@neurealistic/gh-mcp
v0.1.0
Published
MCP server for the GitHub API (PRs, issues, reviews, repos) — server-side token, HTTP mode, run_steps batch. Companion to @neurealistic/git-mcp. Runs via npx, no docker.
Maintainers
Readme
@neurealistic/gh-mcp
An MCP server for the GitHub API — pull requests, issues, reviews, comments, repos. Companion to
@neurealistic/git-mcp: git-mcp does git (local working
tree + token-authenticated push); this does GitHub the platform (PRs, issues, reviews — things that
don't exist in git).
Why not the official github-mcp-server?
The official server's HTTP mode requires a per-request Authorization: Bearer — so when a daemon
hosts it for other agents, the token has to travel in each agent's request (and land in an agent-readable
config). gh-mcp keeps the token server-side in GITHUB_TOKEN: one daemon-hosted instance, agents
connect over HTTP and use its tools without ever holding the token.
Run
# stdio (an MCP host manages the process):
GITHUB_TOKEN=ghp_xxx npx -y @neurealistic/gh-mcp
# HTTP (a daemon hosts one instance; agents connect to the url):
GITHUB_TOKEN=ghp_xxx MCP_PORT=4912 npx -y @neurealistic/gh-mcp
# → http://127.0.0.1:4912/mcpEnv
| var | meaning |
|---|---|
| GITHUB_TOKEN | required — a PAT. The only place the secret lives. |
| MCP_PORT | set → HTTP mode on that port; unset → stdio. |
| GH_HOST | API host (default api.github.com; GitHub Enterprise → your …/api/v3 host). |
| GH_MCP_ALLOW_REPOS | optional comma-separated owner/repo allowlist — any tool touching a repo outside it errors. |
Tools
| tool | does |
|---|---|
| gh_me | authenticated user (whoami) |
| gh_pr_list / gh_pr_get / gh_pr_files | list / get a PR / its changed files |
| gh_pr_reviews / gh_pr_review_comments / gh_pr_comments | formal reviews / line-level review threads / discussion comments |
| gh_pr_create / gh_pr_comment / gh_pr_review / gh_pr_merge | open / comment on / review (APPROVE·REQUEST_CHANGES·COMMENT) / merge |
| gh_issue_list / gh_issue_get / gh_issue_comment / gh_issue_create | issues |
| gh_repo_get | repository metadata |
| gh_request | escape hatch — arbitrary REST call (method + path [+ body]); covers anything without a dedicated tool |
| run_steps | batch — a sequence of REST calls with {{var}} / {{var.field}} threading between steps |
run_steps — batch + threading
{
"steps": [
{ "method": "POST", "path": "/repos/acme/app/pulls",
"body": { "title": "x", "head": "feat", "base": "main" }, "return": "pr" },
{ "method": "POST", "path": "/repos/acme/app/issues/{{pr.number}}/comments",
"body": { "body": "opened via run_steps" } }
]
}Each step's JSON response is captured under its return name; a later path/body interpolates
{{name}} (whole value) or {{name.field.subfield}} (a JSON path into it). Stops at the first error.
License
MIT
