
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
mcparmory-github
Advanced tools
Base URL: https://api.github.com
| Category | Developer Tools |
| Tools | 897 |
| Auth | Bearer Token, OAuth2 |
OAUTH2_CLIENT_ID=YOUR_OAUTH2_CLIENT_ID \
OAUTH2_CLIENT_SECRET=YOUR_OAUTH2_CLIENT_SECRET \
OAUTH2_SCOPES=YOUR_OAUTH2_SCOPES \
BEARER_TOKEN=YOUR_BEARER_TOKEN \
uvx mcparmory-github
pip install mcparmory-github
OAUTH2_CLIENT_ID=YOUR_OAUTH2_CLIENT_ID \
OAUTH2_CLIENT_SECRET=YOUR_OAUTH2_CLIENT_SECRET \
OAUTH2_SCOPES=YOUR_OAUTH2_SCOPES \
BEARER_TOKEN=YOUR_BEARER_TOKEN \
mcparmory-github
Add to your MCP client config (e.g. Claude Desktop, Cursor, Codex):
{
"mcpServers": {
"github": {
"command": "uvx",
"args": ["mcparmory-github"],
"env": {
"OAUTH2_CLIENT_ID": "YOUR_OAUTH2_CLIENT_ID",
"OAUTH2_CLIENT_SECRET": "YOUR_OAUTH2_CLIENT_SECRET",
"OAUTH2_SCOPES": "YOUR_OAUTH2_SCOPES",
"BEARER_TOKEN": "YOUR_BEARER_TOKEN"
}
}
}
}
Set OAUTH2_SCOPES to a comma-separated list of scopes your app requires (e.g. OAUTH2_SCOPES=scope_a,scope_b). Some OAuth2 providers may also use additional scope env vars such as OAUTH2_USER_SCOPES; open .env to see all generated scope buckets and descriptions.
Set the following environment variables (via MCP client env config, shell export, or .env file):
OAUTH2_CLIENT_ID — OAuth2 client IDOAUTH2_CLIENT_SECRET — OAuth2 client secretOAUTH2_SCOPES — OAuth2 scopes (comma-separated)BEARER_TOKEN — Bearer tokenDo not commit credentials to version control.
Add this redirect URI to your OAuth provider's allowed redirect URIs:
http://localhost:9400/callback
If you change OAUTH2_CALLBACK_PORT in .env, update the redirect URI to match.
On first use, a browser window opens automatically for OAuth authorization. Grant access when prompted — tokens are saved to tokens/oauth2_tokens.json and refreshed automatically.
Re-authorization: Delete tokens/oauth2_tokens.json and restart the server.
First, configure your credentials in .env (see Credentials above).
pip install -r requirements.txt
python server.py
Edit .mcp.json and replace <SERVER_DIR> with the absolute path to this directory, then add to your MCP client configuration.
Example (if server is at /home/user/mcp-servers/github):
{
"mcpServers": {
"github": {
"command": "python",
"args": ["/home/user/mcp-servers/github/server.py"]
}
}
}
docker run -p 8000:8000 -p 9400:9400 -v ./tokens:/app/tokens \
-e OAUTH2_CLIENT_ID=YOUR_OAUTH2_CLIENT_ID \
-e OAUTH2_CLIENT_SECRET=YOUR_OAUTH2_CLIENT_SECRET \
-e OAUTH2_SCOPES=YOUR_OAUTH2_SCOPES \
-e BEARER_TOKEN=YOUR_BEARER_TOKEN \
ghcr.io/mcparmory/github:latest
First, configure your credentials in .env (see Credentials above).
docker build -t github .
mkdir -p tokens
docker run -p 8000:8000 -p 9400:9400 -v ./tokens:/app/tokens --env-file .env github
Before running, make sure ports 8000, 9400 are free. If you changed the callback port in .env, update the -p port mapping and your OAuth provider's redirect URI to match.
On first run, the server prints an authorization URL — check docker logs for the URL. Open it in your browser to complete OAuth consent. Tokens are persisted to ./tokens/ via the volume mount so re-authorization is not needed on subsequent runs.
For Docker, use SSE transport in your MCP client config:
{
"mcpServers": {
"github": {
"type": "sse",
"url": "http://localhost:8000/sse"
}
}
}
.env - Credentials and server configuration.mcp.json - MCP client config templateDockerfile - Container buildLICENSE - MIT license for this generated coderequirements.txt - Python dependenciesREADME.md - This fileserver.py - MCP server entry point_auth.py - Authentication handlers_models.py - Request/response models_validators.py - Input validationNote: Files starting with . are hidden by default on macOS/Linux. Use ls -a in terminal or enable "Show hidden files" in your file manager to see .env and .mcp.json.
Generated by MCP Blacksmith · Quickstart docs · Report a bug
FAQs
Manage repositories, users, releases, and automate GitHub workflows
We found that mcparmory-github demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.