Skip to main content

Set up the GitLab MCP server

GitLab ships an MCP server inside GitLab itself, so there is no separate service to deploy: MintMCP connects to the /api/v4/mcp endpoint on GitLab.com or on your Self-Managed or Dedicated instance. This guide covers allowing MCP access in GitLab, installing the server from MintMCP's recommended servers, and connecting each user with their own GitLab login, so every tool call runs with that user's existing GitLab permissions.

GitLab's MCP server is in beta, and GitLab adds tools to it with each GitLab release. Check GitLab's MCP server documentation for the current status and the tiers and offerings it supports.

Prerequisites​

  • A MintMCP admin account
  • On GitLab.com, the Owner role on your top-level group. On Self-Managed or Dedicated, a GitLab administrator
  • A Self-Managed or Dedicated instance that MintMCP can reach over the internet, with a GitLab version that includes the MCP server
  • A GitLab account for each user who will connect

Allow MCP access in GitLab​

GitLab controls MCP client access with one setting, and where it lives depends on how you run GitLab:

  • GitLab.com: an Owner of your top-level group goes to Settings > General > Permissions and group features, selects Allow connection to GitLab under MCP client access, and saves. See Allow access to the MCP server.
  • Self-Managed or Dedicated: the instance setting is the only one that applies, and new instances usually have it on already, so an administrator only needs to confirm that Allow connection to GitLab is selected under MCP client access in Admin > Settings > General > Visibility and access controls. Group-level settings have no effect here. See instance settings.

Add GitLab to MintMCP​

GitLab supports OAuth with dynamic client registration, so MintMCP registers itself as an OAuth client automatically and there are no client credentials to configure.

  1. In MintMCP, go to MCP store and open the Recommended servers tab.
  2. Select GitLab to open the configuration panel. The OAuth authorization method and the Per-user credentials connection type are pre-set from the catalog.
  3. Set the server URL:
    • GitLab.com: https://gitlab.com/api/v4/mcp
    • Self-Managed or Dedicated: https://<your-gitlab-host>/api/v4/mcp
  4. Click Install.

When users first connect, MintMCP redirects them to GitLab. They sign in, including single sign-on or two-factor authentication if your GitLab requires it, and approve the mcp scope. GitLab labels the request as coming from [Unverified Dynamic Application] MintMCP Client with a warning to trust it before authorizing, which is how GitLab shows every dynamically registered client, so users can approve it. GitLab administrators see an extra warning that the client will act as an administrator, because the token carries the signed-in user's full role, so connect with a regular GitLab account rather than an admin one.

What the connector exposes​

GitLab maintains the list of tools its MCP server exposes, and the set you get depends on your GitLab version and tier, so check GitLab's MCP server tools reference for the current list. The server lets an agent find projects and read repository files, open and review merge requests, create and update work items and comments, inspect and run CI/CD pipelines and jobs, and search.

Every call runs as the signed-in GitLab user, so an agent can reach only the groups and projects that user can already see, and can only make changes that user's role allows.

Security considerations​

  • Each user authenticates individually through OAuth, so MintMCP's audit log attributes every tool call to that user's GitLab identity and GitLab applies that user's role on every request.
  • The server includes write tools that commit code, create and merge merge requests, and run pipelines. Use tool customization to expose only the tools each team needs, for example read-only tools for a code-review assistant.
  • Shared credentials are not recommended, because a single login would run every user under one person's GitLab permissions and drop per-user attribution.
  • Access follows the user's GitLab account, so removing a user from a group or blocking them in GitLab ends what an agent can reach through MintMCP. Group Owners and administrators can also turn MCP access off entirely with the same setting used to allow it.

Troubleshooting​

  • Authorization fails with 403 Forbidden - MCP server not enabled for any of your groups (GitLab.com) or 404 Not Found (Self-Managed or Dedicated): MCP client access is off for your top-level group or instance. Turn it on as described in Allow MCP access in GitLab, then click Re-authorize in MintMCP.
  • Authorization fails with OAuth authorization required after a long sign-in: the authorization request expired while the user was signing in. Now that they have a GitLab session, click Re-authorize in MintMCP to start a fresh request.
  • The install cannot reach the server: for Self-Managed or Dedicated, check that the URL ends in /api/v4/mcp and that your instance is reachable from the internet. Your GitLab version must also include the MCP server.
  • A tool GitLab documents is missing: the tool may need a newer GitLab version or a higher tier than yours. Compare GitLab's tool reference against your version.
  • A project or group the user expects is missing: the user's GitLab account does not have access to it. Check whether they can open it in GitLab directly.

Next steps​