github / github/github-mcp-server

Hosted MCP cannot resolve review threads with a fine-grained PAT that succeeds via GraphQL

Open
#3,249 0 comments 0 reactions 0 assignees View on GitHub
ai:bug-report-review:unable-to-process bug server
Dominant language
Go
Stars
33k
Forks
5k
Avg merge
2d 1h
Merged PRs (30d)
52

Description

## Summary

GitHub hosted remote MCP fails to resolve pull request review threads with a fine-grained personal access token, returning:

```text
Resource not accessible by personal access token
```

The same token successfully performs both `unresolveReviewThread` and `resolveReviewThread` through GitHub GraphQL. This appears related to #2381, which reports a different hosted-MCP PR operation failing while the equivalent direct API request succeeds.

## Environment

- Server: GitHub-hosted remote MCP
- Endpoint: `https://api.githubcopilot.com/mcp/`
- Transport: Remote HTTP
- Client: OpenCode
- Authentication: fine-grained PAT supplied in the `Authorization: Bearer` header
- MCP toolsets: `repos,issues,pull_requests`
- Repository: `crsiebler/pogo-gbl-analyzer`
- Token repository permission: **Pull requests: Read and write**
- Approximate failure time: `2026-09-08 05:35 UTC`

## Reproduction

1. Configure the hosted server with `oauth: false`, the endpoint above, an `Authorization: Bearer {env:GITHUB_MCP_TOKEN}` header, and `X-MCP-Toolsets: repos,issues,pull_requests`.
2. Authenticate with a fine-grained PAT that has access to `crsiebler/pogo-gbl-analyzer` and **Pull requests: Read and write**.
3. Read review threads for `crsiebler/pogo-gbl-analyzer#10`.
4. Attempt to resolve `PRRT_kwDOPgvNY86gGnRD` with the MCP review-thread resolution tool.
5. Observe:

```text
failed to resolve review thread: Resource not accessible by personal access token
```

## Expected Behavior

The MCP operation resolves the review thread, matching GitHub GraphQL behavior for the same token.

## Actual Behavior

The MCP operation returns a personal-access-token authorization error. Other writes succeeded in the same MCP workflow: inline replies were posted to five pull request review-comment threads.

## Direct GraphQL Verification

Using the same fine-grained PAT outside MCP, unresolving the thread succeeded:

```bash
GH_TOKEN=github_pat_REDACTED gh api graphql \
-f query='mutation($threadId: ID!) {
unresolveReviewThread(input: {threadId: $threadId}) {
thread { id isResolved }
}
}' \
-f threadId='PRRT_kwDOPgvNY86gGnRD'
```

Response:

```json
{
"data": {
"unresolveReviewThread": {
"thread": {
"id": "PRRT_kwDOPgvNY86gGnRD",
"isResolved": false
}
}
}
}
```

Resolving it again with the same token also succeeded:

```bash
GH_TOKEN=github_pat_REDACTED gh api graphql \
-f query='mutation($threadId: ID!) {
resolveReviewThread(input: {threadId: $threadId}) {
thread { id isResolved }
}
}' \
-f threadId='PRRT_kwDOPgvNY86gGnRD'
```

Response:

```json
{
"data": {
"resolveReviewThread": {
"thread": {
"id": "PRRT_kwDOPgvNY86gGnRD",
"isResolved": true
}
}
}
}
```

## Impact

Agents can reply to inline review feedback but cannot complete the normal review workflow by resolving addressed threads through the hosted GitHub MCP server, despite the configured PAT being authorized for the underlying GraphQL mutation.

## Notes

- The token value is intentionally omitted.
- The hosted endpoint does not expose a locally inspectable server version.
- Inline reply timestamps immediately preceding the failure were `2026-09-08T05:35:45Z` and `2026-09-08T05:35:46Z`.

Contributor guide

Open the contributing guide

Research direction

Start at the hosted MCP review-thread resolution tool entry point and reproduce the failure using the listed endpoint, toolsets, and fine-grained PAT. Compare the operation's authorization path with the successful GraphQL resolveReviewThread mutation. Done means the MCP operation resolves the review thread with the same token and preserves the existing inline-reply behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, go
Domain
api, authentication, backend
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.