ScreenshotNeo

BlogAI agents

How to Use an MCP Server in GitHub Copilot

Configure local or remote MCP servers, enable their tools in Copilot Agent mode, and troubleshoot authentication, policy, and cloud-agent issues.

By the ScreenshotNeo team1 October 20268 min read

Short answer: configure an MCP server for the Copilot client you use, select Agent mode in Copilot Chat when tool use requires it, inspect the server’s available tools, and ask Copilot for a task those tools can perform. MCP (Model Context Protocol) supplies the connection to external tools and data; Copilot remains the client that decides when to call an enabled tool.

This guide covers VS Code, JetBrains IDEs, repository and Copilot cloud-agent configuration, and Copilot CLI. It also explains authentication, least-privilege tool selection, organization policy, common failures, and a ScreenshotNeo MCP example for agents that need website screenshots.

What an MCP server adds to GitHub Copilot

An MCP server exposes tools through a standard protocol. A tool might list pull requests, read repository information, create an issue, query a service, or capture a web page. The server owns the integration and permissions; Copilot supplies the conversational interface and can choose an enabled tool while handling a request.

MCP is not a universal user interface. You still configure a server for each Copilot client, authenticate it, and enable only the tools that the account and organization policy allow.

Use an MCP server in VS Code Copilot Chat

  1. Open Copilot Chat.
  2. Select Agent from the mode dropdown. Some tool workflows are unavailable in ask or edit modes.
  3. Click the Configure tools icon.
  4. Expand the GitHub MCP server or another configured server and review its tools.
  5. Enable the smallest set that can complete your task.
  6. Ask for a concrete operation, such as “List the open pull requests in this repository and summarize the reviewers.”

For a write operation, state the intended scope clearly and confirm that your account has the corresponding GitHub permission. Copilot can use configured tools autonomously, so treat every enabled write tool as an action the agent may invoke.

Check the result

Ask Copilot to identify which tool it used and summarize the returned data. If a tool is not offered, reopen the tools picker and verify that the server is connected and that the tool is not filtered by policy. A missing tool can also mean that the underlying GitHub feature is unavailable to your account.

Add a local or remote MCP server to an IDE

GitHub’s IDE configuration supports both local processes and remote servers. A local server is started with a command and arguments. A remote server is represented by a URL and normally uses OAuth or a personal access token, depending on the client.

Representative local configuration

In clients that use an mcp.json file, place servers under a servers object. This example starts the Model Context Protocol memory server with npx:

{
  "servers": {
    "memory": {
      "command": "npx",
      "args": ["-y", "@modelcontextprotocol/server-memory"]
    }
  }
}

Save the file, restart or reload the IDE if it does not discover the process, then return to Copilot Chat, choose Agent mode, and inspect the tools picker.

Remote GitHub MCP server

The documented remote endpoint for GitHub’s MCP server is:

https://api.githubcopilot.com/mcp/

Authentication varies by client. Use the OAuth flow offered by the client or a personal access token where supported. Keep credentials in the client’s secret store or environment, never in a committed configuration file, and grant only the scopes required by the tools you enable.

Configure MCP for a repository and Copilot cloud agent

Repository administrators configure this path on GitHub.com under Settings → Copilot → MCP servers. The configuration uses an mcpServers object. A server entry can include:

  • type: local, stdio, http, or sse, as accepted by Copilot cloud agent.
  • command and args for local or stdio processes.
  • url for a remote server.
  • Optional headers or env values, including references to Copilot secrets and variables.
  • tools to allowlist the exact tools the agent may call.

Only Agents secrets and variables whose names begin with COPILOT_MCP_ are available to this repository configuration. Add the required secrets or variables after saving the JSON. Repository cloud agent and code review support MCP tools, but not MCP resources or prompts in this configuration path. Remote OAuth-based MCP servers are also not supported there, so use a supported authentication method or a different client.

Example repository configuration shape

{
  "mcpServers": {
    "internal-tools": {
      "type": "http",
      "url": "https://example.internal/mcp",
      "headers": {
        "Authorization": "Bearer ${COPILOT_MCP_INTERNAL_TOKEN}"
      },
      "tools": ["search_docs", "get_build_status"]
    }
  }
}

Replace the example host and tool names with values supplied by your server. Do not commit a real token. Allowlist read-only tools first, then add a write tool only when its need, input validation, and approval process are understood.

Use MCP with the GitHub MCP server

The GitHub MCP server is maintained by GitHub and is available to GitHub users. Each tool still inherits the access requirements of the corresponding GitHub feature. The default toolsets include repos, issues, and pull_requests; additional toolsets include actions, code security, and secret protection. Remote-only toolsets include copilot and github_support_docs_search.

Some operations involving Copilot cloud agent require a paid Copilot license. If a tool returns an entitlement error, check the underlying feature and account plan rather than changing the MCP transport.

Use MCP from Copilot CLI

The GitHub MCP server is built into Copilot CLI. Add another server interactively with:

/mcp add

Useful management commands are:

copilot mcp list
copilot mcp get SERVER-NAME
copilot mcp disable SERVER-NAME
copilot mcp enable SERVER-NAME

Project-specific MCP configuration can be committed so collaborators receive the same server definition. Keep credentials outside the repository and document which tools are safe for routine use.

Security and governance checklist

  • Use the smallest toolset and scope that solves the task.
  • Prefer read-only tools for investigation, review, and documentation.
  • Store tokens in secrets or environment variables; never paste them into prompts or commit them.
  • Review organization and enterprise settings. The “MCP servers in Copilot” policy can disable MCP or restrict servers with an allowlist.
  • Remember that configured agents may call tools without asking for approval.
  • For Copilot code review, every server tool must return annotations.readOnlyHint: true; tools without that annotation, or with it set to false, are excluded.
  • Log tool calls and server responses where your security policy requires an audit trail.

Or skip the browser setup

If your agent needs a website image or PDF, ScreenshotNeo provides an MCP server with take_screenshot, get_page_info, and capture_pdf tools. It removes cookie and consent banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and the response reports the page verdict and billing status in headers.

Configure ScreenshotNeo in the MCP client using the setup shown in the ScreenshotNeo documentation, then enable its tools in Copilot Agent mode. For a direct one-call capture, use:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo supports full-page and element captures, device presets, custom viewports, retina scale, dark mode, PDF options, custom CSS and JavaScript, waits, request blocking, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, TTL caching, signed links, asynchronous jobs, bulk capture, and a usage API. Its free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

Troubleshooting MCP in GitHub Copilot

Symptom Likely cause Fix
Server is absent from the tools picker Wrong config location, invalid JSON, or client has not reloaded Validate the file, confirm the server name and transport, reload or restart the client, then inspect logs.
Local process exits immediately Missing runtime, package, argument, or permission Run the command manually, verify the runtime is on PATH, pin the intended package version, and read stderr.
Remote connection fails Incorrect URL, firewall, TLS, or unsupported transport Check the endpoint from the same network, confirm HTTP/SSE support, and review proxy and certificate logs.
401 or 403 response Missing, expired, or under-scoped credential Reauthenticate, rotate the secret, and grant only the permission required by that tool.
Tool appears but cannot be called Tool allowlist or organization policy filters it Review the tools list and the MCP servers in Copilot policy; ask an administrator to update the allowlist.
Agent ignores the server Chat is not in Agent mode or the prompt does not require the tool Select Agent, enable the tool, and name the desired operation or server in the prompt.
Cloud agent rejects OAuth Repository/cloud-agent configuration does not support remote OAuth MCP servers Use a supported token or environment secret, or configure the server in an IDE or CLI client that supports its OAuth flow.
Code review ignores a tool readOnlyHint is absent or false Mark the tool read-only in the server response; code review excludes write-capable tools.
Operation returns an entitlement error Underlying GitHub feature or Copilot cloud-agent capability needs a different plan Check the feature’s access requirements and account license.

Performance, reliability, and cost considerations

  • Startup: local stdio servers add process startup time. Keep a long-lived process where the client supports it and avoid reinstalling dependencies on every call.
  • Network: remote servers add DNS, TLS, proxy, and service latency. Set practical client timeouts and return concise tool results.
  • Reliability: make tools idempotent where possible, validate inputs server-side, and return actionable errors. A reconnect or retry must not duplicate a destructive write.
  • Context size: allowlisting fewer tools and limiting result fields reduces the descriptions and data Copilot must interpret.
  • Cost: GitHub feature access and Copilot licensing determine entitlement for GitHub MCP tools. A third-party server can have its own pricing. ScreenshotNeo charges only for clean shots; failed loads, bot checks, blank pages, timeouts, and cache hits are not billed.

FAQ

Can Copilot use a remote MCP server?

Yes, IDE clients can use a remote URL when the transport and authentication they support match the server. Repository and cloud-agent configuration has additional restrictions, including no remote OAuth servers in that path.

Do I need Agent mode for every MCP tool?

Use Agent mode for the Copilot Chat workflow that plans and calls tools. If a client exposes a tool in another mode, its picker and documentation determine availability.

Are MCP resources and prompts available to Copilot cloud agent?

The repository/cloud-agent and code-review path supports MCP tools, not MCP resources or prompts.

Can I let an MCP server write to my repository?

Only if the server exposes write tools and your account, repository policy, and Copilot client permit them. Start with read-only tools and add narrowly scoped writes after review.

How do I make a server available to a team?

Use repository MCP settings for a shared cloud-agent configuration, commit project configuration where appropriate for CLI or IDE use, and manage credentials through organization secrets and policy.