A comprehensive GitLab MCP server that enables AI clients to manage projects, merge requests, issues, pipelines, wiki, releases, tags, and milestones through multiple transports and authentication methods.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
form-data uses unsafe random function in form-data for choosing boundary
form-data: CRLF injection in form-data via unescaped multipart field names and filenames
process.env. You'll be asked to provide them before it can run.ComSpecDEFAULT_NULLDISCUSSION_IDDOWNLOAD_TOKEN_SECRETDOWNLOAD_TOKEN_TTLGITLAB_ALLOWED_PROJECT_IDSGITLAB_API_URL— api-url - GitLab API URL (replaces )GITLAB_COMMIT_FILES_PER_PAGEGITLAB_GRAPHQL_URLGITLAB_OAUTH_CLIENT_ID— Local OAuth: GITLAB_USE_OAUTH=true, , GITLAB_OAUTH_REDIRECT_URI, GITLAB_API_URLGITLAB_OAUTH_CLIENT_SECRETGITLAB_OAUTH_REDIRECT_URI— is for local OAuth (GITLAB_USE_OAUTH) only. It doesGITLAB_OAUTH_TOKEN_PATHGITLAB_OAUTH_TOKEN_SCRIPTGITLAB_OAUTH_TOKEN_SCRIPT_TIMEOUT_SECONDSGITLAB_PROJECT_IDGITLAB_READ_ONLY_MODE— read-only=true - Enable read-only mode (replaces , deprecated — prefer --permission-mode=readonly)GITLAB_TOKENISSUE_IIDLOG_LEVELMAX_REQUESTS_PER_MINUTE— Remote multi-user HTTP: STREAMABLE_HTTP=true, REMOTE_AUTHORIZATION=true (or GITLAB_MCP_OAUTH=true), MCP_TRUST_PROXY=true (behind a reverse proxy), =300, MCP_SERVER_URL or MCP_ALLOWED_HOSTS, HOST, PORTMAX_SESSIONS— Capacity limit: Server accepts up to concurrent sessions (default 1000)MCP_DANGEROUSLY_ALLOW_INSECURE_ISSUER_URL— No Set true for local HTTP dev onlyMCP_SERVER_NAME— Multiple side-by-side deployments: set a distinct per instance (e.g. gitlab-selfhosted-readonly) so clients, logs, and telemetry can tell them apartNOTE_IDPROJECT_IDSESSION_TIMEOUT_SECONDS— Session timeout: Auth tokens expire after (default 1 hour) of inactivity. After timeout, the client must send auth headers again. The transport session remains active.WORKSPACE_ROOTSTAR_HISTORY_REPOSTAR_HISTORY_OUTGH_TOKENGITHUB_TOKEN[](https://m8ven.ai/mcp/kirti12025-gitlab-mcp-bojrbx)