validated with bun run plugins:check.
Guided init installs the four canonical skills (githits-code, githits-mcp,
githits-onboarding, and githits-package) only for selected agents. Shared
skill-capable agents use ~/.agents/skills/ at user scope or .agents/skills/
at project scope; native-only agents use their verified native skill directory.
Compatible agents reading a shared root can discover those skills. A later
guided run repairs missing skills, and migration removes only the historical
Cline or Junie githits-mcp/SKILL.md after the complete shared set is verified.
For Claude Code marketplace installs:
For Gemini CLI extension installs:
Full CLI reference: https://docs.githits.com/cli/commands
Most users do not need environment variables. These are the common overrides for CI, auth storage, and local diagnostics:
| Variable | Purpose | Default |
|---|---|---|
GITHITS_API_TOKEN | API token for authentication | unset |
GITHITS_AUTH_STORAGE | Override OAuth storage mode: keychain or file | keychain |
GITHITS_DISABLE_UPDATE_CHECK | Disable npm latest-version update notices | unset |
GITHITS_TELEMETRY | Emit local timing diagnostics to stderr | unset |
Full reference: https://docs.githits.com/cli/environment-variables
This repository contains the GitHits CLI and reusable MCP package:
src/ - CLI commands, local auth, setup flows, and local MCP stdio startuppackages/mcp/ - public @githits/mcp package for transport-neutral MCP
server APIs, tool registration, instructions, and smoke-test helperspackages/core-internal/ - shared workspace implementation used by the CLI
and MCP packagedocs/ - implementation notes and contributor guidelinesscripts/ - package validation, smoke tests, and development utilitiesSee CHANGELOG.md for released changes, pending work, and the current package-version impact.
Requirements:
^20.18.1 || >=22.13.0Common commands:
When changing MCP tools, CLI commands, shared formatters, auth/error envelopes, or MCP/CLI parity behavior, also run the relevant smoke suites:
CI also checks the built product without credentials or live backend calls. Run
the same checks locally after bun run build:
The harness remains on Bun, while product subprocesses execute dist/cli.js
with node from PATH. CI provisions that runtime from .node-version.
When changing MCP instructions, tool descriptions, or agent-facing behavior,
use the targeted agent evals described in eval/agentic/README.md:
Apache-2.0