How to Connect a GitHub MCP Server in VS Code
Connect GitHub’s MCP server to VS Code with the built-in Copilot Chat preview or a manual HTTP configuration, plus read-only setup and fixes.
Short answer: In current VS Code, the simplest option is the GitHub MCP Server preview built into the GitHub Copilot Chat extension. Enable github.copilot.chat.githubMcpServer.enabled, open an agent chat, and select the GitHub tools from the tool picker. For a workspace-level manual setup, add GitHub’s hosted endpoint to .vscode/mcp.json as an HTTP server:
{
"servers": {
"github": {
"type": "http",
"url": "https://api.githubcopilot.com/mcp/"
}
}
}
VS Code also accepts the portable .mcp.json format, which uses a top-level mcpServers object. The built-in preview reuses the GitHub authentication already available to VS Code; the manual hosted-server route has its own documented endpoint, toolset, and read-only options.
Official references: VS Code 1.107 release notes, the VS Code MCP server configuration reference, and GitHub’s remote MCP server documentation.
Choose the connection method
| Route | Best for | Authentication | Configuration | Controls |
|---|---|---|---|---|
| Built-in Copilot Chat preview | Fastest setup in a personal VS Code installation | Existing GitHub authentication in VS Code | One setting | Built-in toolsets, read-only and lockdown settings |
| Manual hosted server | Sharing a workspace configuration or selecting a documented endpoint | Configured according to GitHub’s remote-server instructions | .vscode/mcp.json or .mcp.json |
Endpoint variants, toolsets and optional headers |
Use the built-in route when you want the fewest moving parts. Use manual configuration when the repository should declare its MCP server, when you need a specific hosted endpoint such as the read-only path, or when you need the portable MCP format.
Route A: enable the built-in GitHub MCP Server
Prerequisites
- A current VS Code release with the GitHub Copilot Chat extension installed.
- A GitHub account authenticated in VS Code.
- An agent chat experience enabled in your installation.
The GitHub MCP server was documented as a Preview feature in the November 2025 VS Code 1.107 release. Names and availability can change, so check the installed extension and current release notes if the setting is missing.
Step 1: turn on the server
- Open Settings in VS Code.
- Search for
github.copilot.chat.githubMcpServer.enabled. - Set it to
true.
You can also place the setting in settings.json:
{
"github.copilot.chat.githubMcpServer.enabled": true
}
Step 2: verify the tools
- Open an agent chat.
- Open the chat’s tool picker.
- Confirm that GitHub tools are listed.
- Ask for a low-risk repository lookup, such as listing issues or explaining a file.
The server uses the GitHub authentication already available to VS Code. The release notes describe the default toolset as enabled initially and document settings for selecting toolsets, read-only operation and lockdown.
Useful built-in settings
| Setting | Purpose | When to change it |
|---|---|---|
github.copilot.chat.githubMcpServer.enabled |
Enables the preview server | Set to true to use it |
github.copilot.chat.githubMcpServer.toolsets |
Chooses the GitHub toolsets exposed to the agent | Limit tools to repositories, issues, pull requests, Actions or other supported groups |
github.copilot.chat.githubMcpServer.readonly |
Requests read-only behavior | Prefer it for inspection, search and review workflows |
github.copilot.chat.githubMcpServer.lockdown |
Restricts the server more tightly | Use when your organization requires a constrained tool surface |
Adding some toolsets may require additional permissions. The 1.107 release notes also cautioned that reauthentication was not supported at that time, so update VS Code or the extension if authentication behavior differs in your installation.
Route B: configure GitHub’s hosted MCP endpoint manually
Workspace configuration with .vscode/mcp.json
- Open the repository folder in VS Code.
- Create
.vscode/mcp.json. - Add the hosted HTTP server configuration.
- Save the file and start the server from the MCP controls.
{
"servers": {
"github": {
"type": "http",
"url": "https://api.githubcopilot.com/mcp/"
}
}
}
The top-level key is servers in VS Code’s workspace format. Commit this file only after reviewing whether your team wants every workspace user to inherit the server.
Portable configuration with .mcp.json
Use the portable format when another MCP client should be able to read the same configuration:
{
"mcpServers": {
"github": {
"type": "http",
"url": "https://api.githubcopilot.com/mcp/"
}
}
}
Do not combine the two top-level schemas in one file. VS Code’s .vscode/mcp.json uses servers; the portable .mcp.json format uses mcpServers.
Use the read-only endpoint
GitHub documents a read-only endpoint at:
https://api.githubcopilot.com/mcp/readonly
For a workspace that only needs repository lookup, issue reading or pull-request inspection, configure that path:
{
"servers": {
"github": {
"type": "http",
"url": "https://api.githubcopilot.com/mcp/readonly"
}
}
}
GitHub also documents toolset-specific paths and optional headers for choosing toolsets and read-only behavior. Treat those manual-server controls separately from the built-in Copilot Chat preview settings; they are not the same configuration surface.
Add a server from the Command Palette
You do not have to edit JSON by hand:
- Run MCP: Add Server.
- Choose the workspace or user scope.
- Choose an HTTP server.
- Enter
https://api.githubcopilot.com/mcp/. - Give it the name
github.
Use MCP: Open Workspace Folder MCP Configuration to open the workspace file later. Use MCP: List Servers to start, stop, restart or inspect a server.
Authentication, permissions and tool selection
The built-in preview uses the GitHub authentication already available in VS Code. Manual remote configuration follows GitHub’s hosted-server instructions, including any endpoint-specific headers or authorization requirements described there.
Start with the smallest tool surface that solves the task:
- Repository inspection: use repository and code lookup tools.
- Issue triage: add issue tools only when needed.
- Pull-request review: enable pull-request tools for review workflows.
- Actions or security: add those toolsets only for teams that need them and have approved the permissions.
Prefer read-only mode for agents that should explain, search or review. Enable write-capable tools only when the workflow requires changes and the account permissions are appropriate.
Trust and security checklist
- Review the publisher, endpoint and configuration before starting an unfamiliar MCP server.
- Remember that local MCP servers can run arbitrary code.
- Workspace MCP configuration follows Workspace Trust. In Restricted Mode, workspace MCP configuration is blocked.
- For local stdio servers, read VS Code’s security guidance about sandboxing on macOS and Linux.
- Keep credentials out of committed configuration files. Use the authentication mechanism documented by the server.
- Use the read-only endpoint or setting when the agent does not need write access.
- Limit toolsets so an agent cannot call unrelated operations.
Troubleshooting
The GitHub tools do not appear
Cause: the preview setting is disabled, the extension is missing or the installed version does not include the preview.
Fix: install or update GitHub Copilot Chat, enable github.copilot.chat.githubMcpServer.enabled, reload VS Code, then reopen agent chat and its tool picker.
The setting is missing
Cause: the extension or VS Code version predates the preview, or the feature has changed.
Fix: check the installed extension version and the current VS Code release notes. The setting was documented for VS Code 1.107 in November 2025.
The manual server will not start
Cause: invalid JSON, the wrong schema key, a blocked workspace configuration or a network/authentication problem.
Fix: confirm that .vscode/mcp.json uses servers, that the URL is exactly the documented HTTPS endpoint, and that the folder is trusted. Run MCP: List Servers, select the GitHub server and choose Show Output. VS Code’s MCP documentation identifies that output as the first place to inspect server errors.
“Unknown property” or schema errors
Cause: a portable .mcp.json example was pasted into .vscode/mcp.json, or vice versa.
Fix: use servers in .vscode/mcp.json and mcpServers in .mcp.json. Keep each server entry’s type and url fields intact.
Authentication or permission failures
Cause: the signed-in GitHub account cannot access the repository, a selected toolset needs extra permissions, or the remote route expects authentication that has not been configured.
Fix: verify the account in VS Code, test access to the repository in GitHub, start with the default or read-only toolset, and follow GitHub’s remote-server authentication instructions for manual configuration.
Only some tools are available
Cause: the active toolset is intentionally limited.
Fix: inspect github.copilot.chat.githubMcpServer.toolsets for the built-in route, or use the toolset-specific options and headers documented for the hosted server.
Workspace settings are ignored
Cause: the folder is in Restricted Mode or the configuration file is outside the opened workspace.
Fix: trust the workspace if the repository is safe, open the folder that contains .vscode/mcp.json, and run MCP: List Servers to confirm that VS Code discovered it.
Reliability, performance and operating costs
Reliability
- Use the built-in route when you want VS Code and Copilot Chat to manage discovery and existing authentication.
- Use the hosted endpoint when you want a versioned workspace configuration that teammates can review.
- Keep a read-only configuration available as a fallback for investigation and documentation tasks.
- When a call fails, inspect server output before changing several settings at once; this preserves the original error.
Performance
- Expose only the toolsets an agent needs. A smaller tool list makes tool selection clearer.
- Ask for focused repository operations instead of broad multi-step requests.
- Prefer the nearest documented endpoint and avoid unnecessary local proxy layers.
- For repeated investigations, keep the same trusted workspace open so the MCP server does not need to be rediscovered.
Cost
The MCP connection itself is a VS Code configuration choice. Any GitHub Copilot subscription, organization policy or API usage agreement is separate from the MCP URL; check the current GitHub and Copilot terms for your account.
Or skip the browser setup
If the task is producing screenshots of GitHub pages, documentation or issue views, ScreenshotNeo provides a website screenshot API and MCP server. One request returns a PNG, JPEG, WebP or PDF. Its MCP tools—take_screenshot, get_page_info and capture_pdf—work with Claude, Cursor and other MCP clients.
Cookie and consent banners are accepted and removed before capture, along with more than 60 known consent platforms, newsletter popups and chat widgets. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and each response reports the result with X-Page-Verdict and X-Billed headers.
See the ScreenshotNeo API documentation for all options.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
There are 1,000 free screenshots each month with no card. Paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
FAQ
Do I need to run a local GitHub MCP process?
No. The built-in preview and the manual configuration above use GitHub’s hosted MCP service. Local MCP servers are a separate option and require extra trust review.
Which file should I commit?
Commit .vscode/mcp.json when the workspace should share VS Code’s configuration. Use .mcp.json when portability across MCP clients matters and your tooling supports that format.
Can I make the connection read-only?
Yes. The built-in preview has a read-only setting, and GitHub documents the hosted read-only endpoint at https://api.githubcopilot.com/mcp/readonly.
Why are GitHub Actions or security tools absent?
The default toolset is limited. Add the relevant toolset using the built-in toolset setting or the hosted server’s documented toolset controls, then complete any required reauthorization.
Where are MCP errors recorded?
Run MCP: List Servers, select the server and choose Show Output. You can also open the error notification in Chat and view its output.


