Title: support GitHub App installation‑token authentication (server‑to‑server) for MCP · Issue #311 · github/github-mcp-server · GitHub
Open Graph Title: support GitHub App installation‑token authentication (server‑to‑server) for MCP · Issue #311 · github/github-mcp-server
X Title: support GitHub App installation‑token authentication (server‑to‑server) for MCP · Issue #311 · github/github-mcp-server
Description: Describe the feature or problem you’d like to solve MCP can currently authenticate with: Personal Access Tokens (classic or fine‑grained) ✨ Soon 🚀: OAuth 2.0 device‑code flow via #132 Both approaches depend on credentials that are bound ...
Open Graph Description: Describe the feature or problem you’d like to solve MCP can currently authenticate with: Personal Access Tokens (classic or fine‑grained) ✨ Soon 🚀: OAuth 2.0 device‑code flow via #132 Both approach...
X Description: Describe the feature or problem you’d like to solve MCP can currently authenticate with: Personal Access Tokens (classic or fine‑grained) ✨ Soon 🚀: OAuth 2.0 device‑code flow via #132 Both approach...
Opengraph URL: https://github.com/github/github-mcp-server/issues/311
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"support GitHub App installation‑token authentication (server‑to‑server) for MCP","articleBody":"### Describe the feature or problem you’d like to solve\n\nMCP can currently authenticate with:\n\n* Personal Access Tokens (classic or fine‑grained) ✨\n* *Soon 🚀*: OAuth 2.0 device‑code flow via https://github.com/github/github-mcp-server/issues/132\n\nBoth approaches depend on credentials that are bound to a *human* account. \nIn enterprises(including ours) PAT creation is **often blocked**, and a device‑code token still requires a privileged “service user” to stay alive. \nThat leaves 24 × 7, org‑wide automation brittle and out of step with GitHub’s own security guidance.\n\n| Concern | Fine‑grained PAT | OAuth device‑code |\n|---------|-----------------|-------------------|\n| 👤 Identity coupling | Single user → breaks on off‑boarding | Needs service user |\n| ⏳ Secret lifetime | Up to 1 year; manual/scripted rotation | 8 h access token + 6 mo refresh token |\n| 🔍 Audit clarity | Traffic appears as that user | `oauth-app/\u003capp\u003e (as @user)` |\n| 🛡️ Org policies | PATs often disallowed | Refresh token is still long‑lived |\n\nSo, neither option is ideal for a headless, fleet‑wide MCP deployment.\n\n*Visual cheat‑sheet (PAT vs device‑code vs GitHub App installation):* \n\u003cimg width=\"1091\" alt=\"Image\" src=\"https://github.com/user-attachments/assets/fb2761b6-f829-433d-817b-ae1dc9e0a815\" /\u003e\n\n\n### Proposed solution\n\nAllow **GitHub App installation‑token (server‑to‑server) authentication**.\n\n* install the App at org/enterprise scope with the minimum perms MCP needs (`contents:read`, `metadata:read`, etc) \n* store only the App’s private key in AWS Secrets Manager / KMS\n* at runtime MCP signs a short‑lived JWT → exchanges it for a 60‑minute installation token → refreshes automatically\n* audit events appear as `github‑app/mcp‑server`\n\n**Benefits**\n\n* **zero human coupling** – no PATs, survives re‑orgs and off‑boarding\n* **short‑lived creds** – ≤ 60 min window if a token leaks\n* **governance** – admins can see/change App permissions \u0026 repo list in one click\n* **clear audit trail** – bot traffic is obvious (`github‑app/…`)\n* **future‑proof** – aligns MCP with GitHub’s move away from long‑lived personal tokens\n\n### Additional context\n\n**Suggested implementation approach**\n\n1. add `--auth=github-app` flag\n2. read `APP_ID`, `INSTALLATION_ID`, private‑key path/env var\n3. generate JWT (RS256) → `POST /app/installations/{id}/access_tokens`\n4. inject token into existing GitHub client; transparently refresh on HTTP 401/expiry\n\n*Architecture sketch of MCP + GitHub App flow:* \n\u003cimg width=\"572\" alt=\"Image\" src=\"https://github.com/user-attachments/assets/80bc9a9a-48d8-4ff8-9141-59b5d429f564\" /\u003e\n\nHappy to help spec out more, test, etc - just let me know what’s useful 🙌\n","author":{"url":"https://github.com/Svetlanko","@type":"Person","name":"Svetlanko"},"datePublished":"2025-04-18T21:47:14.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":6},"url":"https://github.com/311/github-mcp-server/issues/311"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:4ef9f1a1-934f-9dad-7c7d-e1b2749c3549 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | EA6C:703A5:286CA58:3AC6EC5:6A60EBE2 |
| html-safe-nonce | b4437cd879255923eb362219d2ad79f551479cc1eb511857d1120c92b2495dfa |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJFQTZDOjcwM0E1OjI4NkNBNTg6M0FDNkVDNTo2QTYwRUJFMiIsInZpc2l0b3JfaWQiOiIyMTQ0ODczNDY1MDE0OTcxMzYyIiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | e5f0b5ea19d13f7924ccec9b0028cec4a25c91f01ae40df3f2e638cfa738f4b9 |
| hovercard-subject-tag | issue:3005815856 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/github/github-mcp-server/311/issue_layout |
| twitter:image | https://opengraph.githubassets.com/95eb471e440fec9f83df158aea80c84b66d0480293e620789efc756e75e1116c/github/github-mcp-server/issues/311 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/95eb471e440fec9f83df158aea80c84b66d0480293e620789efc756e75e1116c/github/github-mcp-server/issues/311 |
| og:image:alt | Describe the feature or problem you’d like to solve MCP can currently authenticate with: Personal Access Tokens (classic or fine‑grained) ✨ Soon 🚀: OAuth 2.0 device‑code flow via #132 Both approach... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | Svetlanko |
| hostname | github.com |
| expected-hostname | github.com |
| None | 3ba36a464b9464992131f4003292a219fc87f92404b0dbe3fd1ef07f11102d0f |
| turbo-cache-control | no-preview |
| go-import | github.com/github/github-mcp-server git https://github.com/github/github-mcp-server.git |
| octolytics-dimension-user_id | 9919 |
| octolytics-dimension-user_login | github |
| octolytics-dimension-repository_id | 942771284 |
| octolytics-dimension-repository_nwo | github/github-mcp-server |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 942771284 |
| octolytics-dimension-repository_network_root_nwo | github/github-mcp-server |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 2cc5e4f897a27632dd600edfec4c737bea2f8338 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width