github / github/github-mcp-server
Hosted MCP cannot resolve review threads with a fine-grained PAT that succeeds via GraphQL
- Lenguaje dominante
- Go
- Estrellas
- 33k
- Forks
- 5k
- Merge medio
- 2 d 1 h
- PR fusionados (30 d)
- 52
Descripción
## Summary
GitHub hosted remote MCP fails to resolve pull request review threads with a fine-grained personal access token, returning:
```text
Resource not accessible by personal access token
```
The same token successfully performs both `unresolveReviewThread` and `resolveReviewThread` through GitHub GraphQL. This appears related to #2381, which reports a different hosted-MCP PR operation failing while the equivalent direct API request succeeds.
## Environment
- Server: GitHub-hosted remote MCP
- Endpoint: `https://api.githubcopilot.com/mcp/`
- Transport: Remote HTTP
- Client: OpenCode
- Authentication: fine-grained PAT supplied in the `Authorization: Bearer` header
- MCP toolsets: `repos,issues,pull_requests`
- Repository: `crsiebler/pogo-gbl-analyzer`
- Token repository permission: **Pull requests: Read and write**
- Approximate failure time: `2026-09-08 05:35 UTC`
## Reproduction
1. Configure the hosted server with `oauth: false`, the endpoint above, an `Authorization: Bearer {env:GITHUB_MCP_TOKEN}` header, and `X-MCP-Toolsets: repos,issues,pull_requests`.
2. Authenticate with a fine-grained PAT that has access to `crsiebler/pogo-gbl-analyzer` and **Pull requests: Read and write**.
3. Read review threads for `crsiebler/pogo-gbl-analyzer#10`.
4. Attempt to resolve `PRRT_kwDOPgvNY86gGnRD` with the MCP review-thread resolution tool.
5. Observe:
```text
failed to resolve review thread: Resource not accessible by personal access token
```
## Expected Behavior
The MCP operation resolves the review thread, matching GitHub GraphQL behavior for the same token.
## Actual Behavior
The MCP operation returns a personal-access-token authorization error. Other writes succeeded in the same MCP workflow: inline replies were posted to five pull request review-comment threads.
## Direct GraphQL Verification
Using the same fine-grained PAT outside MCP, unresolving the thread succeeded:
```bash
GH_TOKEN=github_pat_REDACTED gh api graphql \
-f query='mutation($threadId: ID!) {
unresolveReviewThread(input: {threadId: $threadId}) {
thread { id isResolved }
}
}' \
-f threadId='PRRT_kwDOPgvNY86gGnRD'
```
Response:
```json
{
"data": {
"unresolveReviewThread": {
"thread": {
"id": "PRRT_kwDOPgvNY86gGnRD",
"isResolved": false
}
}
}
}
```
Resolving it again with the same token also succeeded:
```bash
GH_TOKEN=github_pat_REDACTED gh api graphql \
-f query='mutation($threadId: ID!) {
resolveReviewThread(input: {threadId: $threadId}) {
thread { id isResolved }
}
}' \
-f threadId='PRRT_kwDOPgvNY86gGnRD'
```
Response:
```json
{
"data": {
"resolveReviewThread": {
"thread": {
"id": "PRRT_kwDOPgvNY86gGnRD",
"isResolved": true
}
}
}
}
```
## Impact
Agents can reply to inline review feedback but cannot complete the normal review workflow by resolving addressed threads through the hosted GitHub MCP server, despite the configured PAT being authorized for the underlying GraphQL mutation.
## Notes
- The token value is intentionally omitted.
- The hosted endpoint does not expose a locally inspectable server version.
- Inline reply timestamps immediately preceding the failure were `2026-09-08T05:35:45Z` and `2026-09-08T05:35:46Z`.
Guía de contribución
Línea de trabajo
Start at the hosted MCP review-thread resolution tool entry point and reproduce the failure using the listed endpoint, toolsets, and fine-grained PAT. Compare the operation's authorization path with the successful GraphQL resolveReviewThread mutation. Done means the MCP operation resolves the review thread with the same token and preserves the existing inline-reply behavior.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- github, go
- Área
- api, authentication, backend
- Tipo de issue
- Error
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Estado de actividad
- Activo
- Claridad
- Bastante claro
- Aptitud para principiantes
- 35/100