GitHub for AI agents

GitHub is a code hosting platform for Git repositories, pull requests, issues, and CI. Software teams use it to collaborate on and ship code. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Developer toolsOAuth 2.0MCP + RESTgithub.com
AUDIT LOG · GITHUBPOLICY: acme-support
09:41:07 · claude · u_8f2read
github.list_forks
List forks✓ allowed · 212ms
09:41:08 · claude · u_8f2read
github.get_gist
Get a gist✓ allowed · 164ms
09:41:09 · claude · u_8f2write
github.create_a_blob
Create a blob✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
github.delete_gist
Delete a gist✕ blocked · policy: deny
EVERY GITHUB CALL, ON THE RECORD
01 · USE CASES

What agents do in GitHub.

01

Triage and label an issue

Read a new issue, then add the right labels and assignees so it lands in the correct team's queue.

02

Open a pull request for review

Push a branch and open a pull request with a summary, leaving the merge itself for a human to approve.

03

Block a repository delete

Refuse to delete a repository directly, since that is a destructive action requiring explicit human approval.

02 · ACTIONS

896 GitHub actions, graded by risk.

Every GitHub action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

473

Look things up. Allowed by default.

  • github.get_gist
    Get a gist
  • github.get_a_tag
    Get a tag
  • github.get_feeds
    Get feeds
  • github.get_label
    Get a label
  • github.get_a_blob
    Get a blob
  • github.get_an_app
    Get an app
  • github.get_a_tree
    List repository files and directories
  • github.get_a_user
    Get a user
  • github.get_emojis
    Get emojis
  • github.list_forks
    List forks
  • github.list_teams
    List teams
  • github.list_users
    List users
  • github.get_license
    Get a license
  • github.get_octocat
    Get octocat
  • github.search_code
    Search code
  • github.get_a_branch
    Get a branch
+ 457 MORE

write

284

Create and change things. Allow, or ask the user first.

  • github.add_sub_issue
    Add sub-issue to an issue
  • github.create_a_blob
    Create a blob
  • github.create_a_fork
    Create a fork
  • github.create_a_gist
    Create a gist
  • github.create_a_team
    Create a team
  • github.create_a_tree
    Create a tree
  • github.create_branch
    Create a branch
  • github.update_a_gist
    Update a gist
  • github.update_a_team
    Update a team
  • github.create_a_label
    Create a label
  • github.update_a_label
    Update a label
  • github.create_a_commit
    Create a commit
  • github.create_an_issue
    Create an issue
  • github.update_an_issue
    Update an issue
  • github.create_a_release
    Create a release
  • github.create_user_list
    Create user list
+ 268 MORE

destructive

139

Delete, cancel or archive. Ask first, or deny outright.

  • github.delete_gist
    Delete a gist
  • github.delete_label
    Delete a label
  • github.delete_a_file
    Delete a file
  • github.delete_a_team
    Delete a team
  • github.delete_package
    Delete a package for the authenticated user
  • github.delete_project
    Delete a project
  • github.delete_artifact
    Delete an artifact
  • github.delete_app_token
    Delete an app token
  • github.delete_a_release
    Delete a release
  • github.delete_codespace
    Delete a codespace for the authenticated user
  • github.delete_milestone
    Delete a milestone
  • github.delete_user_list
    Delete User List
  • github.delete_deploy_key
    Delete a deploy key
  • github.delete_deployment
    Delete a deployment
  • github.delete_discussion
    Delete a discussion
  • github.cancel_sponsorship
    Cancel sponsorship
+ 123 MORE
03 · HOW IT WORKS

GitHub in three steps.

  1. 01Your users connect GitHubThey sign in to GitHub on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create a blob” can wait for the user, and “delete a gist” can be denied outright.
  3. 03Any agent can actYour agent calls GitHub through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('github', {
  read: 'allow',
  write: 'ask',        // create_a_blob
  destructive: 'deny',  // delete_gist
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How GitHub connects.

Users sign in to GitHub on Arc0 Connect and approve the scopes you request. Build with Arc0’s GitHub OAuth app, or bring your own so the GitHub consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same GitHub connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use GitHub from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

GitHub and Arc0, answered.

Q01

Can I use GitHub with Claude, ChatGPT or Cursor?

Yes. Connect GitHub to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the GitHub actions you allow.

Q02

How do users connect GitHub?

Users sign in to GitHub on Arc0 Connect and approve the scopes you request. Build with Arc0’s GitHub OAuth app, or bring your own so the GitHub consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which GitHub actions can my agent take?

896 in total: 473 read, 284 write and 139 destructive, such as “create a blob”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in GitHub?

Yes. Actions like “delete a gist” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call GitHub too?

Yes. The same GitHub connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug GitHub into your agent.

Your users connect GitHub once, under your brand. Your agent gets 896 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan