Connect through GitHub’s hosted MCP server at https://api.githubcopilot.com/mcp/. This is
the important change: the old @modelcontextprotocol/server-github npm package has been moved
to the servers-archived repository and is no longer maintained. Anthropic’s own MCP docs use
the hosted endpoint.
1. Create a fine-grained token
Go to github.com/settings/personal-access-tokens and generate a fine-grained token with access to only the repositories you need. Grant the permissions you’re actually comfortable handing an AI tool — read-only on contents and issues covers most of what people want.
2. Add the server
claude mcp add --transport http github https://api.githubcopilot.com/mcp/ \
--header "Authorization: Bearer YOUR_GITHUB_PAT"
What it does: registers the hosted server over HTTP and sends your token on every request.
--transport http is what tells Claude Code this is a URL, not a command to launch.
3. Pick the scope
claude mcp add --transport http github --scope user https://api.githubcopilot.com/mcp/ \
--header "Authorization: Bearer YOUR_GITHUB_PAT"
What it does: makes it available in every project instead of just this one. local (the
default) is you in this project; project writes a shared .mcp.json you commit — never put a
token in that one. Details in
installing any MCP server.
Prefer to self-host? GitHub also ships the same server as a container image,
ghcr.io/github/github-mcp-server, run over stdio with a GITHUB_PERSONAL_ACCESS_TOKEN
environment variable.
4. Confirm it connected
/mcp
What it does: shows the server’s health. You want ✔ Connected. Then try it:
Summarize the open issues labeled "bug" in this repo.
What it does: exercises a real tool call, which is the only proof the token has the access you think it has.
If it fails
! Needs authentication or a 401 means the token is wrong, expired, or lacks permission for
that repo. ✘ Failed to connect on a corporate network usually means an outbound proxy. MCP
servers load at session start, so a config change needs a new session, not a reload command.
Treat the token like a password. An MCP server acts with the access you give it, and issue text it returns enters your prompt — so never let a fetched issue body talk Claude into running something. Related: the best MCP servers to start with and Claude Code with GitHub Actions, which is the CI-side integration rather than the local one.
Source: Claude Code MCP documentation.