CCM
/MCP
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic

Gitlab Mcp

zereight/gitlab-mcp
1.6k80 toolsauthSTDIOregistry active
Summary

The GitLab MCP Server provides comprehensive GitLab project management capabilities to AI clients through a Model Context Protocol interface, enabling operations on projects, merge requests, issues, pipelines, wiki, and releases. It offers multiple authentication methods including Personal Access Tokens, OAuth2 with browser-based flows, and remote authorization support, with compatibility across stdio, SSE, and HTTP transports for clients like Claude, VS Code, Cursor, and Copilot. The server solves the problem of giving AI assistants secure, authenticated access to GitLab resources while supporting various deployment scenarios from local desktop use to remote multi-user server deployments.

Install to Claude Code

verified
claude mcp add gitlab-mcp --env GITLAB_PERSONAL_ACCESS_TOKEN=YOUR_GITLAB_PERSONAL_ACCESS_TOKEN --env GITLAB_JOB_TOKEN=YOUR_GITLAB_JOB_TOKEN --env GITLAB_AUTH_COOKIE_PATH=YOUR_GITLAB_AUTH_COOKIE_PATH --env GITLAB_API_URL=https://gitlab.com/api/v4 --env GITLAB_ALLOWED_PROJECT_IDS=YOUR_GITLAB_ALLOWED_PROJECT_IDS --env GITLAB_READ_ONLY_MODE=false --env USE_GITLAB_WIKI=false --env GITLAB_TOOLSETS=YOUR_GITLAB_TOOLSETS --env GITLAB_TOOLS=YOUR_GITLAB_TOOLS --env GITLAB_DENIED_TOOLS_REGEX=YOUR_GITLAB_DENIED_TOOLS_REGEX --env GITLAB_TOOL_POLICY_APPROVE=YOUR_GITLAB_TOOL_POLICY_APPROVE --env GITLAB_TOOL_POLICY_HIDDEN=YOUR_GITLAB_TOOL_POLICY_HIDDEN --env NODE_TLS_REJECT_UNAUTHORIZED=YOUR_NODE_TLS_REJECT_UNAUTHORIZED --env GITLAB_CA_CERT_PATH=YOUR_GITLAB_CA_CERT_PATH -- npx -y @zereight/mcp-gitlab

Run in your terminal. Replace YOUR_* placeholders with real values; add --scope user to install for every project.

Review the command, arguments, and environment values before installing — MCP servers run with your local permissions.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
Email for Agents: Free tier availableEmail for Agents: Free tier available
Email for Agents: Free tier available
Give your AI agent a complete email layer—sending, inbound inboxes, and sandbox testing.
Get 4K emails/month free →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Capacitor makes coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
inference shell
inference shell
create and run specialised agents in minutes
build now →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
Email for Agents: Free tier availableEmail for Agents: Free tier available
Email for Agents: Free tier available
Give your AI agent a complete email layer—sending, inbound inboxes, and sandbox testing.
Get 4K emails/month free →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Capacitor makes coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
inference shell
inference shell
create and run specialised agents in minutes
build now →

Tools

Verified live against the running server on Jun 10, 2026.

verified live80 tools
merge_merge_requestMerge a merge request8 params

Merge a merge request

Parameters* required
squashboolean
Squash commits into a single commit when mergingdefault: false
auto_mergeboolean
If true, the merge request merges when the pipeline succeeds.default: false
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iidstring
The IID of a merge request
merge_commit_messagestring
Custom merge commit message
squash_commit_messagestring
Custom squash commit message
should_remove_source_branchboolean
Remove source branch after mergedefault: false
merge_when_pipeline_succeedsboolean
If true, the merge request merges when the pipeline succeeds.in GitLab 17.11. Usedefault: false
approve_merge_requestApprove a merge request4 params

Approve a merge request

Parameters* required
shastring
The HEAD of the merge request. Optional, but used to ensure the merge request hasn't changed since you last reviewed it
project_id*string
Project ID or complete URL-encoded path to project
approval_passwordstring
Current user's password. Required if 'Require user re-authentication to approve' is enabled in the project settings
merge_request_iid*string
The IID of the merge request to approve
unapprove_merge_requestUnapprove a merge request2 params

Unapprove a merge request

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of the merge request to unapprove
get_merge_request_approval_stateGet merge request approval details including approvers2 params

Get merge request approval details including approvers

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of the merge request
get_merge_request_conflictsGet the conflicts of a merge request2 params

Get the conflicts of a merge request

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of the merge request
list_merge_request_pipelinesList pipelines for a merge request with pagination4 params

List pipelines for a merge request with pagination

Parameters* required
pagenumber
Page number for pagination (default: 1)
per_pagenumber
Number of items per page (max: 100, default: 20)
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The internal ID of the merge request
create_or_update_fileCreate or update a file in a GitLab project8 params

Create or update a file in a GitLab project

Parameters* required
branch*string
Branch to create/update the file in
content*string
Content of the file
commit_idstring
Current file commit ID (for update operations)
file_path*string
Path where to create/update the file
project_id*string
Project ID or complete URL-encoded path to project
previous_pathstring
Path of the file to move/rename
commit_message*string
Commit message
last_commit_idstring
Last known file commit ID
search_repositoriesSearch for GitLab projects4 params

Search for GitLab projects

Parameters* required
pagenumber
Page number for pagination (default: 1)
querystring
Search query (alias for 'search')
searchstring
Search query
per_pagenumber
Number of items per page (max: 100, default: 20)
create_repositoryCreate a new GitLab project4 params

Create a new GitLab project

Parameters* required
name*string
Repository name
visibilitystring
Repository visibility levelone of private · internal · public
descriptionstring
Repository description
initialize_with_readmeboolean
Initialize with README.md
create_groupCreate new group or subgroup5 params

Create new group or subgroup

Parameters* required
name*string
The name of the group
path*string
The path of the group
parent_idnumber
The parent group ID for creating a subgroup
visibilitystring
The group's visibility levelone of private · internal · public
descriptionstring
The group's description
get_file_contentsGet contents of a file or directory from a GitLab project4 params

Get contents of a file or directory from a GitLab project

Parameters* required
refstring
Branch/tag/commit to get contents from
pathstring
Alias of file_path
file_pathstring
Path to the file or directory. Takes precedence over 'path' when both are provided
project_idstring
Project ID or URL-encoded path (optional; falls back to env)
push_filesPush multiple files in a single commit4 params

Push multiple files in a single commit

Parameters* required
files*array
Array of files to push
branch*string
Branch to push to
project_id*string
Project ID or complete URL-encoded path to project
commit_message*string
Commit message
create_issueCreate a new issue8 params

Create a new issue

Parameters* required
title*string
Issue title
labelsarray
Array of label names
weightnumber
Weight of the issue (numeric, typically hours of work)
issue_typestring
The type of issue. One of issue, incident, test_case or task.one of issue · incident · test_case · taskdefault: issue
project_id*string
Project ID or complete URL-encoded path to project
descriptionstring
Issue description
assignee_idsarray
Array of user IDs to assign
milestone_idstring
Milestone ID to assign
create_merge_requestCreate a new merge request13 params

Create a new merge request

Parameters* required
draftboolean
Create as draft merge request
title*string
Merge request title
labelsarray
Labels for the MR
squashboolean
If true, squash all commits into a single commit on merge.
project_id*string
Project ID or complete URL-encoded path to project
descriptionstring
Merge request description
assignee_idsarray
The ID of the users to assign the MR to
reviewer_idsarray
The ID of the users to assign as reviewers of the MR
source_branch*string
Branch containing changes
target_branch*string
Branch to merge into
target_project_idstring
Numeric ID of the target project.
allow_collaborationboolean
Allow commits from upstream members
remove_source_branchboolean
Flag indicating if a merge request should remove the source branch when merging.
fork_repositoryFork a project to your account or specified namespace2 params

Fork a project to your account or specified namespace

Parameters* required
namespacestring
Namespace to fork to (full path)
project_id*string
Project ID or complete URL-encoded path to project
create_branchCreate a new branch3 params

Create a new branch

Parameters* required
refstring
Source branch/commit for new branch
branch*string
Name for the new branch
project_id*string
Project ID or complete URL-encoded path to project
get_branchGet branch details (commit, protection status)2 params

Get branch details (commit, protection status)

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
branch_name*string
Name of the branch
list_branchesList branches in project with search filter4 params

List branches in project with search filter

Parameters* required
pagenumber
Page number for pagination (default: 1)
searchstring
Search term to filter branches by name
per_pagenumber
Number of items per page (max: 100, default: 20)
project_id*string
Project ID or complete URL-encoded path to project
delete_branchDelete branch from project2 params

Delete branch from project

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
branch_name*string
Name of the branch to delete
get_merge_requestGet details of a merge request (mergeRequestIid or branchName required)3 params

Get details of a merge request (mergeRequestIid or branchName required)

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
source_branchstring
Source branch name
merge_request_iidstring
The IID of a merge request
get_merge_request_diffsGet the changes/diffs of a merge request (mergeRequestIid or branchName required)5 params

Get the changes/diffs of a merge request (mergeRequestIid or branchName required)

Parameters* required
viewstring
Diff view typeone of inline · parallel
project_id*string
Project ID or complete URL-encoded path to project
source_branchstring
Source branch name
merge_request_iidstring
The IID of a merge request
excluded_file_patternsarray
Array of regex patterns to exclude files from the diff results. Each pattern is a JavaScript-compatible regular expression that matches file paths to ignore. Examples: ["^vendor/", "^test/mocks/", "\.spec\.ts$", "package-lock\.json"]
list_merge_request_changed_filesList changed file paths in a merge request without diff content (mergeRequestIid or branchName required)4 params

List changed file paths in a merge request without diff content (mergeRequestIid or branchName required)

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
source_branchstring
Source branch name
merge_request_iidstring
The IID of a merge request
excluded_file_patternsarray
Array of regex patterns to exclude files. Examples: ["^vendor/", "\.pb\.go$"]
list_merge_request_diffsList merge request diffs with pagination (mergeRequestIid or branchName required)6 params

List merge request diffs with pagination (mergeRequestIid or branchName required)

Parameters* required
pagenumber
Page number for pagination (default: 1)
unidiffboolean
Present diffs in the unified diff format. Default is false. Introduced in GitLab 16.5.
per_pagenumber
Number of items per page (max: 100, default: 20)
project_id*string
Project ID or complete URL-encoded path to project
source_branchstring
Source branch name
merge_request_iidstring
The IID of a merge request
get_merge_request_file_diffGet diffs for specific files from a merge request (mergeRequestIid or branchName required)5 params

Get diffs for specific files from a merge request (mergeRequestIid or branchName required)

Parameters* required
unidiffboolean
Present diff in the unified diff format. Default is false.
file_paths*array
List of file paths to retrieve diffs for (e.g. ['src/api/users.ts', 'src/repo/user.go']). Call list_merge_request_changed_files first to get the full list of changed paths.
project_id*string
Project ID or complete URL-encoded path to project
source_branchstring
Source branch name
merge_request_iidstring
The IID of a merge request
list_merge_request_versionsList all versions of a merge request2 params

List all versions of a merge request

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The internal ID of the merge request
get_merge_request_versionGet a specific version of a merge request4 params

Get a specific version of a merge request

Parameters* required
unidiffboolean
Present diffs in the unified diff format. Default is false. Introduced in GitLab 16.5.
project_id*string
Project ID or complete URL-encoded path to project
version_id*string
The ID of the merge request diff version
merge_request_iid*string
The internal ID of the merge request
get_branch_diffsGet diffs between two branches or commits5 params

Get diffs between two branches or commits

Parameters* required
to*string
The target branch or commit SHA to compare to
from*string
The base branch or commit SHA to compare from
straightboolean
Comparison method: false for '...' (default), true for '--'
project_id*string
Project ID or complete URL-encoded path to project
excluded_file_patternsarray
Array of regex patterns to exclude files from the diff results. Each pattern is a JavaScript-compatible regular expression that matches file paths to ignore. Examples: ["^vendor/", "^test/mocks/", "\.spec\.ts$", "package-lock\.json"]
update_merge_requestUpdate a merge request (mergeRequestIid or branchName required)13 params

Update a merge request (mergeRequestIid or branchName required)

Parameters* required
draftboolean
Work in progress merge request
titlestring
The title of the merge request
labelsarray
Labels for the MR
squashboolean
Squash commits into a single commit when merging
project_id*string
Project ID or complete URL-encoded path to project
descriptionstring
The description of the merge request
state_eventstring
New state (close/reopen) for the MRone of close · reopen
assignee_idsarray
The ID of the users to assign the MR to
reviewer_idsarray
The ID of the users to assign as reviewers of the MR
source_branchstring
Source branch name
target_branchstring
The target branch
merge_request_iidstring
The IID of a merge request
remove_source_branchboolean
Flag indicating if the source branch should be removed
create_noteCreate a new note (comment) to an issue or merge request4 params

Create a new note (comment) to an issue or merge request

Parameters* required
body*string
Note content
project_id*string
Project ID or namespace/project_path
noteable_iid*string
IID of the issue or merge request
noteable_type*string
Type of noteable (issue or merge_request)one of issue · merge_request
create_merge_request_threadCreate a new thread on a merge request5 params

Create a new thread on a merge request

Parameters* required
body*string
The content of the thread
positionobject
Position when creating a diff note
created_atstring
Date the thread was created at (ISO 8601 format)
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
resolve_merge_request_threadResolve a thread on a merge request4 params

Resolve a thread on a merge request

Parameters* required
resolved*boolean
Whether to resolve the thread
project_id*string
Project ID or complete URL-encoded path to project
discussion_id*string
The ID of a thread
merge_request_iid*string
The IID of a merge request
mr_discussionsList discussion items for a merge request4 params

List discussion items for a merge request

Parameters* required
pagenumber
Page number for pagination (default: 1)
per_pagenumber
Number of items per page (max: 100, default: 20)
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
delete_merge_request_discussion_noteDelete a discussion note on a merge request4 params

Delete a discussion note on a merge request

Parameters* required
note_id*string
The ID of a thread note
project_id*string
Project ID or complete URL-encoded path to project
discussion_id*string
The ID of a thread
merge_request_iid*string
The IID of a merge request
update_merge_request_discussion_noteUpdate a discussion note on a merge request6 params

Update a discussion note on a merge request

Parameters* required
bodystring
The content of the note or reply
note_idstring
The ID of a thread note
resolvedboolean
Resolve or unresolve the note
project_idstring
Project ID or complete URL-encoded path to project
discussion_idstring
The ID of a thread
merge_request_iidstring
The IID of a merge request
create_merge_request_discussion_noteAdd a new discussion note to an existing merge request thread5 params

Add a new discussion note to an existing merge request thread

Parameters* required
body*string
The content of the note or reply
created_atstring
Date the note was created at (ISO 8601 format)
project_id*string
Project ID or complete URL-encoded path to project
discussion_id*string
The ID of a thread
merge_request_iid*string
The IID of a merge request
create_merge_request_noteAdd a new note to a merge request3 params

Add a new note to a merge request

Parameters* required
body*string
The content of the note or reply
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
delete_merge_request_noteDelete an existing merge request note3 params

Delete an existing merge request note

Parameters* required
note_id*string
The ID of a thread note
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
get_merge_request_noteGet a specific note for a merge request3 params

Get a specific note for a merge request

Parameters* required
note_id*string
The ID of a thread note
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
get_merge_request_notesList notes for a merge request6 params

List notes for a merge request

Parameters* required
pagenumber
Page number for pagination
sortstring
The sort order of the notesone of asc · desc
order_bystring
The field to sort the notes byone of created_at · updated_at
per_pagenumber
Number of items per page
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
update_merge_request_noteModify an existing merge request note4 params

Modify an existing merge request note

Parameters* required
body*string
The content of the note or reply
note_id*string
The ID of a thread note
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
get_draft_noteGet a single draft note from a merge request3 params

Get a single draft note from a merge request

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
draft_note_id*string
The ID of the draft note
merge_request_iid*string
The IID of a merge request
list_draft_notesList draft notes for a merge request2 params

List draft notes for a merge request

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
create_draft_noteCreate a draft note for a merge request6 params

Create a draft note for a merge request

Parameters* required
body*string
The content of the draft note
positionobject
Position when creating a diff note
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
resolve_discussionboolean
Whether to resolve the discussion when publishing
in_reply_to_discussion_idstring
The ID of a discussion the draft note replies to
update_draft_noteUpdate an existing draft note6 params

Update an existing draft note

Parameters* required
bodystring
The content of the draft note
positionobject
Position when creating a diff note
project_id*string
Project ID or complete URL-encoded path to project
draft_note_id*string
The ID of the draft note
merge_request_iid*string
The IID of a merge request
resolve_discussionboolean
Whether to resolve the discussion when publishing
delete_draft_noteDelete a draft note3 params

Delete a draft note

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
draft_note_id*string
The ID of the draft note
merge_request_iid*string
The IID of a merge request
publish_draft_notePublish a single draft note3 params

Publish a single draft note

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
draft_note_id*string
The ID of the draft note
merge_request_iid*string
The IID of a merge request
bulk_publish_draft_notesPublish all draft notes for a merge request2 params

Publish all draft notes for a merge request

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
list_merge_request_emoji_reactionsList all emoji reactions on a merge request2 params

List all emoji reactions on a merge request

Parameters* required
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
list_merge_request_note_emoji_reactionsList all emoji reactions on a merge request note. Pass discussion_id for discussion thread replies.4 params

List all emoji reactions on a merge request note. Pass discussion_id for discussion thread replies.

Parameters* required
note_id*string
The ID of a note (comment or thread reply)
project_id*string
Project ID or complete URL-encoded path to project
discussion_idstring
The ID of a discussion thread. Required for notes that are discussion replies; omit for top-level notes.
merge_request_iid*string
The IID of a merge request
create_merge_request_emoji_reactionAdd an emoji reaction to a merge request (e.g. thumbsup, rocket, eyes)3 params

Add an emoji reaction to a merge request (e.g. thumbsup, rocket, eyes)

Parameters* required
name*string
Name of the emoji without colons (e.g. 'thumbsup', 'rocket', 'eyes')
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
delete_merge_request_emoji_reactionRemove an emoji reaction from a merge request3 params

Remove an emoji reaction from a merge request

Parameters* required
award_id*string
The ID of the emoji reaction to delete
project_id*string
Project ID or complete URL-encoded path to project
merge_request_iid*string
The IID of a merge request
create_merge_request_note_emoji_reactionAdd an emoji reaction to a merge request note. Pass discussion_id for discussion thread replies.5 params

Add an emoji reaction to a merge request note. Pass discussion_id for discussion thread replies.

Parameters* required
name*string
Name of the emoji without colons (e.g. 'thumbsup', 'rocket', 'eyes')
note_id*string
The ID of a note (comment or thread reply)
project_id*string
Project ID or complete URL-encoded path to project
discussion_idstring
The ID of a discussion thread. Required for notes that are discussion replies; omit for top-level notes.
merge_request_iid*string
The IID of a merge request
delete_merge_request_note_emoji_reactionRemove an emoji reaction from a merge request note. Pass discussion_id for discussion thread replies.5 params

Remove an emoji reaction from a merge request note. Pass discussion_id for discussion thread replies.

Parameters* required
note_id*string
The ID of a note (comment or thread reply)
award_id*string
The ID of the emoji reaction to delete
project_id*string
Project ID or complete URL-encoded path to project
discussion_idstring
The ID of a discussion thread. Required for notes that are discussion replies; omit for top-level notes.
merge_request_iid*string
The IID of a merge request
update_issue_noteModify an existing issue thread note6 params

Modify an existing issue thread note

Parameters* required
bodystring
The content of the note or reply
note_idstring
The ID of a thread note
resolvedboolean
Resolve or unresolve the note
issue_iidstring
The IID of an issue
project_idstring
Project ID or complete URL-encoded path to project
discussion_idstring
The ID of a thread
create_issue_noteAdd a note to an issue, optionally replying to a discussion thread5 params

Add a note to an issue, optionally replying to a discussion thread

Parameters* required
body*string
The content of the note or reply
issue_iid*string
The IID of an issue
created_atstring
Date the note was created at (ISO 8601 format)
project_id*string
Project ID or complete URL-encoded path to project
discussion_idstring
The ID of a thread. If provided, replies to that thread; otherwise creates a top-level note
list_issue_emoji_reactionsList all emoji reactions on an issue2 params

List all emoji reactions on an issue

Parameters* required
issue_iid*string
The IID of an issue
project_id*string
Project ID or complete URL-encoded path to project
list_issue_note_emoji_reactionsList all emoji reactions on an issue note. Pass discussion_id for discussion thread replies.4 params

List all emoji reactions on an issue note. Pass discussion_id for discussion thread replies.

Parameters* required
note_id*string
The ID of a note (comment or thread reply)
issue_iid*string
The IID of an issue
project_id*string
Project ID or complete URL-encoded path to project
discussion_idstring
The ID of a discussion thread. Required for notes that are discussion replies; omit for top-level notes.
create_issue_emoji_reactionAdd an emoji reaction to an issue (e.g. thumbsup, rocket, eyes)3 params

Add an emoji reaction to an issue (e.g. thumbsup, rocket, eyes)

Parameters* required
name*string
Name of the emoji without colons (e.g. 'thumbsup', 'rocket', 'eyes')
issue_iid*string
The IID of an issue
project_id*string
Project ID or complete URL-encoded path to project
delete_issue_emoji_reactionRemove an emoji reaction from an issue3 params

Remove an emoji reaction from an issue

Parameters* required
award_id*string
The ID of the emoji reaction to delete
issue_iid*string
The IID of an issue
project_id*string
Project ID or complete URL-encoded path to project
create_issue_note_emoji_reactionAdd an emoji reaction to an issue note. Pass discussion_id for discussion thread replies.5 params

Add an emoji reaction to an issue note. Pass discussion_id for discussion thread replies.

Parameters* required
name*string
Name of the emoji without colons (e.g. 'thumbsup', 'rocket', 'eyes')
note_id*string
The ID of a note (comment or thread reply)
issue_iid*string
The IID of an issue
project_id*string
Project ID or complete URL-encoded path to project
discussion_idstring
The ID of a discussion thread. Required for notes that are discussion replies; omit for top-level notes.
delete_issue_note_emoji_reactionRemove an emoji reaction from an issue note. Pass discussion_id for discussion thread replies.5 params

Remove an emoji reaction from an issue note. Pass discussion_id for discussion thread replies.

Parameters* required
note_id*string
The ID of a note (comment or thread reply)
award_id*string
The ID of the emoji reaction to delete
issue_iid*string
The IID of an issue
project_id*string
Project ID or complete URL-encoded path to project
discussion_idstring
The ID of a discussion thread. Required for notes that are discussion replies; omit for top-level notes.
list_issuesList issues (default: created by current user; use scope='all' for all)21 params

List issues (default: created by current user; use scope='all' for all)

Parameters* required
pagenumber
Page number for pagination (default: 1)
scopestring
Return issues from a specific scopeone of created_by_me · assigned_to_me · all
statestring
Return issues with a specific stateone of opened · closed · all
labelsarray
Array of label names
searchstring
Search for specific terms
due_datestring
Return issues that have the due date
per_pagenumber
Number of items per page (max: 100, default: 20)
author_idstring
Return issues created by the given user ID
milestonestring
Milestone title
issue_typestring
Filter to a given type of issue. One of issue, incident, test_case or taskone of issue · incident · test_case · task
project_idstring
Project ID or URL-encoded path (optional - if not provided, lists issues across all accessible projects)
assignee_idstring
Return issues assigned to the given user ID. user id or none or any
confidentialboolean
Filter confidential or public issues
iteration_idstring
Return issues assigned to the given iteration ID. None returns issues that do not belong to an iteration. Any returns issues that belong to an iteration.
created_afterstring
Return issues created after the given time
updated_afterstring
Return issues updated after the given time
created_beforestring
Return issues created before the given time
updated_beforestring
Return issues updated before the given time
author_usernamestring
Return issues created by the given username
assignee_usernamearray
Return issues assigned to the given username
with_labels_detailsboolean
Return more details for each label
my_issuesList issues assigned to the authenticated user11 params

List issues assigned to the authenticated user

Parameters* required
pagenumber
Page number for pagination (default: 1)
statestring
Return issues with a specific state (default: opened)one of opened · closed · all
labelsarray
Array of label names to filter by
searchstring
Search for specific terms in title and description
per_pagenumber
Number of items per page (default: 20, max: 100)
milestonestring
Milestone title to filter by
project_idstring
Project ID or URL-encoded path (optional when GITLAB_PROJECT_ID is set)
created_afterstring
Return issues created after the given time (ISO 8601)
updated_afterstring
Return issues updated after the given time (ISO 8601)
created_beforestring
Return issues created before the given time (ISO 8601)
updated_beforestring
Return issues updated before the given time (ISO 8601)
get_issueGet details of a specific issue2 params

Get details of a specific issue

Parameters* required
issue_iid*string
The internal ID of the project issue
project_id*string
Project ID or URL-encoded path
update_issueUpdate an issue13 params

Update an issue

Parameters* required
titlestring
The title of the issue
labelsarray
Array of label names
weightnumber
Weight of the issue (numeric, typically hours of work)
due_datestring
Date the issue is due (YYYY-MM-DD)
issue_iid*string
The internal ID of the project issue
issue_typestring
The type of issue. One of issue, incident, test_case or task.one of issue · incident · test_case · task
project_id*string
Project ID or URL-encoded path
descriptionstring
The description of the issue
state_eventstring
Update issue state (close/reopen)one of close · reopen
assignee_idsarray
Array of user IDs to assign issue to
confidentialboolean
Set the issue to be confidential
milestone_idstring
Milestone ID to assign
discussion_lockedboolean
Flag to lock discussions
update_issue_description_patchApply a patch (search/replace or unified diff) to an issue description. Reduces token usage by allowing small changes without sending the full description. Supports dry_run to preview changes and create_note to summarize updates.7 params

Apply a patch (search/replace or unified diff) to an issue description. Reduces token usage by allowing small changes without sending the full description. Supports dry_run to preview changes and create_note to summarize updates.

Parameters* required
patch*string
The patch content to apply to the issue description
dry_runboolean
If true, preview changes without updating the issue
issue_iid*string
The internal ID of the project issue
patch_type*string
Type of patch format to applyone of search_replace · unified_diff
project_id*string
Project ID or URL-encoded path
create_noteboolean
If true, add a note summarizing the change after update
allow_multipleboolean
For search_replace: allow multiple matches to all be replaced (default: false — fail on duplicate)
delete_issueDelete an issue2 params

Delete an issue

Parameters* required
issue_iid*string
The internal ID of the project issue
project_id*string
Project ID or URL-encoded path
list_todosList GitLab to-do items for the current user8 params

List GitLab to-do items for the current user

Parameters* required
pagenumber
Page number for pagination (default: 1)
typestring
Filter by to-do target typeone of Issue · MergeRequest · Commit · Epic · DesignManagement::Design · AlertManagement::Alert
statestring
Filter by to-do stateone of pending · done
actionstring
Filter by to-do actionone of assigned · mentioned · build_failed · marked · approval_required · unmergeable
group_idnumber
Filter by group ID
per_pagenumber
Number of items per page (max: 100, default: 20)
author_idnumber
Filter by author ID
project_idnumber
Filter by project ID
mark_todo_doneMark a GitLab to-do item as done1 params

Mark a GitLab to-do item as done

Parameters* required
id*number
The ID of the to-do item
mark_all_todos_doneMark all pending GitLab to-do items as done for the current user

Mark all pending GitLab to-do items as done for the current user

No parameters — call it with no arguments.

list_issue_linksList all issue links for a specific issue2 params

List all issue links for a specific issue

Parameters* required
issue_iid*string
The internal ID of a project's issue
project_id*string
Project ID or URL-encoded path
list_issue_discussionsList discussions for an issue4 params

List discussions for an issue

Parameters* required
pagenumber
Page number for pagination (default: 1)
per_pagenumber
Number of items per page (max: 100, default: 20)
issue_iid*string
The internal ID of the project issue
project_id*string
Project ID or URL-encoded path
get_issue_linkGet a specific issue link3 params

Get a specific issue link

Parameters* required
issue_iid*string
The internal ID of a project's issue
project_id*string
Project ID or URL-encoded path
issue_link_id*string
ID of an issue relationship
create_issue_linkCreate an issue link between two issues5 params

Create an issue link between two issues

Parameters* required
issue_iid*string
The internal ID of a project's issue
link_typestring
The type of the relation, defaults to relates_toone of relates_to · blocks · is_blocked_by
project_id*string
Project ID or URL-encoded path
target_issue_iid*string
The internal ID of a target project's issue
target_project_id*string
The ID or URL-encoded path of a target project
delete_issue_linkDelete an issue link3 params

Delete an issue link

Parameters* required
issue_iid*string
The internal ID of a project's issue
project_id*string
Project ID or URL-encoded path
issue_link_id*string
The ID of an issue relationship
list_namespacesList all namespaces (users and groups) available to the current user. Filter by kind='group' for groups only.4 params

List all namespaces (users and groups) available to the current user. Filter by kind='group' for groups only.

Parameters* required
pagenumber
Page number for pagination (default: 1)
ownedboolean
Filter for namespaces owned by current user
searchstring
Search term for namespaces
per_pagenumber
Number of items per page (max: 100, default: 20)
get_namespaceGet details of a namespace (user or group) by ID or path. Groups are namespaces with kind='group'.1 params

Get details of a namespace (user or group) by ID or path. Groups are namespaces with kind='group'.

Parameters* required
namespace_id*string
Namespace ID or full path
verify_namespaceVerify if a namespace path exists1 params

Verify if a namespace path exists

Parameters* required
path*string
Namespace path to verify
get_projectGet details of a specific project1 params

Get details of a specific project

Parameters* required
project_id*string
Project ID or URL-encoded path
list_projectsList projects accessible by the current user15 params

List projects accessible by the current user

Parameters* required
pagenumber
Page number for pagination (default: 1)
sortstring
Return projects sorted in ascending or descending orderone of asc · desc
ownedboolean
Filter for projects owned by current user
topicstring
Filter by topic (projects tagged with this topic)
searchstring
Search term for projects
simpleboolean
Return only limited fields
archivedboolean
Filter for archived projects
order_bystring
Return projects ordered by fieldone of id · name · path · created_at · updated_at · last_activity_at
per_pagenumber
Number of items per page (max: 100, default: 20)
membershipboolean
Filter for projects where current user is a member
visibilitystring
Filter by project visibilityone of public · internal · private
min_access_levelnumber
Filter by minimum access level
search_namespacesboolean
Needs to be true if search is full path
with_issues_enabledboolean
Filter projects with issues feature enabled
with_merge_requests_enabledboolean
Filter projects with merge requests feature enabled

GitLab MCP Server

MCP Toplist

English | 한국어 | 简体中文

📖 Documentation → Setup guides, environment variables, and the full tool reference live on the hosted docs site.

Star History Chart

@zereight/mcp-gitlab

A comprehensive GitLab MCP server for AI clients. Manage projects, merge requests, issues, pipelines, wiki, releases, tags, milestones, and more through stdio, SSE, and Streamable HTTP.

Supports PAT, OAuth, read-only mode, dynamic API URLs, and remote authorization for VS Code, Claude, Cursor, Copilot, and other MCP clients.

Why use this GitLab MCP?

  • Broad GitLab coverage — projects, repository browsing, merge requests, issues, pipelines, wiki, releases, tags, labels, milestones, and more
  • Flexible auth — Personal Access Token, local OAuth2 browser flow, MCP OAuth proxy, and per-request remote authorization
  • Multiple transports — stdio for local clients, SSE for legacy clients, and Streamable HTTP for modern remote deployments
  • Client-friendly setup — examples for Claude Code, Codex, Antigravity, OpenCode, Copilot, Cline, Roo Code, Cursor, Kilo Code, and Amp Code
  • Self-hosted ready — works with custom GitLab instances, proxy settings, and dynamic API URL routing

Quick start: choose either Personal Access Token or OAuth2 setup below, install @zereight/mcp-gitlab, and use zereight-mcp-gitlab in your MCP client configuration.

Client Setup Guides

  • Claude Code Setup Guide
  • VS Code Setup Guide
  • GitHub Copilot Setup Guide
  • Codex Setup Guide
  • Cursor Setup Guide
  • JSON-Based MCP Clients Setup Guide - for Factory AI Droid, OpenClaw, and OpenCode style clients
  • OAuth2 Authentication Setup Guide
  • Environment Variables Reference
  • Stateless Mode — Multi-Pod HPA
  • Custom Agents and Multiple PAT Setup

Usage

Setup Overview

Authentication Methods

The server supports four authentication methods:

For local/desktop use (most common):

  1. Personal Access Token (GITLAB_PERSONAL_ACCESS_TOKEN) — simplest setup
  2. OAuth2 — Local Browser (GITLAB_USE_OAUTH) — recommended for better security

For server/remote deployments:

  1. OAuth2 — MCP Proxy (GITLAB_MCP_OAUTH) — for remote MCP clients such as Claude.ai
  2. Remote Authorization (REMOTE_AUTHORIZATION) — multi-user deployments where each caller provides their own token

Quick setup paths

  • Claude Code: see Claude Code Setup Guide
  • VS Code: see VS Code Setup Guide
  • GitHub Copilot: see GitHub Copilot Setup Guide
  • Codex: see Codex Setup Guide
  • Cursor: see Cursor Setup Guide
  • Factory AI Droid / OpenClaw / OpenCode style clients: see JSON-Based MCP Clients Setup Guide
  • OAuth browser flow details: see OAuth2 Authentication Setup Guide

For the simplest local setup, start with a Personal Access Token. For browser-based local auth, use OAuth2. For remote or multi-user deployments, continue to the MCP OAuth and Remote Authorization sections later in this README.

Install the server once:

brew tap zereight/gitlab-mcp https://github.com/zereight/gitlab-mcp
brew install zereight/gitlab-mcp/zereight-mcp-gitlab

Or with npm:

npm install -g @zereight/mcp-gitlab

The examples use zereight-mcp-gitlab, a less collision-prone alias for the legacy mcp-gitlab binary. If your MCP client cannot find it, use the absolute path from which zereight-mcp-gitlab.

No global install? Pin npx to the previous stable release (the version these docs recommend), for example npx -y @zereight/mcp-gitlab@2.1.45. If you always want the newest release, use npx -y @zereight/mcp-gitlab@latest instead. The server prints a notice to stderr on startup when a newer version is available (disable with GITLAB_DISABLE_VERSION_CHECK=true).

Using CLI Arguments (for clients with env var issues)

Some MCP clients (like GitHub Copilot CLI) have issues with environment variables. Use CLI arguments instead:

{
  "mcpServers": {
    "gitlab": {
      "command": "zereight-mcp-gitlab",
      "args": ["--token=YOUR_GITLAB_TOKEN", "--api-url=https://gitlab.com/api/v4"],
      "tools": ["*"]
    }
  }
}

Available CLI arguments:

  • --token - GitLab Personal Access Token (replaces GITLAB_PERSONAL_ACCESS_TOKEN)
  • --api-url - GitLab API URL (replaces GITLAB_API_URL)
  • --read-only=true - Enable read-only mode (replaces GITLAB_READ_ONLY_MODE, deprecated — prefer --permission-mode=readonly)
  • --permission-mode - Permission level: readonly, modify (no delete tools), or full (replaces GITLAB_PERMISSION_MODE, default full)
  • --use-wiki=true - Enable wiki API (replaces USE_GITLAB_WIKI, legacy — prefer GITLAB_TOOLSETS=wiki)
  • --use-milestone=true - Enable milestone API (replaces USE_MILESTONE, legacy — prefer GITLAB_TOOLSETS=milestones)
  • --use-pipeline=true - Enable pipeline API (replaces USE_PIPELINE, legacy — prefer GITLAB_TOOLSETS=pipelines)
  • --disable-version-check=true - Disable the startup new-version notice (replaces GITLAB_DISABLE_VERSION_CHECK)

CLI arguments take precedence over environment variables.

Fine-grained tool filtering: use GITLAB_PERMISSION_MODE=modify to allow create/update while blocking every delete tool (including delete mutations through execute_graphql), or GITLAB_PERMISSION_MODE=readonly for read-only access. You can also enable toolset groups with GITLAB_TOOLSETS=<group,…>, allow-list individual tools with GITLAB_TOOLS=<tool,…> (e.g. read-only groups plus a few specific write tools), and deny-list by pattern with GITLAB_DENIED_TOOLS_REGEX. The legacy USE_GITLAB_WIKI / USE_MILESTONE / USE_PIPELINE flags are kept for backward compatibility only. See Tools Reference and Environment Variables.

  • sse
docker run -i --rm \
  -e HOST=0.0.0.0 \
  -e GITLAB_PERSONAL_ACCESS_TOKEN=your_gitlab_token \
  -e GITLAB_API_URL="https://gitlab.com/api/v4" \
  -e GITLAB_PERMISSION_MODE=readonly \
  -e GITLAB_TOOLSETS=wiki,milestones,pipelines \
  -e SSE=true \
  -e SSE_AUTH_TOKEN=your_mcp_sse_token \
  -p 3333:3002 \
  zereight050/gitlab-mcp
{
  "mcpServers": {
    "gitlab": {
      "type": "sse",
      "url": "http://localhost:3333/sse",
      "headers": {
        "Authorization": "Bearer your_mcp_sse_token"
      }
    }
  }
}
  • streamable-http
docker run -i --rm \
  -e HOST=0.0.0.0 \
  -e REMOTE_AUTHORIZATION=true \
  -e GITLAB_API_URL="https://gitlab.com/api/v4" \
  -e GITLAB_PERMISSION_MODE=readonly \
  -e GITLAB_TOOLSETS=wiki,milestones,pipelines \
  -e STREAMABLE_HTTP=true \
  -p 3333:3002 \
  zereight050/gitlab-mcp
{
  "mcpServers": {
    "gitlab": {
      "type": "streamable-http",
      "url": "http://localhost:3333/mcp",
      "headers": {
        "Authorization": "Bearer glpat-..."
      }
    }
  }
}

Using MCP OAuth Proxy (GITLAB_MCP_OAUTH)

For server/remote deployments only. This mode requires the MCP server to be deployed with a publicly accessible HTTPS URL. For local/desktop use, see GITLAB_USE_OAUTH above.

For remote MCP clients that support the MCP OAuth specification (e.g. Claude.ai). The server acts as a full OAuth 2.0 authorization server — unauthenticated requests receive a 401 + WWW-Authenticate response, which triggers the OAuth browser flow automatically on the client side.

Remote MCP clients such as OpenCode, MCPJam, and Claude.ai can send their own callback URL during authorization. If you cannot register every client callback URL in GitLab, enable GITLAB_OAUTH_CALLBACK_PROXY=true. With callback proxy mode, GitLab only needs one registered redirect URI: {MCP_SERVER_URL}/callback.

GITLAB_OAUTH_REDIRECT_URI is for local OAuth (GITLAB_USE_OAUTH) only. It does not override remote MCP OAuth client callback URLs and should not be used to fix remote Unregistered redirect_uri errors.

This variable exists because the local OAuth flow starts a browser on the same machine as the MCP server and listens for the callback on a local HTTP server, for example http://127.0.0.1:8888/callback.

Remote MCP OAuth is different. In GITLAB_MCP_OAUTH=true mode, the MCP client provides its own callback URL during /authorize. GITLAB_OAUTH_REDIRECT_URI does not replace that client-provided URL.

ModeEnable withCallback variableGitLab redirect URI
Local OAuthGITLAB_USE_OAUTH=trueGITLAB_OAUTH_REDIRECT_URIhttp://127.0.0.1:8888/callback or your local callback
Remote MCP OAuthGITLAB_MCP_OAUTH=trueGITLAB_OAUTH_CALLBACK_PROXY=true{MCP_SERVER_URL}/callback

Use GITLAB_OAUTH_REDIRECT_URI only when the MCP server itself owns the local browser callback. Use GITLAB_OAUTH_CALLBACK_PROXY=true when a remote MCP client owns the callback URL.

How it works: You deploy this MCP server somewhere with a public HTTPS URL. MCP clients connect to {MCP_SERVER_URL}/mcp. The server handles the OAuth 2.0 flow, exchanging credentials with GitLab on behalf of the client.

Prerequisites:

  1. A publicly accessible HTTPS server URL (MCP_SERVER_URL) — use ngrok for local testing
  2. A pre-registered GitLab OAuth application with api (or read_api) scopes — Go to Admin area → Applications, set Redirect URI to {MCP_SERVER_URL}/callback
Environment VariableRequiredDescription
GITLAB_MCP_OAUTH✅Set to true to enable
GITLAB_API_URL✅GitLab API base URL
GITLAB_OAUTH_APP_ID✅GitLab OAuth Application ID
MCP_SERVER_URL✅Public HTTPS URL of this MCP server
STREAMABLE_HTTP✅Must be true
GITLAB_OAUTH_CALLBACK_PROXYoptionalSet to true to use the MCP server's fixed /callback URL
GITLAB_OAUTH_SCOPESoptionalComma-separated scopes (default: api,read_api,read_user)
GITLAB_OAUTH_ALLOWED_GROUPSoptionalComma-separated group full paths — only members (and subgroup members) may obtain a token (replaces deprecated GITLAB_ALLOWED_GROUPS)

When STREAMABLE_HTTP=true, server-side GitLab credentials (GITLAB_PERSONAL_ACCESS_TOKEN, GITLAB_JOB_TOKEN, GITLAB_AUTH_COOKIE_PATH, or GITLAB_USE_OAUTH) require REMOTE_AUTHORIZATION=true, GITLAB_MCP_OAUTH=true, or STREAMABLE_HTTP_AUTH_TOKEN.

Troubleshooting Unregistered redirect_uri

Check the redirect_uri in the browser URL. If it points to a client callback such as http://127.0.0.1:xxxxx/.../callback, enable:

GITLAB_OAUTH_CALLBACK_PROXY=true

Do not fix remote MCP OAuth by changing GITLAB_OAUTH_REDIRECT_URI. That variable is for local OAuth (GITLAB_USE_OAUTH) only.

docker run -i --rm \
  -e HOST=0.0.0.0 \
  -e GITLAB_MCP_OAUTH=true \
  -e GITLAB_OAUTH_CALLBACK_PROXY=true \
  -e STREAMABLE_HTTP=true \
  -e MCP_SERVER_URL=https://your-server.example.com \
  -e GITLAB_API_URL="https://gitlab.com/api/v4" \
  -e GITLAB_OAUTH_APP_ID=your_app_id \
  -p 3000:3002 \
  zereight050/gitlab-mcp

MCP client configuration:

{
  "mcpServers": {
    "gitlab": {
      "type": "http",
      "url": "https://your-server.example.com/mcp"
    }
  }
}

Using Remote Authorization (REMOTE_AUTHORIZATION)

For server/remote deployments only. Each HTTP caller provides their own GitLab token directly in request headers — no OAuth flow involved.

For multi-user or multi-tenant deployments where each caller provides their own GitLab token in the HTTP request header. No OAuth flow — the MCP server forwards the token to GitLab on behalf of the caller.

Header priority: Private-Token > JOB-TOKEN > Authorization: Bearer

Environment VariableRequiredDescription
REMOTE_AUTHORIZATION✅Set to true to enable
STREAMABLE_HTTP✅Must be true
ENABLE_DYNAMIC_API_URLoptionalAllow per-request GitLab URL via X-GitLab-API-URL header
GITLAB_ALLOWED_HOSTSoptionalComma-separated allowed X-GitLab-API-URL hosts; GITLAB_API_URL hosts are always allowed
GITLAB_ALLOW_UNAUTHENTICATED_TOOL_DISCOVERYoptionalAllow unauthenticated initialize, notifications/initialized, and tools/list only (tool calls still require auth)
MCP_SERVER_URL / MCP_ALLOWED_HOSTS / MCP_ALLOWED_ORIGINSoptionalAllowed public /mcp host/origin values for DNS rebinding protection
MCP_TRUST_PROXYoptionalTrust Forwarded / X-Forwarded-* headers behind a reverse proxy (download URLs, Express req.ip, /mcp IP rate limits, OAuth rate limits)

GITLAB_ALLOW_UNAUTHENTICATED_TOOL_DISCOVERY=true is intended for MCP gateways or admin UIs that need to inspect tool metadata before a user provides a GitLab token. Leave it disabled unless the tool list is safe to expose in your deployment.

When MCP_SERVER_URL is not set, remote download URLs fall back to the local server address. Set MCP_TRUST_PROXY=true only if the server is reachable through a trusted reverse proxy and direct client access to the MCP server is blocked. This enables Express trust proxy for Streamable HTTP and SSE, derives public download URLs from Forwarded / X-Forwarded-Proto / X-Forwarded-Host / X-Forwarded-Prefix, and keeps OAuth endpoint rate limiting working when proxies send X-Forwarded-For with a client port (for example 1.2.3.4:5678). Existing OAuth+proxy deployments must set this explicitly after the flag was introduced.

Example request headers:

Private-Token: glpat-xxxxxxxxxxxxxxxxxxxx

or using a Bearer token:

Authorization: Bearer glpat-xxxxxxxxxxxxxxxxxxxx

⚠️ REMOTE_AUTHORIZATION is not compatible with SSE transport. STREAMABLE_HTTP=true is required.

Environment Variables

Use the dedicated reference for the full environment variable list:

  • Environment Variables Reference

Most users only need one of these starting sets:

  • Local PAT: GITLAB_PERSONAL_ACCESS_TOKEN, GITLAB_API_URL
  • Local OAuth: GITLAB_USE_OAUTH=true, GITLAB_OAUTH_CLIENT_ID, GITLAB_OAUTH_REDIRECT_URI, GITLAB_API_URL
  • Remote multi-user HTTP: STREAMABLE_HTTP=true, REMOTE_AUTHORIZATION=true (or GITLAB_MCP_OAUTH=true), MCP_TRUST_PROXY=true (behind a reverse proxy), MAX_REQUESTS_PER_MINUTE=300, MCP_SERVER_URL or MCP_ALLOWED_HOSTS, HOST, PORT
  • Multiple side-by-side deployments: set a distinct MCP_SERVER_NAME per instance (e.g. gitlab-selfhosted-readonly) so clients, logs, and telemetry can tell them apart
  • Multi-pod HPA (stateless): above + OAUTH_STATELESS_MODE=true, OAUTH_STATELESS_SECRET (same across all pods). See Stateless Mode.

Commonly referenced variables:

  • GITLAB_API_URL
  • GITLAB_PERSONAL_ACCESS_TOKEN
  • GITLAB_USE_OAUTH
  • REMOTE_AUTHORIZATION
  • MCP_TRUST_PROXY
  • MAX_REQUESTS_PER_MINUTE
  • MAX_SESSIONS
  • MCP_ALLOWED_HOSTS
  • MCP_ALLOWED_ORIGINS
  • GITLAB_MCP_OAUTH
  • GITLAB_OAUTH_CALLBACK_PROXY
  • OAUTH_REGISTER_RATE_LIMIT_PER_HOUR
  • OAUTH_STATELESS_MODE
  • OAUTH_STATELESS_SECRET

The reference document also covers:

  • auth and OAuth variables
  • MCP OAuth proxy variables
  • project and tool filtering variables
  • dynamic tool discovery via discover_tools (on-demand toolset activation)
  • transport and session variables
  • proxy and TLS variables

For callback proxy mode details, see GitLab MCP OAuth Callback Proxy.

Remote Authorization Setup (Multi-User Support)

When using REMOTE_AUTHORIZATION=true, the MCP server can support multiple users, each with their own GitLab token passed via HTTP headers. This is useful for:

  • Shared MCP server instances where each user needs their own GitLab access
  • IDE integrations that can inject user-specific tokens into MCP requests

Setup Example:

# Start server with remote authorization
docker run -d \
  -e HOST=0.0.0.0 \
  -e STREAMABLE_HTTP=true \
  -e REMOTE_AUTHORIZATION=true \
  -e GITLAB_API_URL="https://gitlab.com/api/v4" \
  -e GITLAB_PERMISSION_MODE=readonly \
  -e SESSION_TIMEOUT_SECONDS=3600 \
  -p 3333:3002 \
  zereight050/gitlab-mcp

Client Configuration:

Your IDE or MCP client must send one of these headers with each request:

Authorization: Bearer glpat-xxxxxxxxxxxxxxxxxxxx

or

Private-Token: glpat-xxxxxxxxxxxxxxxxxxxx

The token is stored per session (identified by mcp-session-id header) and reused for subsequent requests in the same session.

Remote Authorization Client Configuration Example with Cursor

{
  "mcpServers": {
    "GitLab": {
      "url": "http(s)://<your_mcp_gitlab_server>/mcp",
      "headers": {
        "Authorization": "Bearer glpat-..."
      }
    }
  }
}

Important Notes:

  • Remote authorization only works with Streamable HTTP transport
  • Each session is isolated - tokens from one session cannot access another session's data Tokens are automatically cleaned up when sessions close
  • Session timeout: Auth tokens expire after SESSION_TIMEOUT_SECONDS (default 1 hour) of inactivity. After timeout, the client must send auth headers again. The transport session remains active.
  • Each request resets the timeout timer for that session
  • Rate limiting: /mcp requests are limited to MAX_REQUESTS_PER_MINUTE per client IP, and per MCP session when using OAuth or remote authorization (default 60). See environment-variables.md.
  • Capacity limit: Server accepts up to MAX_SESSIONS concurrent sessions (default 1000)

MCP OAuth Setup (Claude.ai Native OAuth)

When using GITLAB_MCP_OAUTH=true, the server acts as an OAuth proxy to your GitLab instance. Claude.ai (and any MCP-spec-compliant client) handles the entire browser authentication flow automatically — no manual Personal Access Token management needed.

Prerequisites:

A pre-registered GitLab OAuth application is required. GitLab restricts dynamically registered (unverified) applications to the mcp scope, which is insufficient for API calls (need api or read_api).

  1. Go to your GitLab instance → Admin Area > Applications (instance-wide) or User Settings > Applications (personal)
  2. Create a new application with:
    • Confidential: unchecked
    • Scopes: api, read_api, read_user (or whichever scopes you intend to request via GITLAB_OAUTH_SCOPES)
  3. Save and copy the Application ID — this is your GITLAB_OAUTH_APP_ID

How it works:

  1. User adds your MCP server URL in Claude.ai
  2. Claude.ai discovers OAuth endpoints via /.well-known/oauth-authorization-server
  3. Claude.ai registers itself via Dynamic Client Registration (POST /register) — handled locally by the MCP server (each client gets a virtual client ID)
  4. Claude.ai redirects the user's browser to GitLab's login page using the pre-registered OAuth application
  5. User authenticates; GitLab redirects back to https://claude.ai/api/mcp/auth_callback
  6. Claude.ai sends Authorization: Bearer <token> on every MCP request
  7. Server validates the token with GitLab and stores it per session

Server setup:

docker run -d \
  -e STREAMABLE_HTTP=true \
  -e GITLAB_MCP_OAUTH=true \
  -e GITLAB_OAUTH_APP_ID="your-gitlab-oauth-app-client-id" \
  -e GITLAB_API_URL="https://gitlab.example.com/api/v4" \
  -e MCP_SERVER_URL="https://your-mcp-server.example.com" \
  -p 3002:3002 \
  zereight050/gitlab-mcp

For local development (HTTP allowed):

MCP_DANGEROUSLY_ALLOW_INSECURE_ISSUER_URL=true \
STREAMABLE_HTTP=true \
GITLAB_MCP_OAUTH=true \
GITLAB_OAUTH_APP_ID=your-gitlab-oauth-app-client-id \
MCP_SERVER_URL=http://localhost:3002 \
GITLAB_API_URL=https://gitlab.com/api/v4 \
node build/index.js

Claude.ai configuration:

{
  "mcpServers": {
    "GitLab": {
      "url": "https://your-mcp-server.example.com/mcp"
    }
  }
}

No headers field is needed — Claude.ai obtains the token via OAuth automatically.

Environment variables:

VariableRequiredDescription
GITLAB_MCP_OAUTHYesSet to true to enable
GITLAB_OAUTH_APP_IDYesClient ID of the pre-registered GitLab OAuth application
MCP_SERVER_URLYesPublic HTTPS URL of your MCP server; also allowed for /mcp Host/Origin checks
GITLAB_API_URLYesYour GitLab instance API URL (e.g. https://gitlab.com/api/v4)
STREAMABLE_HTTPYesMust be true (SSE is not supported)
GITLAB_OAUTH_SCOPESNoComma-separated GitLab scopes to request (e.g. api,read_user). Defaults to api (or read_api when GITLAB_READ_ONLY_MODE=true). The pre-registered application must be configured with at least these scopes.
OAUTH_REGISTER_RATE_LIMIT_PER_HOURNoPer-IP rolling limit for Dynamic Client Registration (POST /register). Default 20/hour; range 1–1000. Raise when clients (e.g. multiple IDE windows) hit registration throttling. Not a GitLab API limit.
MCP_DANGEROUSLY_ALLOW_INSECURE_ISSUER_URLNoSet true for local HTTP dev only

Important Notes:

  • MCP OAuth only works with Streamable HTTP transport (SSE=true is incompatible)
  • Each user session stores its own OAuth token — sessions are fully isolated
  • Session timeout, rate limiting, and capacity limits apply identically to the REMOTE_AUTHORIZATION mode (SESSION_TIMEOUT_SECONDS, MAX_REQUESTS_PER_MINUTE, MAX_SESSIONS)
  • DCR rate limiting: POST /register is limited to OAUTH_REGISTER_RATE_LIMIT_PER_HOUR per client IP (default 20/hour). Separate from /mcp limits and GitLab API quotas. See environment-variables.md.
  • Header auth fallback: when Private-Token or JOB-TOKEN request headers are present, OAuth validation is skipped and the raw token is used directly for that session. This allows PATs and CI job tokens to be used alongside the OAuth flow on the same server instance. Authorization: Bearer is always treated as an OAuth token — use Private-Token for PAT-based header auth.

Agent Skill Files

Pre-built skill files are available in skills/gitlab-mcp/ for AI agents that support skill/instruction loading (Claude Code, GitHub Copilot, Cursor, etc.).

  • SKILL.md — Core guide (~800 tokens) with toolset overview, key workflows, and parameter hints
  • reference/ — Detailed workflow docs for code review, merge requests, issues, pipelines, and vulnerability triage

Install with the skills CLI:

npx skills add zereight/gitlab-mcp --skill gitlab-mcp-skill

Register the skill directory in your AI client to get optimal tool usage guidance without relying solely on the full ListTools response.

Tools 🛠️

Click to expand
  1. merge_merge_request - Merge a merge request in a GitLab project
  2. approve_merge_request - Approve a merge request (requires appropriate permissions)
  3. unapprove_merge_request - Unapprove a previously approved merge request
  4. get_merge_request_approval_state - Get merge request approval details including approvers (uses approval_state when available, otherwise falls back to approvals)
  5. get_merge_request_conflicts - Get the conflicts of a merge request in a GitLab project
  6. list_merge_request_pipelines - List pipelines for a merge request with pagination support
  7. execute_graphql - Execute a GitLab GraphQL query
  8. create_or_update_file - Create or update a single file in a GitLab project
  9. search_repositories - Search for GitLab projects
  10. create_repository - Create a new GitLab project
  11. create_group - Create a new GitLab group or subgroup (name, path, description, visibility, and optional parent_id)
  12. get_file_contents - Get the contents of a file or directory from a GitLab project
  13. push_files - Push multiple files to a GitLab project in a single commit
  14. create_issue - Create a new issue in a GitLab project
  15. create_merge_request - Create a new merge request in a GitLab project
  16. fork_repository - Fork a GitLab project to your account or specified namespace
  17. create_branch - Create a new branch in a GitLab project
  18. get_branch - Get branch details (commit, protection status)
  19. list_branches - List branches in project with search filter
  20. delete_branch - Delete branch from project
  21. list_protected_branches - List protected branches in a project, supports search filter
  22. get_protected_branch - Get details of a single protected branch (access levels, force push settings)
  23. protect_branch - Protect a repository branch (set push/merge/unprotect access levels)
  24. unprotect_branch - Remove protection from a previously protected branch
  25. update_default_branch - Change the default branch of a project
  26. get_merge_request - Get details of a merge request with compact deployment summary, behind-count, commit addition summary, and approval summary (Either mergeRequestIid or branchName must be provided)
  27. get_merge_request_diffs - Get the changes/diffs of a merge request (Either mergeRequestIid or branchName must be provided)
  28. list_merge_request_changed_files - STEP 1 of code review workflow. Returns ONLY the list of changed file paths in a merge request — WITHOUT diff content. Call this first to get file paths, then call get_merge_request_file_diff with multiple files in a single batched call (recommended 3-5 files per call). Supports excluded_file_patterns filtering using regex. (Either mergeRequestIid or branchName must be provided)
  29. list_merge_request_diffs - List merge request diffs with pagination support (Either mergeRequestIid or branchName must be provided)
  30. get_merge_request_file_diff - STEP 2 of code review workflow. Get diffs for one or more files from a merge request. Call list_merge_request_changed_files first, then pass them as an array to fetch diffs efficiently. Batching multiple files (recommended 3-5) is supported. (Either mergeRequestIid or branchName must be provided)
  31. list_merge_request_versions - List all versions of a merge request
  32. get_merge_request_version - Get a specific version of a merge request
  33. get_branch_diffs - Get the changes/diffs between two branches or commits in a GitLab project
  34. update_merge_request - Update a merge request (Either mergeRequestIid or branchName must be provided)
  35. create_note - Create a new note (comment) to an issue or merge request
  36. create_merge_request_thread - Create a new thread on a merge request
  37. resolve_merge_request_thread - Resolve a thread on a merge request
  38. mr_discussions - List discussion items for a merge request
  39. delete_merge_request_discussion_note - Delete a discussion note on a merge request
  40. update_merge_request_discussion_note - Update a discussion note on a merge request
  41. create_merge_request_discussion_note - Add a new discussion note to an existing merge request thread
  42. create_merge_request_note - Add a new note to an existing merge request thread
  43. delete_merge_request_note - Delete an existing merge request note
  44. get_merge_request_note - Get a specific note for a merge request
  45. get_merge_request_notes - List notes for a merge request
  46. update_merge_request_note - Modify an existing merge request thread note
  47. get_draft_note - Get a single draft note from a merge request
  48. list_draft_notes - List draft notes for a merge request
  49. create_draft_note - Create a draft note for a merge request
  50. update_draft_note - Update an existing draft note
  51. delete_draft_note - Delete a draft note
  52. publish_draft_note - Publish a single draft note
  53. bulk_publish_draft_notes - Publish all draft notes for a merge request
  54. list_merge_request_emoji_reactions - List all emoji reactions on a merge request
  55. list_merge_request_note_emoji_reactions - List all emoji reactions on a merge request note. Pass discussion_id for discussion thread replies.
  56. create_merge_request_emoji_reaction - Add an emoji reaction to a merge request (e.g. thumbsup, rocket, eyes)
  57. delete_merge_request_emoji_reaction - Remove an emoji reaction from a merge request
  58. create_merge_request_note_emoji_reaction - Add an emoji reaction to a merge request note. Pass discussion_id for discussion thread replies.
  59. delete_merge_request_note_emoji_reaction - Remove an emoji reaction from a merge request note. Pass discussion_id for discussion thread replies.
  60. update_issue_note - Modify an existing issue thread note
  61. create_issue_note - Add a new note to an existing issue thread
  62. list_issue_emoji_reactions - List all emoji reactions on an issue
  63. list_issue_note_emoji_reactions - List all emoji reactions on an issue note. Pass discussion_id for discussion thread replies.
  64. create_issue_emoji_reaction - Add an emoji reaction to an issue (e.g. thumbsup, rocket, eyes)
  65. delete_issue_emoji_reaction - Remove an emoji reaction from an issue
  66. create_issue_note_emoji_reaction - Add an emoji reaction to an issue note. Pass discussion_id for discussion thread replies.
  67. delete_issue_note_emoji_reaction - Remove an emoji reaction from an issue note. Pass discussion_id for discussion thread replies.
  68. list_issues - List issues (default: created by current user only; use scope='all' for all accessible issues)
  69. my_issues - List issues assigned to the authenticated user (defaults to open issues)
  70. get_issue - Get details of a specific issue in a GitLab project
  71. update_issue - Update an issue in a GitLab project
  72. update_issue_description_patch - Apply a patch (search/replace or unified diff) to an issue description. Reduces token usage by sending only the change instead of the full description. Supports dry_run to preview and create_note to summarize.
  73. delete_issue - Delete an issue from a GitLab project
  74. list_todos - List GitLab to-do items for the current user
  75. mark_todo_done - Mark a GitLab to-do item as done
  76. mark_all_todos_done - Mark all pending GitLab to-do items as done for the current user
  77. list_issue_links - List all issue links for a specific issue
  78. list_issue_discussions - List discussions for an issue in a GitLab project
  79. get_issue_link - Get a specific issue link
  80. create_issue_link - Create an issue link between two issues
  81. delete_issue_link - Delete an issue link
  82. list_namespaces - List all namespaces available to the current user
  83. get_namespace - Get details of a namespace by ID or path
  84. verify_namespace - Verify if a namespace path exists
  85. get_project - Get details of a specific project
  86. list_projects - List projects accessible by the current user
  87. update_project - Update project settings such as description, visibility, default branch, and feature access levels
  88. list_project_members - List members of a GitLab project
  89. list_group_members - List members of a GitLab group with optional name or username search
  90. list_labels - List labels for a project
  91. get_label - Get a single label from a project
  92. create_label - Create a new label in a project
  93. update_label - Update an existing label in a project
  94. delete_label - Delete a label from a project
  95. list_group_projects - List projects in a GitLab group with filtering options
  96. list_wiki_pages - List wiki pages in a GitLab project
  97. get_wiki_page - Get details of a specific wiki page
  98. create_wiki_page - Create a new wiki page in a GitLab project
  99. update_wiki_page - Update an existing wiki page in a GitLab project
  100. delete_wiki_page - Delete a wiki page from a GitLab project
  101. list_group_wiki_pages - List wiki pages in a GitLab group
  102. get_group_wiki_page - Get details of a specific group wiki page
  103. create_group_wiki_page - Create a new wiki page in a GitLab group
  104. update_group_wiki_page - Update an existing wiki page in a GitLab group
  105. delete_group_wiki_page - Delete a wiki page from a GitLab group
  106. get_repository_tree - Get the repository tree for a GitLab project (list files and directories)
  107. list_pipelines - List pipelines in a GitLab project with filtering options
  108. get_pipeline - Get details of a specific pipeline in a GitLab project
  109. list_deployments - List deployments in a GitLab project with filtering options
  110. get_deployment - Get details of a specific deployment in a GitLab project
  111. list_environments - List environments in a GitLab project
  112. get_environment - Get details of a specific environment in a GitLab project
  113. list_pipeline_jobs - List all jobs in a specific pipeline
  114. list_pipeline_trigger_jobs - List all trigger jobs (bridges) in a specific pipeline that trigger downstream pipelines
  115. get_pipeline_job - Get details of a GitLab pipeline job number
  116. get_pipeline_job_output - Get the output/trace of a GitLab pipeline job with optional pagination to limit context window usage
  117. validate_ci_lint - Validate provided GitLab CI/CD YAML content for a project
  118. validate_project_ci_lint - Validate an existing .gitlab-ci.yml configuration for a project
  119. list_ci_catalog_resources - List GitLab CI/CD Catalog resources/components visible to the user
  120. get_ci_catalog_resource - Get details for a GitLab CI/CD Catalog resource, including versions and components
  121. create_pipeline - Create a new pipeline for a branch or tag
  122. retry_pipeline - Retry a failed or canceled pipeline
  123. cancel_pipeline - Cancel a running pipeline
  124. play_pipeline_job - Run a manual pipeline job
  125. retry_pipeline_job - Retry a failed or canceled pipeline job
  126. cancel_pipeline_job - Cancel a running pipeline job
  127. list_job_artifacts - List artifact files in a job's artifacts archive. Returns file names, paths, types, and sizes
  128. download_job_artifacts - Download the entire artifact archive (zip) for a job to a local path. Returns the saved file path
  129. get_job_artifact_file - Get the content of a single file from a job's artifacts by its path within the archive
  130. list_merge_requests - List merge requests globally or in a specific GitLab project with filtering options (project_id is now optional)
  131. list_milestones - List milestones in a GitLab project with filtering options
  132. get_milestone - Get details of a specific milestone
  133. create_milestone - Create a new milestone in a GitLab project
  134. edit_milestone - Edit an existing milestone in a GitLab project
  135. delete_milestone - Delete a milestone from a GitLab project
  136. get_milestone_issue - Get issues associated with a specific milestone
  137. get_milestone_merge_requests - Get merge requests associated with a specific milestone
  138. promote_milestone - Promote a milestone to the next stage
  139. get_milestone_burndown_events - Get burndown events for a specific milestone
  140. list_group_milestones - List milestones in a GitLab group with filtering options
  141. get_group_milestone - Get details of a specific group milestone
  142. create_group_milestone - Create a new milestone in a GitLab group
  143. edit_group_milestone - Edit an existing group milestone
  144. delete_group_milestone - Delete a milestone from a GitLab group
  145. get_group_milestone_issue - Get issues associated with a specific group milestone
  146. get_group_milestone_merge_requests - Get merge requests associated with a specific group milestone
  147. get_group_milestone_burndown_events - Get burndown events for a specific group milestone
  148. get_users - Get GitLab user details by usernames
  149. get_user - Get user details by ID
  150. whoami - Get current authenticated user details
  151. list_commits - List repository commits with filtering options
  152. get_commit - Get details of a specific commit
  153. get_commit_diff - Get changes/diffs of a specific commit
  154. get_file_blame - Get git blame for a file at a given ref. Each entry maps a contiguous range of source lines to the commit that last changed them (id, author, authored_date, message). Use range_start/range_end to limit blame to specific lines.
  155. list_commit_statuses - List statuses for a specific commit
  156. create_commit_status - Create or update the status of a specific commit
  157. list_group_iterations - List group iterations with filtering options
  158. upload_markdown - Upload a file to a GitLab project for use in markdown content
  159. download_attachment - Download an uploaded file from a GitLab project by secret and filename
  160. health_check - Verify server status and authentication; when authenticated, reports GitLab instance version from /api/v4/version (version, revision, enterprise)
  161. list_events - List all events for the currently authenticated user
  162. get_project_events - List all visible events for a specified project
  163. list_releases - List all releases for a project
  164. get_release - Get a release by tag name
  165. create_release - Create a new release in a GitLab project
  166. update_release - Update an existing release in a GitLab project
  167. delete_release - Delete a release from a GitLab project (does not delete the associated tag)
  168. create_release_evidence - Create release evidence for an existing release (GitLab Premium/Ultimate only)
  169. download_release_asset - Download a release asset file by direct asset path
  170. list_tags - List repository tags with filtering and pagination support
  171. get_tag - Get details of a specific repository tag
  172. create_tag - Create a new tag in the repository
  173. delete_tag - Delete a tag from the repository
  174. get_tag_signature - Get the signature of a signed tag
  175. get_work_item - Get a single work item with full details including status, hierarchy (parent/children), type, labels, assignees, and all widgets
  176. list_work_items - List work items in a project with filters (type, state, search, assignees, labels). Returns items with status and hierarchy info
  177. create_work_item - Create a new work item (issue, task, incident, test_case, epic, key_result, objective, requirement, ticket). Supports setting title, description, labels, assignees, weight, parent, health status, start/due dates, milestone, and confidentiality
  178. update_work_item - Update a work item. Can modify title, description, labels, assignees, weight, state, status, parent hierarchy, children, health status, start/due dates, milestone, confidentiality, linked items, and custom fields
  179. convert_work_item_type - Convert a work item to a different type (e.g. issue to task, task to incident)
  180. list_work_item_statuses - List available statuses for a work item type in a project. Requires GitLab Premium/Ultimate with configurable statuses
  181. list_custom_field_definitions - List available custom field definitions for a work item type in a project. Returns field names, types, and IDs needed for setting custom fields via update_work_item
  182. move_work_item - Move a work item (issue, task, etc.) to a different project. Uses GitLab GraphQL issueMove mutation
  183. list_work_item_notes - List notes and discussions on a work item. Returns threaded discussions with author, body, timestamps, and system/internal flags
  184. create_work_item_note - Add a note/comment to a work item. Supports Markdown, internal notes, and threaded replies
  185. list_work_item_emoji_reactions - List all emoji reactions on a work item
  186. list_work_item_note_emoji_reactions - List all emoji reactions on a work item note (comment, thread, or thread reply)
  187. create_work_item_emoji_reaction - Add an emoji reaction to a work item (e.g. thumbsup, rocket, eyes)
  188. delete_work_item_emoji_reaction - Remove an emoji reaction from a work item
  189. create_work_item_note_emoji_reaction - Add an emoji reaction to a work item note (comment, thread, or thread reply)
  190. delete_work_item_note_emoji_reaction - Remove an emoji reaction from a work item note (comment, thread, or thread reply)
  191. get_timeline_events - List timeline events for an incident. Returns chronological events with notes, timestamps, and tags
  192. create_timeline_event - Create a timeline event on an incident. Supports tags: 'Start time', 'End time', 'Impact detected', 'Response initiated', 'Impact mitigated', 'Cause identified'
  193. list_webhooks - List all configured webhooks for a GitLab project or group. Provide either project_id or group_id
  194. list_webhook_events - List recent webhook events (past 7 days) for a project or group webhook. Use summary mode for overview, then get_webhook_event for full details
  195. get_webhook_event - Get full details of a specific webhook event by ID, including request/response payloads
  196. search_code - Search for code across all projects on the GitLab instance (requires advanced search or exact code search to be enabled)
  197. search_project_code - Search for code within a specific GitLab project (requires advanced search or exact code search to be enabled)
  198. search_group_code - Search for code within a specific GitLab group (requires advanced search or exact code search to be enabled)
  199. list_project_variables - List CI/CD variables for a project with optional environment scope filter
  200. get_project_variable - Get a single CI/CD variable from a project by key, with optional environment scope filter
  201. create_project_variable - Create a new CI/CD variable in a project
  202. update_project_variable - Update an existing CI/CD variable in a project, with optional filter to disambiguate by environment scope
  203. delete_project_variable - Delete a CI/CD variable from a project, with optional filter to disambiguate by environment scope
  204. list_group_variables - List CI/CD variables for a group with optional environment scope filter
  205. get_group_variable - Get a single CI/CD variable from a group by key, with optional environment scope filter
  206. create_group_variable - Create a new CI/CD variable in a group
  207. update_group_variable - Update an existing CI/CD variable in a group, with optional filter to disambiguate by environment scope
  208. delete_group_variable - Delete a CI/CD variable from a group, with optional filter to disambiguate by environment scope
  209. get_dependency_proxy_settings - Get dependency proxy settings for a group (enabled status, blob count, total size, image prefix, TTL policy)
  210. update_dependency_proxy_settings - Update dependency proxy settings for a group (enable/disable, credentials for authenticated Docker Hub pulls)
  211. list_dependency_proxy_blobs - List cached dependency proxy blobs for a group with cursor-based pagination
  212. purge_dependency_proxy_cache - Schedule purge of all cached dependency proxy blobs for a group
  213. list_project_vulnerabilities - List vulnerabilities for a project with optional state, severity, and report type filters (GraphQL-backed, cursor pagination)
  214. get_vulnerability - Get full details of a specific vulnerability
  215. dismiss_vulnerability - Dismiss a vulnerability with a reason (acceptable_risk, false_positive, used_in_tests, mitigating_control, not_applicable) and optional comment
  216. confirm_vulnerability - Confirm a vulnerability as a real finding requiring remediation
  217. discover_tools - Discover and activate additional tool categories for this session. Available categories: merge_requests, issues, repositories, branches, projects, labels, ci, groups, pipelines, milestones, wiki, releases, tags, users, workitems, webhooks, search, variables, dependency_proxy, vulnerabilities. Already-active categories are listed in the response.

Wiki page titles vs. slugs

GitLab derives a wiki page's slug (its URL, /-/wikis/<slug>) from the page title. Passing title to update_wiki_page / update_group_wiki_page therefore renames the page and changes its URL — for nested pages it can also move the page to a different path — which breaks existing links.

To change only the displayed title while keeping the URL stable, do not pass title. Instead, store the display title in the page content's YAML front matter and update the content:

---
title: My Custom Display Title
---

Page body…

GitLab keeps the slug/URL untouched and shows the front-matter title in the UI. Read it back with get_wiki_page using render_html: true, which populates the front_matter field — the plain title field always reflects the slug-derived value.

Testing 🧪

The project includes comprehensive test coverage including remote authorization:

# Run all tests (API validation + remote auth)
npm test

# Run only remote authorization tests
npm run test:remote-auth

# Run all tests including readonly MCP tests
npm run test:all

# Run only API validation
npm run test:integration

All remote authorization tests use a mock GitLab server and do not require actual GitLab credentials.

Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
Email for Agents: Free tier availableEmail for Agents: Free tier available
Email for Agents: Free tier available
Give your AI agent a complete email layer—sending, inbound inboxes, and sandbox testing.
Get 4K emails/month free →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Capacitor makes coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
inference shell
inference shell
create and run specialised agents in minutes
build now →

Configuration

GITLAB_PERSONAL_ACCESS_TOKEN*secret

GitLab personal access token for local stdio use. Create a token with the GitLab scopes needed by the tools you plan to use, such as api or read_api.

GITLAB_JOB_TOKENsecret

Optional GitLab CI job token to use instead of a personal access token when running inside GitLab CI.

GITLAB_AUTH_COOKIE_PATH

Optional path to a GitLab authentication cookie file for cookie-based authentication.

GITLAB_API_URLdefault: https://gitlab.com/api/v4

GitLab API base URL. Use https://gitlab.com/api/v4 for GitLab.com or your self-managed GitLab API URL.

GITLAB_ALLOWED_PROJECT_IDS

Optional comma-separated list of GitLab project IDs that this server is allowed to access.

GITLAB_READ_ONLY_MODEdefault: false

Set to true to expose only read-only tools and block write operations.

USE_GITLAB_WIKIdefault: false

Set to true to enable GitLab wiki tools.

GITLAB_TOOLSETS

Optional comma-separated list of toolsets to enable, such as projects, issues, merge_requests, pipelines, releases, users, groups, wiki, or search.

GITLAB_TOOLS

Optional comma-separated list of individual tool names to add on top of enabled toolsets.

GITLAB_DENIED_TOOLS_REGEX

Optional regular expression used to hide matching tools from the server.

GITLAB_TOOL_POLICY_APPROVE

Optional comma-separated list of tool names that require explicit approval before execution.

GITLAB_TOOL_POLICY_HIDDEN

Optional comma-separated list of tool names to hide from tools/list.

NODE_TLS_REJECT_UNAUTHORIZED

Set to 0 only when you intentionally need to connect to a GitLab instance with invalid or self-signed TLS certificates.

GITLAB_CA_CERT_PATH

Optional path to a custom CA certificate file for self-managed GitLab instances.

Categories
Developer ToolsDocuments & Knowledge
Registryactive
Package@zereight/mcp-gitlab
TransportSTDIO
AuthRequired
Tools verifiedJun 10, 2026
UpdatedMay 30, 2026
View on GitHub

Related Developer Tools MCP Servers

View all →
Git Mcp Server

ray0907/git-mcp-server

MCP server for GitLab and GitHub
Git Mcp Server

cyanheads/git-mcp-server

Comprehensive Git MCP server enabling native git tools including clone, commit, worktree, & more.
221
Atlassian Dc Mcp Bitbucket

io.github.b1ff/atlassian-dc-mcp-bitbucket

MCP server for Atlassian Bitbucket Data Center - interact with repositories and code
77
Atlassian Dc Mcp Jira

io.github.b1ff/atlassian-dc-mcp-jira

MCP server for Atlassian Jira Data Center - search, view, and create issues
77
Atlassian Jira

com.mcparmory/atlassian-jira

Create, search, and manage issues, projects, and team workflows
25
Vscode Terminal Mcp

sirlordt/vscode-terminal-mcp

Execute commands in visible VSCode terminal tabs with output capture and session reuse.
1