gitlab-mcp
Provides tools for interacting with gitlab.com projects, including managing issues, merge requests, code reviews, repository files, commits, branches, tags, CI pipelines and jobs, wiki pages, snippets, releases, labels, milestones, deployments, and activity/todos.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@gitlab-mcpsummarize the failing jobs in my latest pipeline"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
gitlab-mcp
An MCP server for gitlab.com. One binary over stdio, signed in as you. It works inside projects: issues, merge requests, reviews, the repository and CI. Instance and group administration, runners, CI variables and tokens are out of scope.
Unofficial, and not affiliated with GitLab Inc. See NOTICE.
What makes this one different
A small surface, gated by registration. About fifty tools rather than an API mirror, and a tool that is switched off is not registered, so it cannot be called at all.
Nothing it writes runs a quick action.
/mergein a comment is refused or escaped, never executed.Content is marked as untrusted. Issues, reviews, files and job logs come back inside boundaries the content cannot close.
Signs in like a desktop app. Your own OAuth application, a browser tab, the token in the OS keyring.
Verifiable releases. Signed checksums, build provenance and SBOMs.
Related MCP server: GitLab MCP Server
Status
Stable: the release badge above names the newest tag, and
CHANGELOG.md says what each one holds. The tool surface is a
contract: tools keep their names and output fields.
docs/architecture.md §16 is the plan.
Tools
Tool | What it does |
| Who is signed in, with which scopes, and what GitLab reports about itself |
| Turn a GitLab web URL into the arguments another tool takes, and name that tool |
| Find projects by name, or within a group |
| One project: default branch, visibility, what it has turned on |
| Who has access to a project, and with which role |
| Accounts by exact username or by name |
| Find issues across gitlab.com, a group or a project |
| One issue, its description marked as untrusted content |
| Create an issue; labels, assignees and milestone checked first |
| Change an issue's fields, refused if it changed since you read it |
| The comment threads on an issue or a merge request |
| Comment on an issue or merge request, reply in a thread, or start one, on a diff line or not |
| Resolve or reopen a thread on a merge request or an issue |
| Link two issues, in one project or two |
| Remove the link between two issues |
| Find merge requests across gitlab.com or a project |
| One merge request with its approvals |
| The files a merge request changes, with line counts and GitLab's markers |
| A merge request's diffs, file by file, bounded |
| A merge request's commits |
| Open a merge request from a branch |
| Change a merge request's fields, refused if it changed since you read it |
| A draft review comment, on the merge request or a diff line |
| Your unpublished review comments on a merge request |
| Delete one of your drafts |
| Publish all your drafts at once, with a summary and reviewer state |
| A file at a ref, bounded |
| A directory listing at a ref |
| A project's branches |
| Commits on a ref or a path |
| One commit and its diff, bounded |
| The commits and diffs between two refs, bounded |
| A project's tags |
| Create a branch from a ref |
| Commit file changes to a branch; never the default or a protected one |
| Who last changed each line of a file, bounded |
| Apply a commit to a branch; never the default or a protected one |
| Undo a commit on a branch with a new one; never the default or a protected one |
| A project's CI pipelines |
| One pipeline with the jobs that failed, trigger jobs included |
| A pipeline's jobs |
| A window of a job's log, secrets masked; the failing section on request |
| Check a project's CI configuration at a ref, or configuration you pass |
| The files a job kept as artifacts |
| One text file of a job's artifacts, secrets masked, bounded |
| The labels a project's issues and merge requests can carry |
| A project's or a group's milestones |
| Code, commits, comments and more, in a project, a group or everywhere |
| Your to-do items |
| Mark your to-do items done |
| Merge at the head you reviewed, or when the pipeline succeeds (Ship) |
| Approve at the head you reviewed (Ship) |
| Withdraw your approval (Ship) |
| Rebase a merge request's source branch, from the head you reviewed (Ship) |
| Move an issue to another project, never to one more people can see (Ship) |
| Run a pipeline for a ref, with variables whose values are never shown (Ship) |
| Retry a pipeline's failed and canceled jobs (Ship) |
| Run a finished job again, with inputs (Ship) |
| Start a manual job, with variables and inputs (Ship) |
| Cancel a running pipeline (Ship) |
| Delete a branch; never the default, a protected or an unmerged one unless asked (Destructive) |
| Delete one of your own comments (Destructive) |
| A project wiki's pages ( |
| One wiki page, bounded ( |
| Create a wiki page, or change one unchanged since you read it ( |
| Delete a wiki page ( |
| A project's snippets, or your own ( |
| One snippet and a file of it, bounded ( |
| Create a snippet, always private ( |
| A project's releases ( |
| One release and its notes ( |
| Create a release, and its tag at a ref, with asset links to the project's own pages ( |
| Create a tag at a ref; never a protected one ( |
| Delete a tag; never a protected one ( |
| Create a project label ( |
| Change a project label unchanged since you read it ( |
| Delete a project label ( |
| Create a project milestone ( |
| Change, close or reopen a milestone unchanged since you read it ( |
| Delete a project milestone ( |
| A project's environments and their last deployment ( |
| What was deployed where, and by which job ( |
| Recent activity, yours or a project's ( |
Ship and Destructive tools are registered only with the settings below,
and the six toolsets only when GITLAB_MCP_TOOLSETS names them.
Three resources carry the same text for clients that attach rather than call: an issue, a merge request and a job log.
Install
Download an archive for your platform from the releases page, or:
go install github.com/mmedum/gitlab-mcp/cmd/gitlab-mcp@latestClaude Desktop users can open the .mcpb bundle from the same release.
It does not log you in; do the steps below first.
Sign in
You bring your own OAuth application. Nothing is shipped in the binary, and there are no personal access tokens.
Register an application, once. On gitlab.com: your avatar → Edit profile → Applications (or a group's). Redirect URI
http://127.0.0.1/callback, Confidential unchecked, scopeapi(read_apifor read-only).docs/setup.mdhas the exact values.Log in from a terminal:
gitlab-mcp login --client-id <application id>It prints the scopes it will ask for, opens your browser, and stores the token in the OS keyring. On a machine without a browser,
--no-browserprints the URL and thessh -Lline to forward the callback.Check it:
gitlab-mcp doctordoctorwalks the connection, TLS, the sign-in, the application, the granted scopes and one call as you, and names what is missing.statusandlogoutdo what they say;--profilekeeps two gitlab.com logins side by side.
Connect a client
Claude Code:
claude mcp add gitlab -- gitlab-mcpAny client that takes a JSON server list:
{
"mcpServers": {
"gitlab": { "command": "gitlab-mcp" }
}
}Claude Desktop can instead open the .mcpb bundle from a release.
Configuration
Every setting is an environment variable with the GITLAB_MCP_ prefix
and a matching flag. docs/configuration.md lists them all.
Safety
GitLab content was written by someone other than you, and some of it is written to steer an agent. The server marks it as untrusted data, never fetches what it references, and nothing it adds tells the model to act on it.
What can be registered depends on the settings, because GitLab's api
scope cannot separate any of it:
Setting | Registers |
| Read tools only, with a |
default | Read and Write: issues, comments, reviews, branches, merge requests |
| adds merging, approving, running CI and releases |
| adds deletion, and each call must pass |
No quick actions. GitLab runs
/merge,/closeand the rest from a description or comment. Every body this server sends is checked, and a quick-action line is refused, or escaped when you ask.Protected branches. Code reaches the default branch or a protected branch only through a merge request; a direct commit there is refused.
No blind retries. A create that may or may not have happened is settled by reading, never by creating again.
The default token can still merge and approve; leaving Ship off stops
this server doing so, not anything else holding the token.
docs/security.md says more.
Verify a release
Each release signs checksums.txt with a keyless Sigstore certificate
and attests every archive and the bundle:
sha256sum -c checksums.txt --ignore-missing
cosign verify-blob checksums.txt --bundle checksums.txt.bundle \
--certificate-identity "https://github.com/mmedum/gitlab-mcp/.github/workflows/release.yml@refs/tags/<tag>" \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
gh attestation verify <archive> --repo mmedum/gitlab-mcpContributing
CONTRIBUTING.md. Security reports go through SECURITY.md, not an
issue.
License
Apache-2.0. See LICENSE and NOTICE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Task management for people and AI agents, with scoped OAuth access to issues, projects, and docs.
Task management for people and AI agents, with scoped OAuth access to issues, projects, and docs.
GitLab MCP — wraps the GitLab REST API v4 (BYO API key)
Getting Things Done (GTD) board for AI agents: capture to Inbox, next actions by context, projects, waiting-for, someday/maybe. Remote Streamable HTTP server with OAuth 2.1 login (passwordless email code). 16 tools + 4 prompts. Setup guide: https://gtdbrain.com/connect?source=glama
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables interaction with GitLab repositories through secure OAuth 2.0 authentication. Supports comprehensive GitLab operations including merge requests, issues, file management, commits, and branch operations through natural language.9 npmMIT
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants to interact with GitLab by wrapping the REST API v4 into executable tools for repository and branch management. It supports operations like creating projects, managing branches, and retrieving user information through the Model Context Protocol.11 npm1ISC
- AlicenseBqualityCmaintenanceProvides full control over GitLab epics, issues, merge requests, pipelines, and more via a conversational interface, with dry-run safety.1006 npm2MIT
- AlicenseNot gradedqualityFmaintenanceEnables AI assistants to interact with the GitLab API, providing over 1000 tools for managing groups, projects, users, and more through natural language.185 npmMIT