GitLab MCP Server
by dediwsn
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SSE | No | Set to true to enable the SSE transport. | |
| HOST | No | Host interface the server binds to (e.g. 0.0.0.0 for containerized deployments). | |
| PORT | No | Port the server listens on. | |
| GITLAB_API_URL | No | GitLab API base URL (e.g. https://gitlab.com/api/v4 or your self-hosted instance). | |
| MCP_SERVER_URL | No | Public HTTPS URL of this MCP server. Required for GITLAB_MCP_OAUTH=true; also allowed for /mcp Host/Origin checks. | |
| SSE_AUTH_TOKEN | No | Bearer token required to authenticate SSE transport clients. | |
| GITLAB_TOOLSETS | No | Comma-separated list of toolset groups to enable (e.g. wiki,milestones,pipelines). | |
| STREAMABLE_HTTP | No | Set to true to enable the Streamable HTTP transport. Required for REMOTE_AUTHORIZATION and GITLAB_MCP_OAUTH modes. | |
| GITLAB_MCP_OAUTH | No | Set to true to enable the MCP OAuth proxy mode for remote MCP clients (server/remote deployments only). Requires a publicly accessible HTTPS URL. | |
| GITLAB_USE_OAUTH | No | Set to true to enable the OAuth2 local browser flow (recommended for better security on local/desktop use). | |
| GITLAB_OAUTH_APP_ID | No | Client ID of the pre-registered GitLab OAuth application. Required for GITLAB_MCP_OAUTH=true. | |
| REMOTE_AUTHORIZATION | No | Set to true to enable remote authorization, where each HTTP caller provides their own GitLab token in request headers (Private-Token, JOB-TOKEN, or Authorization: Bearer). Requires STREAMABLE_HTTP=true. | |
| GITLAB_READ_ONLY_MODE | No | Enable read-only mode (deprecated; prefer GITLAB_PERMISSION_MODE=readonly). | |
| GITLAB_MASKING_ENABLED | No | Set to true to enable text-response masking. | |
| GITLAB_OAUTH_CLIENT_ID | No | OAuth client/application ID used for the local OAuth browser flow (GITLAB_USE_OAUTH=true). | |
| GITLAB_PERMISSION_MODE | No | Permission level: readonly, modify (no delete or teardown tools), or full. Replaces GITLAB_READ_ONLY_MODE. Default is full. | |
| GITLAB_OAUTH_REDIRECT_URI | No | Local OAuth callback URL, e.g. http://127.0.0.1:8888/callback. For local OAuth (GITLAB_USE_OAUTH) only; does not override remote MCP OAuth client callback URLs. | |
| GITLAB_DISABLE_VERSION_CHECK | No | Set to true to disable the startup new-version notice. | |
| GITLAB_PERSONAL_ACCESS_TOKEN | No | GitLab Personal Access Token for the simplest local/desktop authentication method. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
No tools | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
This server cannot be deployed
Maintenance
ActivityActive
ResponsivenessNo issues