@neurealistic/git-mcp
v0.1.1
Published
MCP server for git — local working-tree ops + token-authenticated push/fetch (no host credential helper). Runs via npx, no docker.
Maintainers
Readme
@neurealistic/git-mcp
An MCP server for git: local working-tree operations + token-authenticated push/fetch — without
relying on the host credential helper (keychain / gh CLI). Runs via npx, no docker.
The official github-mcp-server covers the GitHub API (PRs, issues, API-level commits) but not local working-tree git (rebase, staged commits, pushing a local branch); the reference git MCP has no token model → push falls back to host credentials. A sandboxed agent must never reach host secrets. This server runs the git CLI on a given repo and, for network ops, injects a token one-off into the remote URL — never persisted in git config, never exposed to the caller. Auth lives in the server's env, so the agent pushes with a scoped identity without ever handling the secret.
Run
// .mcp.json
{
"mcpServers": {
"git": {
"command": "npx",
"args": ["-y", "--prefer-offline", "@neurealistic/git-mcp"],
"env": {
"GIT_TOKEN": "<a scoped PAT>", // required for push/fetch on private/https remotes
"GIT_USER": "x-access-token", // GitHub convention; GitLab: "oauth2"
"GIT_MCP_ALLOW_DIRS": "/path/to/worktrees" // optional: confine which repos may be operated on
}
}
}
}Stdio by default (the host manages it); set MCP_PORT for HTTP (/mcp).
Tools
Every tool takes repo (absolute path to the repo / worktree).
| Tool | Does |
|---|---|
| git_status | short status + branch |
| git_log | commit log (max, oneline) |
| git_diff | diff (staged, ref) · git_show (ref, stat) |
| git_branch | list branches · git_checkout (ref, create, startPoint) |
| git_add | stage paths (default all) · git_commit (message, all) |
| git_reset | reset to ref (hard) · git_rebase (onto / abort / cont) · git_merge |
| git_remote | list remotes |
| git_fetch / git_pull / git_push | token-authenticated network ops; git_push uses --force-with-lease on force |
Network ops use GIT_TOKEN via a one-off authed URL; with no token they fall back to the named remote
(git's own auth). The token is never written to config or returned.
License
MIT
