GitHub MCP server for marketing work: when to use GitHub's own, and when a guarded one
GitHub's official MCP server is the right choice for software work: hosted or local, dozens of toolsets, and writes that include merging pull requests. For a marketing agent the useful subset is narrower and safer — read the code a launch ships, and propose site changes as a draft pull request a person merges.
What already exists for this platform
GitHub maintains an official MCP server: hosted at api.githubcopilot.com/mcp/, or run locally from a container or a binary. It groups its tools into toolsets — repositories, issues, pull requests, Actions, code security, projects and more — and offers a --read-only flag that skips every write tool.
- Built for developers. It can create and update files (
create_or_update_file), manage branches, trigger workflows and merge pull requests (merge_pull_request). - Read-only is all or nothing. The flag removes every write; there is no middle setting of "propose, but never merge".
- Use it for coding. If your agent writes software, GitHub's own server is the better tool, and this guide does not suggest otherwise.
What a guarded, marketing-shaped server adds
| GitHub's official server | Agent Planners MCP | |
|---|---|---|
| GitHub tools | Dozens of toolsets | 15 reads, 7 writes |
| File writes | Any branch, including the default | One file per approval, on a new branch only; the default branch and .github/workflows are refused |
| Merging and deleting | Available as tools | Not offered; merge, delete and force arguments are refused |
| Pull requests | Created as asked | Opened as drafts; a person merges |
| Text from issues and files | Returned as-is | Marked untrusted, read as data never as instructions |
| Other platforms in the same session | No | 28 more platforms on one endpoint |
tools/list offers the same 22 GitHub tools of the 1012 on the endpoint. A key only sees the writes if it carries tools:write.How to configure it
- 1Create a key in API & MCP.
tools:readfor reading; addtools:writefor issues, comments, draft releases, branches, files and draft pull requests. - 2Connect GitHub under Integrations. The grant asks for
read:user,read:organdpublic_repo; private repositories need therepopermission, which a deployment opts into and a Re-authorize grants. - 3Add the server to Claude Code, Claude Desktop or Codex with the snippet below.
- 4Run
describe_permissions, thengithub__list_repos, and name repositories as owner/name.
claude mcp add --transport http agentplanners https://www.agentplanners.com/api/mcp \
--header "Authorization: Bearer ap_live_…"~/.codex/config.toml, with the key in an environment variable rather than the file: [mcp_servers.agentplanners] / url = "…/api/mcp" / bearer_token_env_var = "AGENTPLANNERS_API_KEY".The change flow, step by step
Nothing in the flow merges. The change reaches the default branch only when a person merges the pull request on GitHub.
- 1
github__get_treeandgithub__get_fileread what is there. - 2
github__create_branchmakes a new branch from the default branch; an existing name is never moved. - 3
github__put_filewrites one file per call on that branch. The current version is read first and a stale caller version is refused; the result shows the before and the after. - 4
github__create_pull_requestopens a draft. If the repository does not allow drafts, it retries once as a normal pull request and says so.
Frequently asked questions
- Is there an official GitHub MCP server?
- Yes. GitHub maintains one, hosted at api.githubcopilot.com/mcp/ or run locally, with toolsets for repositories, issues, pull requests, Actions and more, a --read-only flag, and write tools that include merging pull requests.
- Can an AI agent merge pull requests through MCP?
- With GitHub's official server, yes — merge_pull_request is one of its tools. This server deliberately offers no merge: an agent opens a draft pull request and a person merges it on GitHub.
- How do I give an AI agent safe write access to a GitHub repository?
- Limit it to new branches and draft pull requests: one file per approved write, never the default branch, never workflow files, no merge and no delete. Then the worst case is a draft pull request someone closes.