Back to Browse

Gitlab MCP Server

by Mmedum
Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

GitLab over MCP from your own account: issues, merge requests, reviews, the repository and CI.

About

GitLab over MCP from your own account: issues, merge requests, reviews, the repository and CI.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. Trust signals: trusted author (10/10 approved).

6 files analyzed · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

database

Check that this permission is expected for this type of plugin.

Documentation

View on GitHub

From the project's GitHub README.

gitlab-mcp

CI Release Go Reference License: Apache 2.0

An MCP server for gitlab.com. One binary over stdio, signed in as you. It works inside projects: issues, merge requests, reviews, the repository and CI. Instance and group administration, runners, CI variables and tokens are out of scope.

Unofficial, and not affiliated with GitLab Inc. See NOTICE.

What makes this one different

  • A small surface, gated by registration. About sixty tools rather than an API mirror, and a tool that is switched off is not registered, so it cannot be called at all.
  • Nothing it writes runs a quick action. /merge in a comment is refused or escaped, never executed.
  • Content is marked as untrusted. Issues, reviews, files and job logs come back inside boundaries the content cannot close.
  • Signs in like a desktop app. Your own OAuth application, a browser tab, the token in the OS keyring.
  • Verifiable releases. Signed checksums, build provenance and SBOMs.

Status

Stable: the release badge above names the newest tag, and CHANGELOG.md says what each one holds. The tool surface is a contract: tools keep their names and output fields. docs/architecture.md §16 is the plan.

Tools

ToolWhat it does
get_meWho is signed in, with which scopes, and what GitLab reports about itself
resolve_urlTurn a GitLab web URL into the arguments another tool takes, and name that tool
search_projectsFind projects by name, or within a group
get_projectOne project: default branch, visibility, what it has turned on
list_membersWho has access to a project, and with which role
find_usersAccounts by exact username or by name
search_issuesFind issues across gitlab.com, a group or a project
get_issueOne issue, its description marked as untrusted content, and its linked merge requests
create_issueCreate an issue; labels, assignees and milestone checked first
update_issueChange an issue's fields, refused if it changed since you read it
list_discussionsThe comment threads on an issue or a merge request
list_item_eventsAn issue's or a merge request's label, state, milestone and weight changes, newest first
add_commentComment on an issue or merge request, reply in a thread, or start one, on a diff line or not
update_commentEdit one of your own comments in place, in its thread and on its diff line
resolve_discussionResolve or reopen a thread on a merge request or an issue
link_issuesLink two issues, in one project or two
unlink_issuesRemove the link between two issues
search_merge_requestsFind merge requests across gitlab.com or a project
get_merge_requestOne merge request with its approvals and linked issues
list_mr_filesThe files a merge request changes, with line counts and GitLab's markers
get_mr_diffA merge request's diffs, file by file, bounded
list_mr_commitsA merge request's commits
create_merge_requestOpen a merge request from a branch
update_merge_requestChange a merge request's fields, refused if it changed since you read it
track_timeSet or reset an issue's or a merge request's time estimate, and add or reset its time spent
add_review_commentA draft review comment, on the merge request or a diff line
list_review_commentsYour unpublished review comments on a merge request
delete_review_commentDelete one of your drafts
submit_reviewPublish all your drafts at once, with a summary and reviewer state
get_fileA file at a ref, bounded
list_treeA directory listing at a ref
list_branchesA project's branches
list_commitsCommits on a ref or a path
get_commitOne commit and its diff, bounded, and the merge requests that contain it
compare_refsThe commits and diffs between two refs, bounded
list_tagsA project's tags
create_branchCreate a branch from a ref
create_commitCommit file changes to a branch; never the default or a protected one
get_blameWho last changed each line of a file, bounded
cherry_pick_commitApply a commit to a branch; never the default or a protected one
revert_commitUndo a commit on a branch with a new one; never the default or a protected one
list_pipelinesA project's CI pipelines
get_pipelineOne pipeline with the jobs that failed, trigger jobs included
list_jobsA pipeline's jobs
get_job_logA window of a job's log, secrets masked; the failing section on request
get_test_reportA pipeline's test counts and failed cases, secrets masked, bounded
lint_ciCheck a project's CI configuration at a ref, or configuration you pass
list_job_artifactsThe files a job kept as artifacts
get_job_artifactOne text file of a job's artifacts, secrets masked, bounded
list_labelsThe labels a project's issues and merge requests can carry
list_milestonesA project's or a group's milestones
list_boardsA project's issue boards and their lists, each with the search_issues arguments that read it
searchCode, commits, comments and more, in a project, a group or everywhere
list_todosYour to-do items
mark_todos_doneMark your to-do items done
add_todoAdd a to-do for yourself on an issue or a merge request
subscribeSubscribe to an issue's or a merge request's notifications, or unsubscribe
merge_merge_requestMerge at the head you reviewed, or when the pipeline succeeds (Ship)
approve_merge_requestApprove at the head you reviewed (Ship)
unapprove_merge_requestWithdraw your approval (Ship)
rebase_merge_requestRebase a merge request's source branch, from the head you reviewed (Ship)
move_issueMove an issue to another project, never to one more people can see (Ship)
run_pipelineRun a pipeline for a ref, with variables whose values are never shown (Ship)
retry_pipelineRetry a pipeline's failed and canceled jobs (Ship)
retry_jobRun a finished job again, with inputs (Ship)
play_jobStart a manual job, with variables and inputs (Ship)
cancel_pipelineCancel a running pipeline (Ship)
delete_branchDelete a branch; never the default, a protected or an unmerged one unless asked (Destructive)
delete_commentDelete one of your own comments (Destructive)
list_wiki_pagesA project wiki's pages (wiki toolset)
get_wiki_pageOne wiki page, bounded (wiki toolset)
save_wiki_pageCreate a wiki page, or change one unchanged since you read it (wiki toolset)
delete_wiki_pageDelete a wiki page (wiki toolset, Destructive)
list_snippetsA project's snippets, or your own (snippets toolset)
get_snippetOne snippet and a file of it, bounded (snippets toolset)
create_snippetCreate a snippet, always private (snippets toolset)
update_snippetChange one of your own private snippets: title, description, files; refused if it changed since you read it (snippets toolset)
delete_snippetDelete one of your own snippets (snippets toolset, Destructive)
list_releasesA project's releases (releases toolset)
get_releaseOne release and its notes (releases toolset)
create_releaseCreate a release, and its tag at a ref, with asset links to the project's own pages (releases toolset, Ship)
create_tagCreate a tag at a ref; never a protected one (releases toolset)
delete_tagDelete a tag; never a protected one (releases toolset, Destructive)
create_labelCreate a project label (planning toolset)
update_labelChange a project label unchanged since you read it (planning toolset)
delete_labelDelete a project label (planning toolset, Destructive)
create_milestoneCreate a project milestone (planning toolset)
update_milestoneChange, close or reopen a milestone unchanged since you read it (planning toolset)
delete_milestoneDelete a project milestone (planning toolset, Destructive)
list_environmentsA project's environments and their last deployment (deployments toolset)
list_deploymentsWhat was deployed where, and by which job (deployments toolset)
list_eventsRecent activity, yours or a project's (activity toolset)

Ship and Destructive tools are registered only with the settings below, and the six toolsets only when GITLAB_MCP_TOOLSETS names them.

Three resources carry the same text for clients that attach rather than call: an issue, a merge request and a job log.

Install

Download an archive for your platform from the releases page, or:

go install github.com/mmedum/gitlab-mcp/v2/cmd/gitlab-mcp@latest

Claude Desktop users can open the .mcpb bundle from the same release. It does not log you in; do the steps below first.

Sign in

You bring your own OAuth application. Nothing is shipped in the binary, and there are no personal access tokens.

  1. Register an application, once. On gitlab.com: your avatar → Edit profile → Applications (or a group's). Redirect URI http://127.0.0.1/callback, Confidential unchecked, scope api (read_api for read-only). docs/setup.md has the exact values.

  2. Log in from a terminal:

    gitlab-mcp login --client-id <application id>
    

    It prints the scopes it will ask for, opens your browser, and stores the token in the OS keyring. On a machine without a browser, --no-browser prints the URL and the ssh -L line to forward the callback.

  3. Check it:

    gitlab-mcp doctor
    

    doctor walks the connection, TLS, the sign-in, the application, the granted scopes and one call as you, and names what is missing. status and logout do what they say; --profile keeps two gitlab.com logins side by side.

Connect a client

Claude Code:

claude mcp add gitlab -- gitlab-mcp

Any client that takes a JSON server list:

{
  "mcpServers": {
    "gitlab": { "command": "gitlab-mcp" }
  }
}

Claude Desktop can instead open the .mcpb bundle from a release.

Configuration

Every setting is an environment variable with the GITLAB_MCP_ prefix and a matching flag. docs/configuration.md lists them all.

Safety

GitLab content was written by someone other than you, and some of it is written to steer an agent. The server marks it as untrusted data, never fetches what it references, and nothing it adds tells the model to act on it.

What can be registered depends on the settings, because GitLab's api scope cannot separate any of it:

SettingRegisters
GITLAB_MCP_READ_ONLY=trueRead tools only, with a read_api token
defaultRead and Write: issues, comments, reviews, branches, merge requests
GITLAB_MCP_ENABLE_SHIP=trueadds merging, approving, running CI and releases
GITLAB_MCP_ENABLE_DESTRUCTIVE=trueadds deletion, and each call must pass confirm: true

When your MCP client supports elicitation, the server also asks you before it merges, approves, runs a manual job or a pipeline on a protected ref, publishes a release or a tag, makes a confidential issue public, or deletes anything. Only your accept writes.

  • No quick actions. GitLab runs /merge, /close and the rest from a description or comment. Every body this server sends is checked, and a quick-action line is refused, or escaped when you ask.
  • Protected branches. Code reaches the default branch or a protected branch only through a merge request; a direct commit there is refused.
  • No blind retries. A create that may or may not have happened is settled by reading, never by creating again.

The default token can still merge and approve; leaving Ship off stops this server doing so, not anything else holding the token. docs/security.md says more.

Verify a release

Each release signs checksums.txt with a keyless Sigstore certificate and attests every archive and the bundle:

sha256sum -c checksums.txt --ignore-missing
cosign verify-blob checksums.txt --bundle checksums.txt.bundle \
  --certificate-identity "https://github.com/mmedum/gitlab-mcp/.github/workflows/release.yml@refs/tags/<tag>" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com
gh attestation verify <archive> --repo mmedum/gitlab-mcp

Contributing

CONTRIBUTING.md. Security reports go through SECURITY.md, not an issue.

License

Apache-2.0. See LICENSE and NOTICE.

Reviews

No reviews yet

Be the first to review this server!