Enable GitHub API OAuth and document public clients (#395)

Enable GitHub remote MCP OAuth with the tested public client credentials
and callback, and add GitHub to the API marketplace. Add GitHub and
Slack README warnings explaining public OAuth client identity.

Validation: JSON/config checks passed; live OAuth was not rerun.
This commit is contained in:
willwang-openai
2026-09-28 10:08:07 -07:00
committed by GitHub
parent 1dc195897a
commit 5fd93af4cd
5 changed files with 39 additions and 2 deletions
+12
View File
@@ -652,6 +652,18 @@
"interface": {
"displayName": "Qodo"
}
},
{
"name": "github",
"source": {
"source": "local",
"path": "./plugins/github"
},
"policy": {
"installation": "AVAILABLE",
"authentication": "ON_INSTALL"
},
"category": "Developer Tools"
}
]
}
+2 -1
View File
@@ -1,6 +1,6 @@
{
"name": "github",
"version": "0.1.11",
"version": "0.1.12",
"description": "Inspect repositories, triage pull requests and issues, debug CI, and publish changes through a hybrid GitHub connector and CLI workflow.",
"author": {
"name": "OpenAI",
@@ -26,6 +26,7 @@
"actions"
],
"apps": "./.app.json",
"mcpServers": "./.mcp.json",
"interface": {
"displayName": "GitHub",
"shortDescription": "Triage PRs, issues, CI, and publish flows",
+6 -1
View File
@@ -3,7 +3,12 @@
"github": {
"type": "http",
"url": "https://api.githubcopilot.com/mcp/",
"bearer_token_env_var": "GITHUB_PAT_TOKEN"
"oauth": {
"client_id": "Iv23liZgMPSa3samkW2k",
"client_secret": "824c9cd33b8de28213447789c7517ad720138be5",
"callback_port": 12799,
"callback_url": "http://127.0.0.1:12799/callback/ymAt1Jnt6ghN"
}
}
}
}
+9
View File
@@ -0,0 +1,9 @@
# GitHub
**Warning: this plugin is a public OAuth client.** Its OAuth client ID and
`client_secret` are intentionally distributed in [`.mcp.json`](.mcp.json).
Anyone can copy these values, so they cannot prove that a request comes from this
plugin. User access and refresh tokens must still be kept private.
For more context, see Okta's
[The Identity of OAuth Public Clients](https://developer.okta.com/blog/2022/06/01/oauth-public-client-identity).
+10
View File
@@ -0,0 +1,10 @@
# Slack
**Warning: this plugin is a public OAuth client.** Its OAuth `client_id` is
published in [`.mcp.json`](.mcp.json), and no client secret is included. The public
ID can be copied to impersonate the client in OAuth requests; it cannot prove
that a request comes from this plugin. Access to a Slack account still requires
user authorization.
For more context, see Okta's
[The Identity of OAuth Public Clients](https://developer.okta.com/blog/2022/06/01/oauth-public-client-identity).