All of GitLab for your AI assistant. Up to 1,098 actions over GitLab's REST and GraphQL APIs, from Free to Ultimate and on GitLab.com, in one self-contained binary that works with Claude, Cursor, VS Code, Codex and any other MCP client. You ask in plain language; it does the GitLab work.
11,168 tokens of startup context by default, the same on every GitLab tier (1,840 with GITLAB_MCP_CAPABILITY_SURFACE=minimal). Two tools reach the whole catalog, where listing every tool as its own costs from 560,384 to 713,287 tokens. Measured with the cl100k_base tokenizer and checked in CI. How it is measured
"Review merge request !15: is it safe to merge?" · "Why did the last pipeline fail?" · "List open issues assigned to me" · "Generate release notes from v1.0 to v2.0"
- Every tier and every instance. Free/CE, Premium and Ultimate, self-managed or GitLab.com with its Orbit knowledge graph. The tier is detected and the catalog follows it.
- The token you already have. A personal, project or group access token with
api, orread_apifor the actions GitLab accepts from it; a fine-grained token, judged action by action from its grant; OAuth in HTTP mode. Each action's tool reference entry says which scope and which fine-grained permissions it needs. - Guard rails. Read-only mode, safe mode (a preview of each write instead of the write), tools excluded by name, and a confirmation before anything destructive.
- Three surfaces, two transports. Two discovery tools by default, one tool per domain or one per action; stdio for a desktop client, or HTTP for a shared deployment that keeps each credential apart. 45 resources and 37 prompts besides.
- Releases you can verify. Signed checksums, an SBOM per binary and build provenance for every artifact.
The buttons register the Docker image, so they need Docker; the Claude Desktop row downloads a native extension instead. Create a personal access token with the api scope (or read_api for the actions GitLab accepts from it; add GITLAB_MCP_READ_ONLY=true when nothing may be written).
| Client | One-click button | Token step |
|---|---|---|
| VS Code | prompts you (masked) | |
| Cursor | edit YOUR_GITLAB_TOKEN |
|
| LM Studio | edit YOUR_GITLAB_TOKEN |
|
| Kiro | edit YOUR_GITLAB_TOKEN |
|
| Claude Desktop | settings UI |
Claude Code. The registration command never carries the token: -e GITLAB_TOKEN forwards it from the environment Claude Code hands docker.
export GITLAB_TOKEN=glpat-xxxx
claude mcp add gitlab --transport stdio \
-- docker run -i --rm -e GITLAB_TOKEN ghcr.io/jmrplens/gitlab-mcp-server:latestAny other client runs one of these as the server's command, with GITLAB_TOKEN in the environment it passes:
npx -y @jmrp.io/gitlab-mcp-server # npm, nothing installed first
uvx jmrplens-gitlab-mcp-server # PyPI, nothing installed first
dnx gitlab-mcp-server # NuGet (.NET 10 SDK), nothing installed first
brew install jmrplens/tap/gitlab-mcp-server # Homebrew, macOS and Linux
winget install --id jmrplens.gitlab-mcp-server -e # winget, Windows
docker run -i --rm -e GITLAB_TOKEN ghcr.io/jmrplens/gitlab-mcp-server:latestFor a self-managed instance, set GITLAB_URL=https://gitlab.example.com beside the token; with the Docker image, also forward it by adding -e GITLAB_URL to the docker arguments, since the container receives only the variables named there (Docker install). Every channel, per-client configuration and verification step is in the installation guide, and an assistant installing it for you will find the same in llms.txt.
To try it first, a public instance runs at https://mcp.jmrp.io/gitlab, and the browser inspector calls it read-only after an OAuth sign-in. Your token and every request pass through that machine, so run it yourself to keep using it; the hosted endpoint page says what it is and is not.
Everything else is at jmrp.io/docs/gitlab-mcp-server, in English and Spanish: getting started, configuration, tool surfaces, HTTP server mode, security, privacy and troubleshooting.
Contributions are welcome here on GitHub; CONTRIBUTING.md describes the workflow, and CODE_OF_CONDUCT.md applies. Report a vulnerability privately, as SECURITY.md describes. The server is MIT licensed (LICENSE).
Maintained by José M. Requena Plens · Project page · Hosted instance: mcp.jmrp.io/gitlab
