gitlab-mcp
A MCP server for GitLab with powerful, safe, policy-controlled access
Install / Use
claude mcp add mcpland -- npx -y github:mcpland/gitlab-mcpIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of gitlab-mcp
gitlab-mcp scores 81/100 on our quality scale, 3502nd of 4,598 Development & Engineering skills we index.
Its MCP Server is 28 KB long, well organised into 43 sections with 17 code examples: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 29 days ago, so gitlab-mcp is actively maintained.
- Our last check on 2026-09-29 found the source still online.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
gitlab-mcp compared with similar skills
All 4 of these similar skills score higher than gitlab-mcp; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| gitlab-mcp (this skill)by mcpland | 81 | 10 | 29d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 95.5k | 2d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.9k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.3k | today | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 45.7k | 2d ago | CLAUDE.md |
Frequently asked questions
- How do I install gitlab-mcp?
- Run
claude mcp add mcpland -- npx -y github:mcpland/gitlab-mcp. The install tabs above show the steps for each supported agent. - Which AI agents does gitlab-mcp work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is gitlab-mcp safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is gitlab-mcp still maintained?
- The repository was last updated 29 days ago, so gitlab-mcp is actively maintained.
Skill content
View source on GitHubgitlab-mcp
A production-ready MCP server for GitLab. It lets AI assistants read and manage GitLab projects, merge requests, issues, pipelines, wikis, releases, and more through a broad, policy-controlled tool registry.
Highlights
- Comprehensive GitLab coverage — projects, merge requests (with code-context analysis), issues, pipelines, wikis, milestones, releases, labels, commits, branches, GraphQL, and file management
- Multiple transports — stdio for local CLI usage, Streamable HTTP for remote deployments, optional SSE
- Flexible authentication — personal access tokens, OAuth 2.0 PKCE, external token scripts, token files, cookie-based auth, and per-request remote authorization
- Policy engine — readonly/modify/full modes, tool allowlist/denylist, feature toggles, and project-scoped restrictions
- Enterprise networking — HTTP/HTTPS proxy, custom CA certificates, Cloudflare bypass, multi-instance API rotation
- Output control — JSON, compact JSON, or YAML formatting with configurable response size limits
Usage
Supported clients
Claude Desktop, Claude Code, VS Code, GitHub Copilot Chat (VS Code), Cursor, JetBrains AI Assistant, GitLab Duo, and any MCP client that supports stdio or streamable HTTP.
Current client format references:
- MCP transports and protocol
- Claude Code MCP
- VS Code MCP servers
- Cursor MCP
- JetBrains AI Assistant MCP
Authentication methods
The server supports three auth patterns:
- Personal Access Token (PAT)
- OAuth 2.0 PKCE (recommended for local interactive use)
- Remote per-request auth (
REMOTE_AUTHORIZATION=true, HTTP mode)
OAuth2 setup (stdio, recommended for local interactive use)
- Create a GitLab OAuth application in
Settings -> Applications. - Set redirect URI to
http://127.0.0.1:8765/callback(or your custom callback). - Set scope to
api. - Copy the Application ID as
GITLAB_OAUTH_CLIENT_ID.
{
"mcpServers": {
"gitlab": {
"command": "npx",
"args": ["-y", "gitlab-mcp@latest"],
"env": {
"GITLAB_USE_OAUTH": "true",
"GITLAB_OAUTH_CLIENT_ID": "your_oauth_client_id",
"GITLAB_OAUTH_REDIRECT_URI": "http://127.0.0.1:8765/callback",
"GITLAB_API_URL": "https://gitlab.com/api/v4",
"GITLAB_ALLOWED_PROJECT_IDS": "",
"GITLAB_PERMISSION_MODE": "full",
"USE_GITLAB_WIKI": "true",
"USE_MILESTONE": "true",
"USE_PIPELINE": "true"
}
}
}
}
If your OAuth app is confidential, also set GITLAB_OAUTH_CLIENT_SECRET.
Personal Access Token setup (stdio)
{
"mcpServers": {
"gitlab": {
"command": "npx",
"args": ["-y", "gitlab-mcp@latest"],
"env": {
"GITLAB_PERSONAL_ACCESS_TOKEN": "glpa…[redacted]",
"GITLAB_API_URL": "https://gitlab.com/api/v4",
"GITLAB_ALLOWED_PROJECT_IDS": "",
"GITLAB_PERMISSION_MODE": "full",
"USE_GITLAB_WIKI": "true",
"USE_MILESTONE": "true",
"USE_PIPELINE": "true"
}
}
}
}
VS Code .vscode/mcp.json examples
PAT with secure prompt input:
{
"inputs": [
{
"type": "promptString",
"id": "gitlab_token",
"description": "GitLab Personal Access Token",
"password": true
}
],
"servers": {
"gitlab": {
"type": "stdio",
"command": "node",
"args": ["/absolute/path/to/gitlab-mcp/dist/index.js"],
"env": {
"GITLAB_PERSONAL_ACCESS_TOKEN": "${input:gitlab_token}",
"GITLAB_API_URL": "https://gitlab.com/api/v4",
"GITLAB_PERMISSION_MODE": "full"
}
}
}
}
OAuth (confidential app) with secure prompt input:
{
"inputs": [
{
"type": "promptString",
"id": "gitlab_oauth_secret",
"description": "GitLab OAuth Client Secret",
"password": true
}
],
"servers": {
"gitlab": {
"type": "stdio",
"command": "node",
"args": ["/absolute/path/to/gitlab-mcp/dist/index.js"],
"env": {
"GITLAB_USE_OAUTH": "true",
"GITLAB_OAUTH_CLIENT_ID": "your_oauth_client_id",
"GITLAB_OAUTH_CLIENT_SECRET": "${input:gitlab_oauth_secret}",
"GITLAB_OAUTH_REDIRECT_URI": "http://127.0.0.1:8765/callback",
"GITLAB_API_URL": "https://gitlab.com/api/v4"
}
}
}
}
GitHub Copilot Chat in VS Code uses the same .vscode/mcp.json format.
Claude Desktop / Claude Code / Cursor
Claude Desktop reads claude_desktop_config.json.
Claude Code supports project-level .mcp.json and claude mcp add-json.
Cursor uses .cursor/mcp.json.
{
"mcpServers": {
"gitlab": {
"command": "node",
"args": ["/absolute/path/to/gitlab-mcp/dist/index.js"],
"env": {
"GITLAB_PERSONAL_ACCESS_TOKEN": "glpa…[redacted]",
"GITLAB_API_URL": "https://gitlab.com/api/v4"
}
}
}
}
GitLab Duo (~/.gitlab/duo/mcp.json)
{
"mcpServers": {
"gitlab": {
"command": "node",
"args": ["/absolute/path/to/gitlab-mcp/dist/index.js"],
"env": {
"GITLAB_PERSONAL_ACCESS_TOKEN": "glpa…[redacted]",
"GITLAB_API_URL": "https://gitlab.com/api/v4"
}
}
},
"approvedTools": ["gitlab_get_project", "gitlab_list_merge_requests"]
}
JetBrains AI Assistant
JetBrains can import an existing MCP JSON config or register the server manually.
Use stdio command node /absolute/path/to/gitlab-mcp/dist/index.js, or HTTP endpoint http://127.0.0.1:3333/mcp with required headers.
Remote authorization (multi-user HTTP)
Start server:
REMOTE_AUTHORIZATION=true \
HTTP_HOST=0.0.0.0 \
MCP_ALLOWED_HOSTS=127.0.0.1 \
HTTP_PORT=3333 \
node dist/http.js
Client config:
{
"mcpServers": {
"gitlab": {
"url": "http://127.0.0.1:3333/mcp",
"headers": {
"Authorization": "Bearer glpa…[redacted]"
}
}
}
}
Dynamic per-request API URL:
REMOTE_AUTHORIZATION=true \
ENABLE_DYNAMIC_API_URL=true \
HTTP_HOST=0.0.0.0 \
MCP_ALLOWED_HOSTS=127.0.0.1 \
HTTP_PORT=3333 \
node dist/http.js
Add header in client requests:
{
"headers": {
"Authorization": "Bearer glpa…[redacted]",
"X-GitLab-API-URL": "https://gitlab.example.com/api/v4"
}
}
Remote auth behavior matrix:
| Server Mode | Required Request Headers | Token Fallback Chain |
| ----------------------------------------------------------- | --------------------------------------------------------------------------------------------- | -------------------- |
| REMOTE_AUTHORIZATION=false on local HTTP bind only | none | enabled |
| REMOTE_AUTHORIZATION=true | Authorization: Bearer <token>, Private-Token: <token>, or Job-Token: <token> | disabled |
| REMOTE_AUTHORIZATION=true + ENABLE_DYNAMIC_API_URL=true | Authorization, Private-Token, or Job-Token, and X-GitLab-API-URL: https://host/api/v4 | disabled |
When HTTP_HOST is not 127.0.0.1, localhost, or ::1, HTTP startup rejects
server-side GITLAB_PERSONAL_ACCESS_TOKEN or GITLAB_JOB_TOKEN unless inbound
requests are protected by MCP_HTTP_AUTH_TOKEN, REMOTE_AUTHORIZATION=true, or
GITLAB_MCP_OAUTH=true.
Docker
For containerized deployments, PAT or remote auth is recommended.
OAuth interactive callback flow is usually less convenient in containers.
The Compose service listens on 0.0.0.0 inside the container but publishes only
127.0.0.1:3333 on the host by default. For the remote-authorization example,
set REMOTE_AUTHORIZATION=true in .env, leave server-side GitLab credentials
empty, and send each client's GitLab token as shown above.
docker compose up --build -d
or:
docker build -t gitlab-mcp .
docker run -d \
--name gitlab-mcp \
-p 127.0.0.1:3333:3333 \
-e HTTP_HOST=0.0.0.0 \
-e MCP_ALLOWED_HOSTS=127.0.0.1 \
-e REMOTE_AUTHORIZATION=true \
-e GITLAB_API_URL=https://gitlab.com/api/v4 \
gitlab-mcp
Clients must send their GitLab credential in Authorization: Bearer <token>,
Private-Token, or Job-Token. To keep a GitLab token in the container instead,
set a separate 32+ character MCP_HTTP_AUTH_TOKEN and require clients to send that
value as the bearer token; never expose a server-held GitLab token as the MCP bearer.
Compatibility notes
GITLAB_PROJECT_IDis not a supported environment variable in this repository.- To set an effective default project, use
GITLAB_ALLOWED_PROJECT_IDSwith one project ID, or passproject_idin tool arguments. - CLI argument overrides such as
--tokenor--api-urlare not implemented (--env-fileis supported). - JSON config files do not support comments (
//).
MCP Server Configuration
HTTP server
pnpm install
cp .env.example .env
pnpm build
# stdio (local MCP)
pnpm start
# streamable HTTP server (http://127.0.0.1:3333/mcp)
pnpm start:http
# optional: load a specific env file
pnpm start -- --env-file .env.local
pnpm start:http -- --env-file .env.local
Transport and entrypoint
| Transport | Entry Point | Endpoint | Best For |
| ------------------- | -------------------- | ---------------------------- | ------------------------------------ |
| stdio | node dist/index.js | stdin/stdout | Local single-user MCP clients |
| Streamable HTTP | node dist/http.js | POST/GET/DELETE /mcp | Remote/shared deployments |
| SSE (legacy) | node dist/http.js | GET /sse, POST /messages | Legacy SSE-only clients (SSE=true) |
| Health | node dist/http.js | GET /healthz | Liveness/readiness checks |
SSE=true is not compatible with REMOTE_AUTHORIZATION=true.
Tool Categories
Tools are organized into these categories. All GitLab tools use the gitlab_ prefix, except health_check.
| Category | Examples |
| ------------------- | ---------------------------------------------------------------------------- |
| Projects | get_project, list_projects, create_repository, update_project |
| Repository | get_repository_tree, get_file_contents, push_files, protected branches |
| Merge Requests | list_merge_requests, get_merge_request_conflicts, merge_merge_request |
| MR Code Context | get_merge_request_code_context (advanced code review) |
| MR Discussions | list_merge_request_discussions, create_merge_request_thread |
| MR Notes | list_merge_request_notes, create_merge_request_note |
| Draft Notes | list_draft_notes, create_draft_note, bulk_publish_draft_notes |
| Issues | list_issues, create_issue, update_issue, issue links |
| Pipelines | list_pipelines, list_deployments, get_job_artifact_file
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
95.5kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.9kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.3kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
ai-job-search
45.7kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
