[{"data":1,"prerenderedAt":42},["ShallowReactive",2],{"$f3jeg9qwnr1zs3":3},{"href":4,"title":5,"description":6,"kind":7,"mark":8,"planned":9,"contributors":10,"provenance":8,"html":11,"headings":12},"\u002Fdocs\u002Ftools\u002Fgithub","GitHub","Issues, pull requests, reviews and checks, through GitHub's own hosted MCP server.","integrates",null,false,[],"\u003Ch2 id=\"what-a-member-can-do\">What a member can do\u003C\u002Fh2>\n\u003Cp>With GitHub bound, a member can work in the repositories its account can see: read and file issues, comment,\nopen and review pull requests, read branches and files, and read check runs and Actions. Each task names the\nGitHub tools it may call, such as \u003Ccode>github.issue_read\u003C\u002Fcode> or \u003Ccode>github.create_pull_request\u003C\u002Fcode>; a tool the task does not\nname is refused, whatever the binding allows.\u003C\u002Fp>\n\u003Cp>Code itself is written in a \u003Ca href=\"\u002Fdocs\u002Ftools\u002Fworkspaces\">workspace\u003C\u002Fa>: a throwaway copy of the repository for one run,\npushed back to a branch.\u003C\u002Fp>\n\u003Ch2 id=\"who-connects-it\">Who connects it\u003C\u002Fh2>\n\u003Cp>Whoever binds GitHub decides which account a member acts as. GitHub's hosted MCP server acts as \u003Cstrong>the account\nthat created the token\u003C\u002Fstrong>, so every issue, comment, review and pull request is attributed to that account.\u003C\u002Fp>\n\u003Cp>A binding can sit on the enterprise, a team, a member, a role or a task, and the one further down replaces the one\nabove: task, then role, then member, then team, then enterprise. Bind GitHub on a member, with a token created by\nthat member's own GitHub account, and the member's work appears under its own name and avatar. Bind it on the\nenterprise with your own token, and everything any member does appears as you.\u003C\u002Fp>\n\u003Ch2 id=\"what-waits-for-you\">What waits for you\u003C\u002Fh2>\n\u003Cp>Merging is the decision to keep for yourself. A task that names the merge tool, \u003Ccode>github.merge_pull_request\u003C\u002Fcode>, has to\ndeclare a gate on it, or it cannot be saved; with the gate, the run writes a summary of what goes live, and nothing\nmerges until you approve it on \u003Cstrong>Gates\u003C\u002Fstrong>. You can send it back with the changes you want instead.\u003C\u002Fp>\n\u003Cp>Name GitHub tools one by one on a task that merges, rather than the whole GitHub toolset, so the merge is always the\ngated tool. Anything else a task does on GitHub goes ahead as the task allows, unless the task declares a gate on it\ntoo.\u003C\u002Fp>\n\u003Ch2 id=\"setup\">Setup\u003C\u002Fh2>\n\u003Ch3 id=\"the-server\">The server\u003C\u002Fh3>\n\u003Cp>Leave \u003Cstrong>MCP server URL\u003C\u002Fstrong> blank when you add the tool: it defaults to GitHub's hosted server,\n\u003Ccode>https:\u002F\u002Fapi.githubcopilot.com\u002Fmcp\u002F\u003C\u002Fcode>. The binding offers GitHub's issues, repositories, pull requests, checks and\nActions toolsets. To narrow them, add the binding over the \u003Ca href=\"\u002Fdocs\u002Fapi\">API\u003C\u002Fa> with \u003Ccode>toolsets\u003C\u002Fcode>, a comma-separated\nlist such as \u003Ccode>issues,pull_requests\u003C\u002Fcode>; the portal's form has no field for it.\u003C\u002Fp>\n\u003Ch3 id=\"the-token\">The token\u003C\u002Fh3>\n\u003Cp>Use a \u003Cstrong>classic\u003C\u002Fstrong> personal access token with these scopes:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>repo read:org\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Add \u003Ccode>workflow\u003C\u002Fcode> if a task changes files under \u003Ccode>.github\u002Fworkflows\u002F\u003C\u002Fcode>, and \u003Ccode>project\u003C\u002Fcode> if a task edits GitHub Projects.\nThe token is sent to GitHub as \u003Ccode>Authorization: Bearer &lt;token&gt;\u003C\u002Fcode>; the model never sees it.\u003C\u002Fp>\n\u003Ch3 id=\"custom-props-for-workspaces\">Custom props, for workspaces\u003C\u002Fh3>\n\u003Cp>A \u003Ca href=\"\u002Fdocs\u002Ftools\u002Fworkspaces\">workspace\u003C\u002Fa> clones and pushes through the code host binding whose \u003Ccode>git.host\u003C\u002Fcode> matches the\nrepository's. To let workspaces use this binding for repositories on GitHub, open it on \u003Cstrong>Tools\u003C\u002Fstrong>, press\n\u003Cstrong>Custom props\u003C\u002Fstrong> at the top right of the form, and add these keys (or send them as \u003Ccode>props\u003C\u002Fcode> over the\n\u003Ca href=\"\u002Fdocs\u002Fapi\">API\u003C\u002Fa>):\u003C\u002Fp>\n\u003Cdiv class=\"prose__table\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Key\u003C\u002Fth>\n\u003Cth>Value\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>\u003Ccode>git.host\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>github.com\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Ccode>git.username\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>x-access-token\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Ccode>git.repoTemplate\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>https:\u002F\u002Fgithub.com\u002F{repo}.git\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n\u003Cp>\u003Ccode>git.repoTemplate\u003C\u002Fcode> lets a run name its repository as \u003Ccode>owner\u002Fname\u003C\u002Fcode>. Without \u003Ccode>git.host\u003C\u002Fcode>, a workspace offers this token\nto no host: a public repository still clones, and nothing pushes.\u003C\u002Fp>\n\u003Cp>Add \u003Ccode>git.repo\u003C\u002Fcode> too only when every run that reaches this binding works in one repository, for runs that name none:\n\u003Ccode>https:\u002F\u002Fgithub.com\u002Facme\u002Fsite.git\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>A run reads the nearest GitHub binding it reaches, and only that one. Add the keys to every GitHub binding a run can\nreach first: the enterprise's, and each member's own. Tools flags a binding that lacks them while another GitHub\nbinding has them.\u003C\u002Fp>\n\u003Ch3 id=\"giving-a-member-its-own-github-account\">Giving a member its own GitHub account\u003C\u002Fh3>\n\u003Cp>A member joins GitHub the way a person would: its own account, signed up with its own Zero Human address, and\nadded to your organisation as a member on a seat. GitHub's terms allow a person to run a machine account as well as\ntheir own; whoever sets it up accepts the terms for it and is responsible for what it does.\u003C\u002Fp>\n\u003Cp>Every GitHub email for the member (the launch code, the invitation, sign-in codes) goes to the member's own\naddress, and appears in the \u003Cstrong>Inbox\u003C\u002Fstrong> on its member page in the portal. When a step says GitHub has sent an\nemail, open that Inbox.\u003C\u002Fp>\n\u003Cp>Work in a \u003Cstrong>separate browser profile or a private window\u003C\u002Fstrong>: your usual browser is signed in to GitHub as you, and\nthe token has to be created while GitHub is signed in as the member.\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Create the account.\u003C\u002Fstrong> At \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fsignup\">github.com\u002Fsignup\u003C\u002Fa>, sign up with the member's email\naddress. Choose a username that matches the member's name: it shows on every comment and commit. Enter the\nlaunch code from the member's Inbox. Stay on the free plan; the seat comes from your organisation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Turn on two-factor authentication.\u003C\u002Fstrong> Settings → Password and authentication. Use an authenticator app, and\nkeep the recovery codes with the password.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Invite it to your organisation.\u003C\u002Fstrong> As an owner, in your usual browser: People → Invite member, as a\n\u003Cstrong>Member\u003C\u002Fstrong>. Add it to the teams that reach the repositories it will work in: the MCP server only sees what the\naccount can see. Accept the invitation in the separate profile.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Set up the profile.\u003C\u002Fstrong> Name, avatar, and the member's role as its bio. Make sure its email address is\nverified and primary: commits are only linked to an account whose verified address matches.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Create the token.\u003C\u002Fstrong> Settings → Developer settings → Personal access tokens → Tokens (classic). Name it\n\u003Ccode>Zero Human OS\u003C\u002Fcode>, choose the longest expiry your organisation allows (and note the date: the binding stops\nworking when it lapses), tick the scopes above, and copy the token. If your organisation uses SAML single\nsign-on, authorise the token for it.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Bind it.\u003C\u002Fstrong> In the portal, on the member's page → \u003Cstrong>Tools\u003C\u002Fstrong>, remove any existing \u003Ccode>github\u003C\u002Fcode> binding first, then\n\u003Cstrong>Add tool\u003C\u002Fstrong>: type \u003Ccode>github\u003C\u002Fcode>, auth \u003Cstrong>Bearer token \u002F PAT\u003C\u002Fstrong>, and the token.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Check it.\u003C\u002Fstrong> Run a task that comments on an issue or opens a pull request as the member. It should appear\nunder the member's name and avatar, and the run page shows the call and its result.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch2 id=\"troubleshooting\">Troubleshooting\u003C\u002Fh2>\n\u003Cdiv class=\"prose__table\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>What you see\u003C\u002Fth>\n\u003Cth>Why\u003C\u002Fth>\n\u003Cth>What to do\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>A comment or pull request appears as you\u003C\u002Ftd>\n\u003Ctd>The token was created while GitHub was signed in as you\u003C\u002Ftd>\n\u003Ctd>Create a new token in the separate profile, then remove the binding and bind the new one\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>The launch code or invitation never arrives\u003C\u002Ftd>\n\u003Ctd>The member's email address is wrong\u003C\u002Ftd>\n\u003Ctd>Check the email on the member page\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Ccode>Not Found\u003C\u002Fcode> on a repository the member should reach\u003C\u002Ftd>\n\u003Ctd>The account is not on a team with access, or the token is not authorised for single sign-on\u003C\u002Ftd>\n\u003Ctd>Add it to the team, or authorise the token for your organisation\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Ccode>not_mcp_url\u003C\u002Fcode> when saving\u003C\u002Ftd>\n\u003Ctd>The URL is GitHub's REST API, not its MCP server\u003C\u002Ftd>\n\u003Ctd>Leave the URL blank, or use \u003Ccode>https:\u002F\u002Fapi.githubcopilot.com\u002Fmcp\u002F\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>The invitation fails, or the member is removed\u003C\u002Ftd>\n\u003Ctd>Your organisation requires two-factor authentication\u003C\u002Ftd>\n\u003Ctd>Turn it on (step 2), then invite again\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Calls fail with an auth error after working\u003C\u002Ftd>\n\u003Ctd>The token expired or was revoked, or the account left the organisation\u003C\u002Ftd>\n\u003Ctd>Create a new token and bind it\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>A workspace run fails \u003Ccode>workspace_repo_no_clone_address\u003C\u002Fcode>, or its push is refused\u003C\u002Ftd>\n\u003Ctd>The binding the run reaches has no \u003Ccode>git.*\u003C\u002Fcode> custom props, so \u003Ccode>owner\u002Fname\u003C\u002Fcode> cannot be expanded or the token is not offered to \u003Ccode>github.com\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>Add the custom props above, on every GitHub binding a run can reach first: each member's own binding too\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n",[13,17,20,23,26,30,33,36,39],{"id":14,"text":15,"level":16,"planned":9},"what-a-member-can-do","What a member can do",2,{"id":18,"text":19,"level":16,"planned":9},"who-connects-it","Who connects it",{"id":21,"text":22,"level":16,"planned":9},"what-waits-for-you","What waits for you",{"id":24,"text":25,"level":16,"planned":9},"setup","Setup",{"id":27,"text":28,"level":29,"planned":9},"the-server","The server",3,{"id":31,"text":32,"level":29,"planned":9},"the-token","The token",{"id":34,"text":35,"level":29,"planned":9},"custom-props-for-workspaces","Custom props, for workspaces",{"id":37,"text":38,"level":29,"planned":9},"giving-a-member-its-own-github-account","Giving a member its own GitHub account",{"id":40,"text":41,"level":16,"planned":9},"troubleshooting","Troubleshooting",1791124519791]