GitHub MCP setup: remote, Docker and read-only access
Set up GitHub MCP with remote or Docker connections, bounded tools and permissions, and a first read test with an independently checked result.
A first GitHub MCP test can answer one bounded question: can this connection find a known repository and read its contents correctly? Choose the expected repository and a specific file before you begin. Once that read works, plan separate tests for issues or pull requests. This guide separates the connection method, authorization and observed result. Merely seeing a tool in the client does not answer all three questions, and a successful public read does not establish private access.
Choose remote access or a local Docker process
GitHub provides a remote MCP service and a locally launched server. Match the transport supported by your client to the deployment you want. The official project documents the remote endpoint https://api.githubcopilot.com/mcp/ and container image ghcr.io/github/github-mcp-server. Authentication and configuration differ by connection method. A Docker command belongs in an executable configuration, not in the URL field for a remote connection.
| Route | Preparation | First evidence |
|---|---|---|
| Remote | Compatible HTTP client and authentication | Initialization and tool list |
| Docker | Available Docker engine and process environment | Server starts through stdio |
| Both | Chosen test repository and required permissions | Expected file is read correctly |
Visit the GitHub app page for documented tasks. Use the GitHub registry search to compare entries. A server with GitHub in its name is not necessarily the official project. Check its repository and publisher at the source before adopting a configuration.
Limit tools and account permissions separately
The official local server documents --read-only and the Docker setting GITHUB_READ_ONLY=1. This removes write tools from the offered inventory. Your authentication must also permit access to the intended resources. The server setting does not replace bounded account permissions. After startup, inspect the actual tool inventory and record which operation you selected for the test.
Start with an uncritical public repository. Reading it successfully does not prove access to private content. Treat private access as a separate step with its own expected response when you need it. Do not put credentials into search fields, screenshots or configuration examples shared with other people.
Follow the Docker environment into the container
A variable supplied to the client still needs to reach the container. For token authentication, the project documents -e GITHUB_PERSONAL_ACCESS_TOKEN before the image name. Its value must already be present in the Docker process environment. A desktop client does not necessarily inherit your terminal environment. The Docker guide explains that boundary, stdio and mounts.
Use the configuration builder for your client when the selected registry entry contains a launch template. Compare the output with documentation for your intended server version. A template is a starting file; it does not confirm authentication or successful startup.
Run a reproducible read test
Record the client version, connection method and test repository. Choose a file path and expected content.
Initialize the connection and inspect the tool inventory. Confirm that the required read operation is present.
Request only the prepared resource. Independently compare repository, path and content with the GitHub interface.
Record results and limitations. Repeat the same test after changes to the version, authentication or enabled tools.
The public GitHub verification report describes two historical reads. It illustrates a bounded measurement rather than proving your current installation. For a later write workflow, the issue guide lists additional steps. Keep that workflow separate from the read-only acceptance test.
- Do remote connections require Docker?
- The remote service does not require a local Docker server. Check whether your client supports the documented remote connection.
- Does the tool list prove authorization?
- No. An operation may be visible while the requested resource is inaccessible to your authenticated account.
- Why does only the private repository fail?
- Check repository selection and effective permissions first. Do not automatically repeat the entire installation process.
- Can a read test count as a write test?
- No. Creating and modifying resources need separate tests with a controlled destination and readback.
Official documentation checked on 1 October 2026. The test plans are editorial suggestions.
- GitHub MCP Server
Show retrieval command
curl -s https://github.com/github/github-mcp-server - GitHub MCP server configuration
Show retrieval command
curl -s https://github.com/github/github-mcp-server/blob/main/docs/server-configuration.md