github / github/github-mcp-server

Hosted MCP cannot resolve review threads with a fine-grained PAT that succeeds via GraphQL

Aperta
#3,249 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
ai:bug-report-review:unable-to-process bug server
Lingua principale
Go
Stelle
33k
Fork
5k
Merge medio
2g 1h
PR unite (30g)
52

Descrizione

## Summary

GitHub hosted remote MCP fails to resolve pull request review threads with a fine-grained personal access token, returning:

```text
Resource not accessible by personal access token
```

The same token successfully performs both `unresolveReviewThread` and `resolveReviewThread` through GitHub GraphQL. This appears related to #2381, which reports a different hosted-MCP PR operation failing while the equivalent direct API request succeeds.

## Environment

- Server: GitHub-hosted remote MCP
- Endpoint: `https://api.githubcopilot.com/mcp/`
- Transport: Remote HTTP
- Client: OpenCode
- Authentication: fine-grained PAT supplied in the `Authorization: Bearer` header
- MCP toolsets: `repos,issues,pull_requests`
- Repository: `crsiebler/pogo-gbl-analyzer`
- Token repository permission: **Pull requests: Read and write**
- Approximate failure time: `2026-09-08 05:35 UTC`

## Reproduction

1. Configure the hosted server with `oauth: false`, the endpoint above, an `Authorization: Bearer {env:GITHUB_MCP_TOKEN}` header, and `X-MCP-Toolsets: repos,issues,pull_requests`.
2. Authenticate with a fine-grained PAT that has access to `crsiebler/pogo-gbl-analyzer` and **Pull requests: Read and write**.
3. Read review threads for `crsiebler/pogo-gbl-analyzer#10`.
4. Attempt to resolve `PRRT_kwDOPgvNY86gGnRD` with the MCP review-thread resolution tool.
5. Observe:

```text
failed to resolve review thread: Resource not accessible by personal access token
```

## Expected Behavior

The MCP operation resolves the review thread, matching GitHub GraphQL behavior for the same token.

## Actual Behavior

The MCP operation returns a personal-access-token authorization error. Other writes succeeded in the same MCP workflow: inline replies were posted to five pull request review-comment threads.

## Direct GraphQL Verification

Using the same fine-grained PAT outside MCP, unresolving the thread succeeded:

```bash
GH_TOKEN=github_pat_REDACTED gh api graphql \
-f query='mutation($threadId: ID!) {
unresolveReviewThread(input: {threadId: $threadId}) {
thread { id isResolved }
}
}' \
-f threadId='PRRT_kwDOPgvNY86gGnRD'
```

Response:

```json
{
"data": {
"unresolveReviewThread": {
"thread": {
"id": "PRRT_kwDOPgvNY86gGnRD",
"isResolved": false
}
}
}
}
```

Resolving it again with the same token also succeeded:

```bash
GH_TOKEN=github_pat_REDACTED gh api graphql \
-f query='mutation($threadId: ID!) {
resolveReviewThread(input: {threadId: $threadId}) {
thread { id isResolved }
}
}' \
-f threadId='PRRT_kwDOPgvNY86gGnRD'
```

Response:

```json
{
"data": {
"resolveReviewThread": {
"thread": {
"id": "PRRT_kwDOPgvNY86gGnRD",
"isResolved": true
}
}
}
}
```

## Impact

Agents can reply to inline review feedback but cannot complete the normal review workflow by resolving addressed threads through the hosted GitHub MCP server, despite the configured PAT being authorized for the underlying GraphQL mutation.

## Notes

- The token value is intentionally omitted.
- The hosted endpoint does not expose a locally inspectable server version.
- Inline reply timestamps immediately preceding the failure were `2026-09-08T05:35:45Z` and `2026-09-08T05:35:46Z`.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start at the hosted MCP review-thread resolution tool entry point and reproduce the failure using the listed endpoint, toolsets, and fine-grained PAT. Compare the operation's authorization path with the successful GraphQL resolveReviewThread mutation. Done means the MCP operation resolves the review thread with the same token and preserves the existing inline-reply behavior.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
github, go
Ambito
api, authentication, backend
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Attiva
Chiarezza
Abbastanza chiara
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.