How to Use a Remote GitHub MCP Server
Connect GitHub’s hosted MCP server to an MCP client, authenticate safely, choose tools, and troubleshoot IDE and Copilot workflows.
Short answer: Add GitHub’s hosted MCP endpoint to an MCP-compatible client, authenticate with OAuth (the documented default) or a supported personal access token, then use the client’s agent and tool picker to run GitHub actions. For standard GitHub accounts, the endpoint is https://api.githubcopilot.com/mcp/. GitHub Enterprise Cloud organizations with data residency use an organization-specific endpoint such as https://copilot-api.octocorp.ghe.com/mcp. GitHub documents the IDE workflow.
What a remote GitHub MCP server is
MCP (Model Context Protocol) lets an AI host discover and call tools exposed by a server. With GitHub’s remote server, GitHub hosts the service. Your IDE or agent client stores the server URL and handles authentication; you do not run the GitHub MCP server on your own machine for this workflow.
GitHub describes the remote option as the recommended setup for most users. The available tools, transports, authentication methods, and client controls depend on the host application, so check the current support in the client you plan to use.
Before you connect
- Use an MCP-compatible client, such as an IDE or agent host with remote HTTP/SSE MCP support.
- Sign in to the GitHub account that should access repositories, issues, pull requests, and other tools.
- If you use Copilot Business or Copilot Enterprise, ask an administrator whether the organization’s MCP servers in Copilot policy is enabled.
- Decide whether your account environment uses the standard endpoint or a GitHub Enterprise Cloud data-residency endpoint.
- Prepare OAuth in the client, or a PAT only when the client and account type support it.
Choose the correct endpoint
| Account environment | Endpoint pattern |
|---|---|
| Standard GitHub | https://api.githubcopilot.com/mcp/ |
| GitHub Enterprise Cloud with data residency | https://copilot-api.SUBDOMAIN.ghe.com/mcp |
For example, an enterprise instance at https://octocorp.ghe.com uses https://copilot-api.octocorp.ghe.com/mcp. Use the endpoint that matches the account and enterprise configuration; do not substitute the standard endpoint for a data-residency organization.
Set up the remote server in VS Code
- Open Copilot Chat in VS Code.
- Switch the chat mode to Agent.
- Open Configure tools and add a remote HTTP/SSE MCP server, or install the GitHub MCP server from the MCP server gallery and confirm it appears in the configured-server list.
- Enter
https://api.githubcopilot.com/mcp/, or your enterprise endpoint. - Choose the client’s Auth action or follow its sign-in prompt to complete OAuth.
- Return to Agent mode, open Configure tools, and confirm that GitHub tools are listed.
- Ask for a read operation first, such as repository information or a list of pull requests. Review the permission prompt before allowing a write operation such as creating an issue.
Controls differ across Visual Studio, JetBrains, Xcode, Eclipse, and other hosts. The same sequence applies—register the remote URL, authenticate, inspect tools, and issue a task—but menu names and transport support vary.
Authentication: OAuth and personal access tokens
OAuth
OAuth is GitHub’s documented default for the remote server. The client opens a GitHub authorization flow, and the server receives only the scopes you approve. Organization policy can further restrict scopes or permitted applications. If an organization blocks the OAuth application, an administrator may need to enable it; GitHub notes exceptions for VS Code and Visual Studio in its setup guidance.
Personal access token
A PAT is an alternative when the host supports PAT authentication. Create or use a token with the permissions required for the operation, keep it in the client’s secret store, and never commit it to a repository or paste it into shared configuration. PAT availability is not universal for Enterprise Managed Users; GitHub says PATs are disabled by default there unless an enterprise administrator enables them.
Diagnostic request with cURL
This request checks whether the endpoint is reachable with a token. The exact MCP negotiation is handled by your client, so use this as a network and authorization diagnostic rather than as a replacement for client setup.
curl -i \
-H "Authorization: Bearer YOUR_GITHUB_TOKEN" \
-H "Accept: text/event-stream, application/json" \
https://api.githubcopilot.com/mcp/
Replace the URL with the enterprise endpoint when required. Keep the token out of shell history where possible; use your shell’s secret-handling facilities or the client’s credential store.
Use the tools from an agent
After authentication, ask for a concrete task and let the host show the tool call and any approval request. Useful first prompts include:
- “Show the repository information for
OWNER/REPO.” - “List open pull requests in
OWNER/REPO.” - “Create an issue in
OWNER/REPOwith this title and body.”
Start with read-only requests while validating repository access. For writes, verify the target repository, branch, issue text, or pull request before approving.
Toolsets and configuration
GitHub provides standard toolsets and supports customization. Remote-only options documented by GitHub include copilot and github_support_docs_search. Depending on the configuration route, a URL path parameter can enable one toolset, while HTTP headers can enable multiple. Local server configuration instead uses command-line flags or environment variables.
Because tool names and configuration controls can change, inspect the current GitHub toolset documentation and the client’s MCP documentation before pinning a production configuration.
Remote IDE setup versus Copilot cloud agent and code review
Repository-level MCP configuration for Copilot cloud agent and code review is a separate context from adding the hosted endpoint to an IDE. GitHub says those repository contexts do not currently support remote MCP servers using OAuth, and they support MCP tools rather than server resources or prompts. GitHub also warns that configured tools can operate autonomously without asking for approval in those contexts. Do not assume that a server working in VS Code Agent mode has identical behavior in cloud agent or code review.
Python and Node.js configuration helpers
The host application performs MCP negotiation and OAuth. These small scripts keep the endpoint selection in one place and can be used by an internal launcher or configuration generator.
Python
import os
enterprise_subdomain = os.getenv("GITHUB_ENTERPRISE_SUBDOMAIN")
if enterprise_subdomain:
endpoint = f"https://copilot-api.{enterprise_subdomain}.ghe.com/mcp"
else:
endpoint = "https://api.githubcopilot.com/mcp/"
config = {"name": "github", "url": endpoint}
print(config)
Node.js
const subdomain = process.env.GITHUB_ENTERPRISE_SUBDOMAIN;
const endpoint = subdomain
? `https://copilot-api.${subdomain}.ghe.com/mcp`
: 'https://api.githubcopilot.com/mcp/';
console.log(JSON.stringify({ name: 'github', url: endpoint }, null, 2));
Pass the printed URL to the MCP client’s remote-server configuration. Do not put a PAT in these files.
Security checklist
- Use OAuth unless your client and account policy require a PAT.
- Grant only the scopes needed for the task.
- Store PATs in a secret manager or the host’s credential store.
- Review organization policies before troubleshooting the client.
- Test read operations before enabling writes.
- Remember that repository-level cloud-agent and code-review tools may run autonomously after configuration.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Authorization fails | The client is signed out, the token is invalid, or required scopes are missing. | Sign in again, verify token validity and scopes, and retry the OAuth flow. |
| No GitHub tools appear | The server was not added, Agent mode is off, or the host cannot use remote MCP. | Confirm the URL, switch to Agent mode, open Configure tools, and verify host support. |
| Works for one user but not the team | An organization or enterprise policy blocks MCP, OAuth, scopes, or the application. | Ask an administrator to review the MCP and OAuth policies. |
| Enterprise request reaches the wrong service | The standard endpoint was used for a data-residency organization. | Use the matching copilot-api.SUBDOMAIN.ghe.com/mcp endpoint. |
| PAT option is unavailable | The client does not support PAT auth or the account is an Enterprise Managed User. | Use OAuth where permitted, or ask the enterprise administrator about PAT enablement. |
| Cloud agent behaves differently from the IDE | Repository-level MCP has separate OAuth and approval constraints. | Read GitHub’s repository MCP guidance and review autonomous tool permissions. |
Performance, reliability, and cost considerations
A hosted server removes the local process, dependency installation, and machine availability from your setup. Request latency still depends on the client, GitHub service, network, repository size, and the specific tool. Keep prompts narrow, ask for the smallest useful result, and avoid repeatedly fetching large repository contexts.
For reliability, pin the correct endpoint for the account environment, keep authentication current, and recheck the official tool list when a workflow changes. Treat tool names and client UI as version-sensitive rather than permanent API contracts.
The MCP setup itself does not establish a separate GitHub pricing claim. Your access depends on the GitHub account, Copilot entitlement, and organization policy applicable to the client.
Or skip the browser setup
If your application only needs rendered pages, ScreenshotNeo provides a website screenshot API and MCP server. One GET request returns a PNG, JPEG, WebP, or PDF, and the MCP tools take_screenshot, get_page_info, and capture_pdf let Claude, Cursor, or another MCP client capture pages without maintaining a browser.
Cookie banners, newsletter popups, and chat widgets are removed before the shot. Bot checks, blank pages, failed loads, timeouts, and cache hits are never billed, and response headers report the page verdict and billing status. You can use the same server from an AI agent or call the API directly.
See the ScreenshotNeo API documentation for all options.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo includes full-page capture, CSS-selector element capture, device presets, custom headers and cookies, waits, request blocking, custom JavaScript, PDFs, signed links, async jobs, bulk capture, caching, and a usage API. It offers 1,000 screenshots a month free with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
FAQ
Do I need to run GitHub’s MCP server locally?
No. The documented remote workflow points your MCP client at GitHub’s hosted endpoint.
Which authentication method should I choose?
Use OAuth when your client and organization allow it. Use a PAT only when supported and limited to the required permissions.
Can I use the standard endpoint for GitHub Enterprise data residency?
No. Use the enterprise-specific copilot-api.SUBDOMAIN.ghe.com/mcp endpoint.
Why can a repository cloud-agent workflow differ from VS Code?
They are separate MCP contexts with different OAuth and approval support. Follow the repository MCP documentation for cloud agent and code review.
How do I know which tools are available?
Open the client’s tool configuration or picker after authentication and inspect the server’s current tool list.


