שרת MCP מאומת: GitLab

שרת ה-MCP של GitLab, הכלים שלו נספרו בריצה חיה על Mac אמיתי.

  • הכלים נספרו2026-08-03macOS 15.7.7
  • חבילה@zereight/mcp-gitlab 2.1.46
  • מדווח על עצמוzereight-gitlab-mcp-server 2.1.46
  • פרוטוקול MCP2025-06-18
  • סביבת ריצהv24.18.0

רשימת הכלים למטה היא לכידה חיה מהשרת הרץ; קריאת כלי מאומתת עדיין ממתינה להרשאות.

התשובה הקצרה

אומת לאחרונה 2026-08-03

שרת ה-MCP של GitLab מחבר עוזר AI ל-GitLab, כך שהוא יכול לקרוא ולפעול על הפרויקטים, בקשות המיזוג, ה-issues, הענפים והפייפליינים שלכם במקום שתלחצו בממשק האינטרנט. זהו שרת קהילתי ולא מוצר של GitLab: הוא מפורסם ל-npm בשם ‎@zereight/mcp-gitlab על ידי המפתח zereight, הוא תחת רישיון MIT, והוא רץ על ה-Mac שלכם על גבי stdio. היה פעם שרת ייחוס רשמי, ‎@modelcontextprotocol/server-gitlab, אבל npm מסמן אותו כלא נתמך עוד והמאגר שלו נמצא בארכיון, בעוד החבילה הזו פרסמה גרסה יום לפני שהרצנו אותה ומורדת בערך פי עשרים יותר, ולכן היא זו שבעמוד הזה. אישור הגישה שלו הוא personal access token של GitLab במשתנה סביבה אחד, והשרת אפילו לא עולה כשהמשתנה הזה ריק. מה שהוכחנו על החיבור עצמו, ומה שעדיין ממתין לטוקן אמיתי, פרוש למטה. הפעלנו אותו עם ערך מציין מקום במשתנה הזה ולא עם טוקן אמיתי: השרת עלה, השלים את לחיצת היד של MCP וענה ל-tools/list עם כל 116 הכלים, שהם הטבלה שלמטה, מילה במילה. הקריאה שבה שאלנו את GitLab כמי אנחנו מחוברים, whoami, יצאה מה-Mac וחזרה עם 401 Unauthorized של GitLab עצמה, כי ערך מציין מקום אינו טוקן. כך שטבלת הכלים נספרה בריצה חיה וכל שגיאה בעמוד הזה היא פלט שלכדנו, בעוד קריאה מאומתת מוצלחת עדיין ממתינה לטוקן שתיצרו בעצמכם. [1][3][2][8][9]

  • כלים

    116, נספרו בריצה חיה

  • אישורי גישה

    personal access token של GitLab [5][10]

  • ערוץ תקשורת

    stdio, רץ על ה-Mac שלכם [1][4]

  • מתחזק

    zereight, קהילתי [1][3]

  • הורדות

    114,673 בשבוע האחרון [2]

  • רישיון

    MIT [1][3]

אימות

איך שרת ה-MCP הזה אומת.

השיטה

הרצנו את השרת עם npx על גבי stdio עם שני משתני סביבה ולא יותר: GITLAB_PERSONAL_ACCESS_TOKEN שהחזיק ערך מציין מקום דמה בסגנון glpat ולא טוקן אמיתי, ו-GITLAB_API_URL שהוגדר ל-‎https://gitlab.com/api/v4, והשרת רשם את הכתובת הזו בחזרה אלינו ככתובת ה-API שהוגדרה לו. הוא השלים את לחיצת היד של MCP, הציג את עצמו כ-zereight-gitlab-mcp-server 2.1.46 על פרוטוקול 2025-06-18, וענה ל-tools/list עם כל 116 הכלים, והטבלה שלמטה היא התשובה הזו, מילה במילה. לפני הכל הוא הדפיס את שתי ההודעות המצוטטות כבאנר ההפעלה, שכל הפעלה של הגרסה הזו מדפיסה כי שני כלי ענפים שייכים לשתי ערכות כלים בו זמנית. הריצה הזו לא ביצעה אף קריאת כלי. ארבע ריצות נוספות של אותה פקודה באו אחריה על אותו Mac בתוך שתי דקות. בראשונה קראנו ל-whoami, הכלי ששואל את GitLab למי שייך הטוקן, ו-GitLab ענתה 401 Unauthorized אחרי 294 מילישניות: הקריאה יצאה מה-Mac ונדחתה בצד השני, כי ערך מציין מקום אינו טוקן, והתשובה הזו היא קריאת הדוגמה שלמטה. בשנייה קראנו ל-health_check, שחזר כתשובה רגילה שהתוכן שלה דיווח שאין אימות. בשלישית שלחנו ל-search_repositories מספר במקום שבו הוא מצפה לטקסט, והשרת דחה את הקריאה תוך 6 מילישניות בלי לפנות ל-GitLab. הרביעית הופעלה בלי טוקן בסביבה בכלל ונעצרה במקום לעלות. לכן הכלים נספרו בריצה חיה וכל שגיאה בעמוד הזה היא פלט אמיתי, בעוד קריאה מאומתת מוצלחת עדיין ממתינה ל-personal access token של GitLab שתיצרו בעצמכם.

הודעת הפתיחה של השרת

Tool "get_branch" is defined in multiple toolsets: "merge_requests" and "branches"
Tool "list_branches" is defined in multiple toolsets: "merge_requests" and "branches"

קריאת כלי אמיתית אחת

tools/call whoami {}
GitLab API error: 401 Unauthorized
{"message":"401 Unauthorized"}

שורות אמיתיות מהתוצאה שנלכדה: מספיק כדי להוכיח שהקריאה נענתה.

כלים

הכלים, כפי שנספרו מהשרת הרץ.

השרת ענה ל-tools/list עם 116 כלים בתאריך 2026-08-03. השמות, התיאורים והפרמטרים למטה הם המילים שלו עצמו, מועתקים מהתשובה הזו וללא עריכה.

כלימה הוא עושה
merge_merge_requestproject_id*merge_request_iidauto_mergemerge_commit_messagemerge_when_pipeline_succeedsshould_remove_source_branchsquash_commit_messagesquash

Merge a merge request

approve_merge_requestproject_id*merge_request_iid*shaapproval_password

Approve a merge request

unapprove_merge_requestproject_id*merge_request_iid*

Unapprove a merge request

get_merge_request_approval_stateproject_id*merge_request_iid*

Get merge request approval details including approvers

get_merge_request_conflictsproject_id*merge_request_iid*

Get the conflicts of a merge request

list_merge_request_pipelinesproject_id*merge_request_iid*pageper_page

List pipelines for a merge request with pagination

create_or_update_fileproject_id*file_path*content*commit_message*branch*previous_pathlast_commit_idcommit_id

Create or update a file in a GitLab project

search_repositoriessearchquerypageper_page

Search for GitLab projects

create_repositoryname*namespace_iddescriptionvisibilityinitialize_with_readme

Create a new GitLab project

create_groupname*path*descriptionvisibilityparent_id

Create new group or subgroup

get_file_contentsproject_idfile_pathpathref

Get contents of a file or directory from a GitLab project

push_filesproject_id*branch*files*commit_message*

Push multiple files in a single commit

create_issueproject_id*title*descriptionassignee_idslabelsmilestone_idissue_typeweight

Create a new issue

create_merge_requestproject_id*title*descriptionsource_branch*target_branch*target_project_idassignee_idsreviewer_idslabelsdraftallow_collaborationremove_source_branchsquash

Create a new merge request

fork_repositoryproject_id*namespace

Fork a project to your account or specified namespace

create_branchproject_id*branch*ref

Create a new branch

get_branchproject_id*branch_name*

Get branch details (commit, protection status)

list_branchesproject_id*searchpageper_page

List branches in project with search filter

delete_branchproject_id*branch_name*

Delete branch from project

list_protected_branchesproject_id*searchpageper_page

List protected branches in a project, supports search filter

get_protected_branchproject_id*branch_name*

Get details of a single protected branch (access levels, force push settings)

protect_branchproject_idbranch_name*namepush_access_levelmerge_access_levelunprotect_access_levelallow_force_pushcode_owner_approval_required

Protect a repository branch (set push/merge/unprotect access levels)

unprotect_branchproject_id*branch_name*

Remove protection from a previously protected branch

update_default_branchproject_id*default_branch*

Change the default branch of a project

get_merge_requestproject_id*merge_request_iidsource_branchinclude_summaries

Get details of a merge request (mergeRequestIid or branchName required). Set include_summaries=true for deployment/commit/approval summaries

get_merge_request_diffsproject_id*merge_request_iidsource_branchviewexcluded_file_patterns

Get the changes/diffs of a merge request (mergeRequestIid or branchName required)

list_merge_request_changed_filesproject_id*merge_request_iidsource_branchexcluded_file_patterns

List changed file paths in a merge request without diff content (mergeRequestIid or branchName required)

list_merge_request_diffsproject_id*merge_request_iidsource_branchpageper_pageunidiff

List merge request diffs with pagination (mergeRequestIid or branchName required)

get_merge_request_file_diffproject_id*merge_request_iidsource_branchfile_paths*unidiff

Get diffs for specific files from a merge request (mergeRequestIid or branchName required)

list_merge_request_versionsproject_id*merge_request_iid*

List all versions of a merge request

get_merge_request_versionproject_id*merge_request_iid*version_id*unidiff

Get a specific version of a merge request

get_branch_diffsproject_id*from*to*straightexcluded_file_patterns

Get diffs between two branches or commits

update_merge_requestproject_id*merge_request_iidsource_branchtitledescriptiontarget_branchassignee_idsreviewer_idslabelsstate_eventremove_source_branchsquashdraftmilestone_id

Update a merge request (mergeRequestIid or branchName required)

create_noteproject_id*noteable_type*noteable_iid*body*

Create a new note (comment) to an issue or merge request

create_merge_request_threadproject_id*merge_request_iid*body*positioncreated_at

Create a new thread on a merge request

resolve_merge_request_threadproject_id*merge_request_iid*discussion_id*resolved*

Resolve a thread on a merge request

mr_discussionsproject_id*merge_request_iid*pageper_page

List discussion items for a merge request

delete_merge_request_discussion_noteproject_id*merge_request_iid*discussion_id*note_id*

Delete a discussion note on a merge request

update_merge_request_discussion_noteproject_idmerge_request_iiddiscussion_idnote_idbodyresolved

Update a discussion note on a merge request

create_merge_request_discussion_noteproject_id*merge_request_iid*discussion_id*body*created_at

Add a new discussion note to an existing merge request thread

create_merge_request_noteproject_id*merge_request_iid*body*

Add a new note to a merge request

delete_merge_request_noteproject_id*merge_request_iid*note_id*

Delete an existing merge request note

get_merge_request_noteproject_id*merge_request_iid*note_id*

Get a specific note for a merge request

get_merge_request_notesproject_id*merge_request_iid*sortorder_byper_pagepage

List notes for a merge request

update_merge_request_noteproject_id*merge_request_iid*note_id*body*

Modify an existing merge request note

get_draft_noteproject_id*merge_request_iid*draft_note_id*

Get a single draft note from a merge request

list_draft_notesproject_id*merge_request_iid*

List draft notes for a merge request

create_draft_noteproject_id*merge_request_iid*body*in_reply_to_discussion_idpositionresolve_discussion

Create a draft note for a merge request

update_draft_noteproject_id*merge_request_iid*draft_note_id*bodypositionresolve_discussion

Update an existing draft note

delete_draft_noteproject_id*merge_request_iid*draft_note_id*

Delete a draft note

publish_draft_noteproject_id*merge_request_iid*draft_note_id*

Publish a single draft note

bulk_publish_draft_notesproject_id*merge_request_iid*reviewer_statenoteinternal

Publish all draft notes for a merge request. Optionally sets reviewer_state and posts a summary note (GitLab 19.2+). Can set reviewer_state even with no drafts.

list_merge_request_emoji_reactionsproject_id*merge_request_iid*

List all emoji reactions on a merge request

list_merge_request_note_emoji_reactionsproject_id*merge_request_iid*note_id*discussion_id

List all emoji reactions on a merge request note. Pass discussion_id for discussion thread replies.

create_merge_request_emoji_reactionproject_id*merge_request_iid*name*

Add an emoji reaction to a merge request (e.g. thumbsup, rocket, eyes)

delete_merge_request_emoji_reactionproject_id*merge_request_iid*award_id*

Remove an emoji reaction from a merge request

create_merge_request_note_emoji_reactionproject_id*merge_request_iid*note_id*discussion_idname*

Add an emoji reaction to a merge request note. Pass discussion_id for discussion thread replies.

delete_merge_request_note_emoji_reactionproject_id*merge_request_iid*note_id*discussion_idaward_id*

Remove an emoji reaction from a merge request note. Pass discussion_id for discussion thread replies.

update_issue_noteproject_idissue_iiddiscussion_idnote_idbodyresolved

Modify an existing issue thread note

create_issue_noteproject_id*issue_iid*discussion_idbody*created_at

Add a note to an issue, optionally replying to a discussion thread

list_issue_emoji_reactionsproject_id*issue_iid*

List all emoji reactions on an issue

list_issue_note_emoji_reactionsproject_id*issue_iid*note_id*discussion_id

List all emoji reactions on an issue note. Pass discussion_id for discussion thread replies.

create_issue_emoji_reactionproject_id*issue_iid*name*

Add an emoji reaction to an issue (e.g. thumbsup, rocket, eyes)

delete_issue_emoji_reactionproject_id*issue_iid*award_id*

Remove an emoji reaction from an issue

create_issue_note_emoji_reactionproject_id*issue_iid*note_id*discussion_idname*

Add an emoji reaction to an issue note. Pass discussion_id for discussion thread replies.

delete_issue_note_emoji_reactionproject_id*issue_iid*note_id*discussion_idaward_id*

Remove an emoji reaction from an issue note. Pass discussion_id for discussion thread replies.

list_issuesproject_idassignee_idassignee_usernameauthor_idauthor_usernameconfidentialcreated_aftercreated_beforedue_datelabelsmilestoneissue_typeiteration_idscopesearchstateupdated_afterupdated_beforewith_labels_detailspageper_page

List issues (default: created by current user; use scope='all' for all)

my_issuesproject_idstatelabelsmilestonesearchcreated_aftercreated_beforeupdated_afterupdated_beforeper_pagepage

List issues assigned to the authenticated user

get_issueproject_id*issue_iid*full_response

Get details of a specific issue. Returns a slim milestone by default; set full_response=true for the complete milestone object

update_issueproject_id*issue_iid*titledescriptionassignee_idsconfidentialdiscussion_lockeddue_datelabelsmilestone_idstate_eventweightissue_typefull_response

Update an issue. Returns a slim confirmation by default; set full_response=true for the complete updated issue object

update_issue_description_patchproject_id*issue_iid*patch_type*patch*dry_runcreate_noteallow_multiple

Apply a patch (search/replace or unified diff) to an issue description. Reduces token usage by allowing small changes without sending the full description. Supports dry_run to preview changes and create_note to summarize updates.

delete_issueproject_id*issue_iid*

Delete an issue

list_todosactionauthor_idproject_idgroup_idstatetypepageper_page

List GitLab to-do items for the current user

mark_todo_doneid*

Mark a GitLab to-do item as done

mark_all_todos_done

Mark all pending GitLab to-do items as done for the current user

list_issue_linksproject_id*issue_iid*

List all issue links for a specific issue

list_issue_discussionsproject_id*issue_iid*pageper_page

List discussions for an issue

get_issue_linkproject_id*issue_iid*issue_link_id*

Get a specific issue link

create_issue_linkproject_id*issue_iid*target_project_id*target_issue_iid*link_type

Create an issue link between two issues

delete_issue_linkproject_id*issue_iid*issue_link_id*

Delete an issue link

list_namespacessearchownedpageper_page

List all namespaces (users and groups) available to the current user. Filter by kind='group' for groups only.

get_namespacenamespace_id*

Get details of a namespace (user or group) by ID or path. Groups are namespaces with kind='group'.

verify_namespacepath*parent_id

Verify if a namespace path exists. Use parent_id to scope the check to a specific parent namespace — required for nested namespaces where the same path may exist under different parents.

get_projectproject_id*

Get details of a specific project

list_projectssearchsearch_namespacesownedmembershipsimplearchivedvisibilityorder_bysortwith_issues_enabledwith_merge_requests_enabledmin_access_leveltopicpageper_page

List projects accessible by the current user

update_projectproject_idnamepathdescriptiondefault_branchvisibilitytopicsrequest_access_enabledremove_source_branch_after_mergeonly_allow_merge_if_pipeline_succeedsonly_allow_merge_if_all_discussions_are_resolvedsquash_optionmerge_methodissues_access_levelmerge_requests_access_levelbuilds_access_levelwiki_access_levelsnippets_access_levelcontainer_registry_access_levelenvironments_access_levelforking_access_levelpackage_registry_access_levelpages_access_level

Update project settings such as description, visibility, default branch, and feature access levels

list_project_membersproject_id*queryuser_idsskip_usersinclude_inheritanceper_pagepage

List members of a GitLab project

list_group_membersgroup_id*queryuser_idsskip_usersinclude_inheritanceper_pagepage

List members of a GitLab group with optional name or username search

list_labelsproject_id*with_countsinclude_ancestor_groupssearchpageper_page

List labels for a project

get_labelproject_id*label_id*include_ancestor_groups

Get a single label from a project

create_labelproject_id*name*color*descriptionpriority

Create a new label in a project

update_labelproject_id*label_id*new_namecolordescriptionpriority

Update an existing label in a project

delete_labelproject_id*label_id*

Delete a label from a project

list_group_projectsgroup_id*include_subgroupssearchorder_bysortarchivedvisibilitywith_issues_enabledwith_merge_requests_enabledmin_access_levelwith_programming_languagestarredstatisticswith_custom_attributeswith_security_reportstopicpageper_page

List projects in a group

get_repository_treeproject_id*pathrefrecursiveper_pagepage_tokenpagination

List files and directories in a repository

validate_ci_lintproject_id*content*dry_runinclude_jobsref

Validate provided GitLab CI/CD YAML content for a project

validate_project_ci_lintproject_id*content_refdry_rundry_run_refinclude_jobs

Validate an existing .gitlab-ci.yml configuration for a project

list_ci_catalog_resourcessearchfirstaftergroup_idsscopesorttopicsverification_level

List GitLab CI/CD Catalog resources/components visible to the user

get_ci_catalog_resourceversion_limitcomponent_limitcomponent_nameinclude_readmeidfull_path

Get details for a GitLab CI/CD Catalog resource, including versions and components

list_merge_requestsproject_idassignee_idassignee_usernameauthor_idauthor_usernamereviewer_idreviewer_usernameapproved_by_usernamescreated_aftercreated_beforeupdated_afterupdated_beforelabelsmilestonescopesearchstateorder_bysorttarget_branchsource_branchwipwith_labels_detailspageper_page

List merge requests (without project_id: user's MRs; with project_id: project MRs)

get_usersusernames*

Get GitLab user details by usernames

get_useruser_id*

Get user details by ID

whoami

Get current authenticated user details

list_commitsproject_id*ref_namesinceuntilpathauthorallwith_statsfirst_parentordertrailerspageper_page

List repository commits with filtering options

get_commitproject_id*sha*stats

Get details of a specific commit

get_commit_diffproject_id*sha*full_diff

Get changes/diffs of a specific commit

get_file_blameproject_idfile_path*ref*range_startrange_end

Get git blame for a file at a given ref. Each entry maps a contiguous range of source lines to the commit that last changed them (id, author, authored_date, message). Use range_start/range_end to limit blame to specific lines.

list_commit_statusesproject_id*sha*refstagenamepipeline_idorder_bysortallpageper_page

List statuses for a commit

create_commit_statusproject_id*sha*state*refnamecontexttarget_urldescriptioncoveragepipeline_id

Create or update the status of a commit

list_group_iterationsgroup_id*statesearchsearch_ininclude_ancestorsinclude_descendantsupdated_beforeupdated_afterpageper_page

List group iterations with filtering options

upload_markdownproject_id*file_path*

Upload a file for use in markdown content

download_attachmentproject_id*secret*filename*local_path

Download an uploaded file from a project (images returned as base64; use local_path to save to disk)

health_check

Verify server status and authentication. When authenticated, also reports the GitLab instance version from GET /api/v4/version (version, revision, enterprise). Version lookup failures do not fail the health check — those fields are omitted.

list_eventsactiontarget_typebeforeafterscopesortpageper_page

List events for the authenticated user (before/after: YYYY-MM-DD)

get_project_eventsproject_id*actiontarget_typebeforeaftersortpageper_page

List events for a project (before/after: YYYY-MM-DD)

discover_toolscategory

Discover and activate additional tool categories for this session. Available categories: merge_requests, issues, repositories, branches, projects, labels, ci, groups, pipelines, milestones, wiki, releases, tags, users, workitems, webhooks, search, variables, dependency_proxy, vulnerabilities. Already-active categories are listed in the response.

פרמטרים המסומנים ב-* הם חובה.

התקנה

הגדרות שעובדות, אחת לכל אפליקציה.

העתיקו את הבלוק של האפליקציה שלכם. כל אחד מהם הוא ההגדרה המדויקת שאיתה אימתנו את השרת.

Claude Desktop

פתחו את הקובץ ‎~/Library/Application Support/Claude/claude_desktop_config.json (בתוך Claude Desktop: Settings, אחר כך Developer, אחר כך Edit Config) והוסיפו:

{
  "mcpServers": {
    "gitlab": {
      "command": "npx",
      "args": [
        "-y",
        "@zereight/mcp-gitlab"
      ],
      "env": {
        "GITLAB_PERSONAL_ACCESS_TOKEN": "glpat-your-token",
        "GITLAB_API_URL": "https://gitlab.com/api/v4"
      }
    }
  }
}

הדביקו את הטוקן שלכם במקום glpat-your-token, ואם הצוות שלכם מארח GitLab משלו, שנו את הכתובת למופע שלכם עם ‎/api/v4 בסוף. הפקודה, הארגומנטים ושני שמות המשתנים הם בדיוק מה שהרצנו, והשרת רשם את כתובת ה-API הזו בחזרה אלינו כשעלה. אם תתקינו את החבילה גלובלית, הפקודה הופכת ל-zereight-mcp-gitlab והארגומנטים נעלמים. אחר כך סגרו ופתחו מחדש את Claude Desktop. [12][5][4]

Claude Code

פקודה אחת בטרמינל:

claude mcp add gitlab --transport stdio --scope local \
  --env GITLAB_PERSONAL_ACCESS_TOKEN=glpat-your-token \
  --env GITLAB_API_URL=https://gitlab.com/api/v4 \
  -- npx -y @zereight/mcp-gitlab

זו הפקודה של הפרויקט עצמו ל-Claude Code עם שינוי אחד: היא מסתיימת ב-‎npx -y @zereight/mcp-gitlab, שלא מתקין כלום, בעוד המדריך מסתיים בבינארי המותקן גלובלית zereight-mcp-gitlab. כל מה שאחרי המקף הכפול הוא הפקודה המדויקת ש-Claude Code יריץ. בדקו שהיא נרשמה עם claude mcp list, והשתמשו ב-‎/mcp בתוך Claude Code כדי לראות את הסטטוס שלה. [13][6]

Cursor

הוסיפו ל-‎~/.cursor/mcp.json עבור כל הפרויקטים, או ל-‎.cursor/mcp.json בתוך פרויקט אחד:

{
  "mcpServers": {
    "gitlab": {
      "command": "npx",
      "args": [
        "-y",
        "@zereight/mcp-gitlab"
      ],
      "env": {
        "GITLAB_PERSONAL_ACCESS_TOKEN": "glpat-your-token",
        "GITLAB_API_URL": "https://gitlab.com/api/v4",
        "GITLAB_READ_ONLY_MODE": "false"
      }
    }
  }
}

Cursor קורא את הקובץ מחדש אחרי הפעלה מחדש. המשתנה השלישי הוא זה שכדאי להכיר: הגדירו את GITLAB_READ_ONLY_MODE ל-true והשרת יציע רק את הכלים לקריאה בלבד, וזו דרך הגיונית להתחיל. כדאי לדעת גם: מדריך ה-Cursor של הפרויקט עצמו מגדיר את עצמו כתבנית קהילתית במאמץ טוב ולא כתיעוד Cursor מאומת מול המאגר, לכן אם Cursor תשנה את מסך ההגדרות, קחו את המעטפת מהתיעוד של Cursor עצמה ושמרו על ערכי command, args ו-env שלמעלה. [14][7][5]

Routines

בלי קובץ JSON ובלי טרמינל. ב-Routines: Settings, אחר כך Assistant, אחר כך Connections, אחר כך Add MCP Server. העבירו את הטופס ל-Command (stdio) והזינו:

Name        GitLab
Command     npx
Arguments   -y @zereight/mcp-gitlab

Environment Variables
GITLAB_PERSONAL_ACCESS_TOKEN    glpat-your-token
GITLAB_API_URL                  https://gitlab.com/api/v4

הערך בשדה ה-Arguments מתפצל לפי רווחים, לכן השאירו בו בדיוק את שלוש המילים האלה. הטוקן שייך ל-Environment Variables, אף פעם לא ל-Arguments. שנו את כתובת ה-API אם הצוות שלכם מארח GitLab משלו, עם ‎/api/v4 בסוף. לחצו קודם על Test Connection: שרת תקין עונה עם מספר הכלים שלו, 116 עבור השרת הזה. בדיקה ירוקה אומרת שהשרת עלה, לא ש-GitLab קיבלה את הטוקן שלכם, לכן שאלו אחריה שאלת קריאה קטנה. [15][5]

בלי טרמינל

איך מגדירים את שרת ה-MCP‏ GitLab בלי טרמינל.

אם מעולם לא פתחתם את הטרמינל ואין לכם כוונה להתחיל, זה המסלול שלכם. Routines היא אפליקציית Mac שמריצה שרתי MCP בשבילכם: ממלאים כמה שדות פעם אחת, והכלים של השרת זמינים ל-AI שלכם בצ׳אט ובשגרות מתוזמנות. בניגוד לשרת קבצים, השרת הזה צריך קודם טוקן מ-GitLab, ולכן זה שלב שתיים.

  1. 01

    התקינו את Routines

    הורידו את האפליקציה מ-getroutines.ai/download, גררו אותה ל-Applications והתחברו.

  2. 02

    צרו טוקן גישה ב-GitLab

    ב-GitLab בחרו את תמונת הפרופיל שלכם בפינה העליונה, אחר כך Edit profile, אחר כך Access ו-Personal access tokens בסרגל הצד, ואז Generate token. תנו לו שם ותאריך תפוגה שנוח לכם איתו, ובחרו הרשאה: api נותנת גישת קריאה וכתיבה מלאה ל-API, ואילו read_api נותנת גישת קריאה בלבד, וזו זו שכדאי להתחיל איתה אם אתם רוצים שהעוזר יסתכל ולא ייגע. GitLab מציגה את הטוקן פעם אחת, לכן העתיקו אותו לפני שאתם סוגרים את העמוד.

  3. 03

    פתחו את הגדרות ה-MCP

    לחצו על החשבון שלכם בתחתית סרגל הצד ובחרו Settings. פתחו את הקטע Assistant, אחר כך את הלשונית Connections, גללו אל MCP Servers ולחצו על Add MCP Server.

  4. 04

    בחרו Command (stdio)‎

    העבירו את הטופס ל-Command (stdio): השרת הזה הוא פקודה שה-Mac שלכם מריץ, לא כתובת אינטרנט. Name: GitLab. Command: npx. Arguments: ‎-y @zereight/mcp-gitlab, בדיוק שלוש המילים האלה.

  5. 05

    הוסיפו את הטוקן ואמרו לאיזו GitLab

    ב-Environment Variables הוסיפו את GITLAB_PERSONAL_ACCESS_TOKEN עם הטוקן שהעתקתם. הוסיפו משתנה שני, GITLAB_API_URL, עם הערך ‎https://gitlab.com/api/v4 עבור השירות הציבורי, או עם המופע של החברה שלכם ו-‎/api/v4 בסוף. השלב הזה אינו רשות: כשהמשתנה הראשון ריק השרת נעצר במקום לעלות, וראינו את זה במו עינינו.

  6. 06

    בדקו, הוסיפו והשתמשו

    לחצו Test Connection: Routines מפעילה את השרת ומדווחת כמה כלים היא מצאה, מאה ושישה עשר עבור השרת הזה. אחר כך לחצו Add Server. שאלו קודם שאלת קריאה, למשל כמי אתם מחוברים ל-GitLab, כי זה מה שמוכיח שהטוקן עצמו עובד. כדי לתת לשגרה מתוזמנת להשתמש בכלים האלה, פתחו את השגרה, מצאו את הכרטיס Tools & connections וסמנו את השרת תחת Apps.

רעיונות לשגרות

שגרות ששווה לתזמן.

אחרי שהשרת מחובר, שגרה מתוזמנת יכולה להשתמש בכלים שלו גם כשאתם לא מול המסך. העתיקו פרומפט, הדביקו אותו ב-Routines ובחרו שעה. הפרומפטים כתובים באנגלית בכוונה, מדביקים אותם בדיוק כפי שהם.

תור סקירה של יום שני

פרומפט

Every Monday at 9:00, list the open merge requests assigned to me in GitLab, note which ones have had no comment or new commit for more than three days and which still have unresolved discussion threads, and save the list as review-queue.md with the oldest first.

בדיקת בילד יומית

פרומפט

Every weekday at 8:30, check the most recent commit statuses on the default branch of my main GitLab project and write one plain-English line telling me whether the last build passed or failed, naming the failing job and the commit title if it failed.

סבב מיון ל-issues

פרומפט

Every weekday at 17:00, list the GitLab issues opened in my project today that have no labels, summarise each one in a line, suggest a label for it, and save the result as triage.md. Do not change anything in GitLab.

פתרון תקלות

השגיאות שנתקלנו בהן, ומה פתר אותן.

שגיאות אמיתיות שנלכדו בריצת האימות, מודפסות בדיוק כפי שהשרת החזיר אותן.

השרת נעצר ברגע שהוא עולה

מה רואים

GITLAB_PERSONAL_ACCESS_TOKEN environment variable is not set
Either set GITLAB_PERSONAL_ACCESS_TOKEN or enable OAuth with GITLAB_USE_OAUTH=true

הפתרון

טוקן כאן אינו רשות, וזה מפתיע אנשים כי לא מעט שרתי MCP אחרים עולים בשמחה בלי אישור הגישה שלהם ונכשלים רק בקריאה הראשונה. כשהופעל בלי שום ערך במשתנה הזה, השרת הזה רשם את שתי השורות האלה ונעצר במקום לחכות ללקוח שלכם, ולכן הלקוח מדווח על שרת שאינו עולה. שימו את הטוקן שלכם ב-GITLAB_PERSONAL_ACCESS_TOKEN, או הגדירו GITLAB_USE_OAUTH=true כדי להשתמש בזרימת ההתחברות בדפדפן במקום, והפעילו אותו שוב.

כל קריאת כלי חוזרת עם 401 Unauthorized

מה רואים

GitLab API error: 401 Unauthorized
{"message":"401 Unauthorized"}

הפתרון

זו התשובה המדויקת שקריאת הדוגמה שלנו קיבלה, קריאת whoami שנשאה ערך מציין מקום שהמצאנו במקום טוקן. בשימוש אמיתי המשמעות היא ש-GitLab דחתה את הטוקן: הוא פג, הוא בוטל, הוא הודבק בלי תו אחד, או שהוא שייך ל-GitLab אחרת מזו ש-GITLAB_API_URL מצביע אליה. צרו טוקן חדש, ודאו שהכתובת מסתיימת ב-‎/api/v4, והפעילו מחדש את השרת כדי שיקרא את הערך החדש. דבר אחד שכדאי לדעת בזמן האיתור: השרת הזה בודק את צורת הקריאה על ה-Mac שלכם לפני שהוא פונה ל-GitLab, ועונה לקריאה בעלת צורה שגויה בתלונת Invalid arguments שלמטה במקום זאת, כך ש-401 מדבר על הטוקן ולא על הארגומנטים.

קריאת כלי חוזרת עם תלונה על ארגומנט

מה רואים

Invalid arguments: search: Expected string, received number

הפתרון

כאן מדבר השרת, לא GitLab. כל כלי מצהיר איזה סוג ערך כל ארגומנט מקבל, וקריאה שאינה מתאימה נדחית על ה-Mac שלכם: הבדיקה שלנו נתנה ל-search_repositories מספר במקום שבו הוא מצפה לטקסט, והדחייה חזרה תוך 6 מילישניות, בלי ששום דבר נשלח ל-gitlab.com ובלי ששום דבר השתנה שם. בשימוש אמיתי המשמעות היא שהעוזר ניחש סוג ערך שגוי, לכן ציינו במילים פשוטות את שם הכלי ואת הערך שאתם רוצים ובקשו ממנו לנסות שוב. הטבלה למעלה מפרטת כל ארגומנט שהשרת הזה מקבל.

שתי אזהרות על כלי ענפים מופיעות בכל הפעלה

מה רואים

Tool "get_branch" is defined in multiple toolsets: "merge_requests" and "branches"
Tool "list_branches" is defined in multiple toolsets: "merge_requests" and "branches"

הפתרון

שום דבר לא תקול. כל הפעלה של גרסה 2.1.46 מדפיסה את שתי השורות האלה לפני כל דבר אחר, כי שני הכלים האלה רשומים גם בערכת merge_requests וגם בערכת branches. זה השרת שמתאר את הקטלוג של עצמו, שני הכלים עובדים כרגיל, ולקוחות שצובעים פלט שרת באדום גורמים לשורות האלה להיראות חמורות ממה שהן.

לקוח ה-MCP לא מצליח להפעיל את השרת בכלל

הפתרון

הפקודה npx שייכת ל-Node.js. אם Node לא מותקן על ה-Mac, כל לקוח בעמוד הזה ייכשל בשלב ההפעלה עוד לפני שהשרת מספיק לומר משהו. התקינו Node מ-nodejs.org, הפעילו מחדש את לקוח ה-MCP ונסו שוב.

שאלות נפוצות

שאלות שאנשים שואלים.

מה זה שרת ה-MCP של GitLab?

זהו שרת Model Context Protocol שמעמיד את ה-API של GitLab מול עוזר AI, ומפורסם ל-npm בשם ‎@zereight/mcp-gitlab. הוא מתוחזק על ידי הקהילה ואינו מוצר רשמי של GitLab: המתחזק הוא המפתח zereight, המאגר הוא zereight/gitlab-mcp ב-GitHub, והרישיון הוא MIT. אחרי החיבור, עוזר יכול לחפש פרויקטים, לקרוא ולכתוב קבצים, לפתוח ולמזג בקשות מיזוג, לטפל ב-issues, לנהל ענפים ולקרוא סטטוס של פייפליינים וקומיטים, הכל דרך חשבון ה-GitLab שלכם. [1][3]

אילו כלים כלולים בשרת ה-MCP של GitLab?

השרת הרץ חשף 116 כלים, והטבלה למעלה היא פלט ה-tools/list החי הזה, מילה במילה. בספירה לפי שם: 40 עוסקים בבקשות מיזוג, מיצירה, מיזוג ואישור ועד דיפים, גרסאות, הערות דיון והערות טיוטה; 20 ב-issues, כולל קישורים, דיונים ו-my_issues; 10 בענפים, כולל הכלים לענפים מוגנים; 5 בקומיטים ובסטטוסים שלהם; 5 בתוויות; 4 בבדיקת CI ובקטלוג ה-CI; 3 במשימות todo ו-3 ב-namespaces; ו-26 הנותרים מכסים פרויקטים, קבוצות וחברים, קובצי מאגר ועץ הקבצים, אירועים וכלי עזר כמו whoami,‏ health_check ו-discover_tools. שנים עשר מהכלים שנספרו למעלה הם תגובות אימוג׳י, וזו אמת מידה הוגנת לכמה במלואו השרת הזה משקף את GitLab.

האם שרת ה-MCP של GitLab בטוח?

התייחסו אליו כאל גישת כתיבה למאגרים שלכם, כי כברירת מחדל זה מה שהוא: 116 הכלים האלה כוללים מיזוג, מחיקת ענפים, מחיקת issues ושינוי הגדרות פרויקט. שני בלמים כדאי להגדיר לפני שמתחילים. הטוקן קובע מה אפשרי בצד של GitLab, וההרשאה read_api נותנת גישת קריאה ל-API בלבד, בעוד api נותנת גישת קריאה וכתיבה מלאה. לשרת יש מתג משלו, GITLAB_READ_ONLY_MODE, שמגביל אותו לכלים לקריאה בלבד כשהוא מוגדר ל-true. אישור הגישה עצמו הוא טוקן שאתם מדביקים בהגדרות של לקוח ה-MCP או בטופס המחברים של Routines, לכן התייחסו לקובץ ההגדרות הזה כמו לכל קובץ שמחזיק סיסמה, ותנו לטוקן תאריך תפוגה. [11][5]

האם שרת ה-MCP של GitLab דורש מפתח API או חשבון?

כן: personal access token של GitLab, שנוצר בפרופיל שלכם ב-GitLab תחת Access ו-Personal access tokens, ומודבק במשתנה הסביבה GITLAB_PERSONAL_ACCESS_TOKEN. הוא אינו רשות כפי שהוא אצל חלק מהשרתים, וזו ההפתעה היחידה כאן: כשהמשתנה הזה ריק השרת רושם תלונה ונעצר במקום לעלות, ולכן גם ריצת האימות שלנו הייתה צריכה ערך מציין מקום רק כדי להגיע לרשימת הכלים. המשתנה השני, GITLAB_API_URL, אומר לאיזו GitLab אתם מתכוונים, ‎https://gitlab.com/api/v4 עבור השירות הציבורי או הכתובת שלכם עם ‎/api/v4 בסוף. הפרויקט מתעד גם זרימת OAuth בדפדפן כחלופה לטוקן. [10][5]

צריך טרמינל כדי להגדיר אותו?

לא. ב-Routines ממלאים פקודה, שני משתני סביבה ושם, ואז לוחצים Test Connection; המדריך למעלה מראה כל לחיצה. Claude Desktop ו-Cursor דורשים עריכה חד-פעמית של קובץ JSON קטן. רק Claude Code הוא כלי טרמינל מטבעו. יצירת הטוקן עצמה קורית בדפדפן, בהגדרות של GitLab. [15][12]

למה לא החבילה הרשמית ‎@modelcontextprotocol/server-gitlab?

כי היא הוצאה משימוש. npm נושא עליה הודעת deprecation שאומרת שהחבילה אינה נתמכת עוד, הגרסה האחרונה שלה היא 2025.4.25 מאפריל 2025, והמאגר שממנו הגיעה, modelcontextprotocol/servers-archived, נמצא בארכיון ב-GitHub ומתואר כשרתי ייחוס שאינם מתוחזקים עוד. לחבילה הקהילתית שבעמוד הזה פורסמה גרסה יום לפני הריצה שלנו, והיא נמשכה 114,673 פעמים ב-npm בשבוע שהסתיים ב-2026-08-02, מול 5,632 לחבילה שהוצאה משימוש, כלומר בערך פי עשרים. [8][9][1][2]

אילו אפליקציות יכולות להשתמש בשרת ה-MCP של GitLab?

כל לקוח MCP שמסוגל להפעיל שרת stdio מקומי: Claude Desktop, Claude Code, Cursor ו-Routines כולם יכולים, וההגדרה המדויקת לכל אחד נמצאת למעלה. הפרויקט מספק מדריכי התקנה משלו לכמה מהם, ורישום ה-npm מפרסם גם תעבורת SSE ו-Streamable HTTP, לצוותים שמעדיפים מופע משותף אחד על פני מופע לכל Mac. השרת עצמו זהה בכל לקוח; רק המקום שבו מדביקים את ההגדרה משתנה. [1][4][12][13][14][15]

מקורות

כל טענה חיצונית, עם קבלה.

כל מה שבעמוד הזה שלא ראינו בעצמנו בריצה מקושר כאן, עם התאריך שבו קראנו אותו. לגבי השאר, הריצה עצמה היא הקבלה.

  1. [1]

    npm registry: @zereight/mcp-gitlabנקרא בתאריך 2026-08-03

    Latest version 2.1.46, published 2026-08-02 by GitHub Actions CI; license MIT; maintainer zereight; keywords include stdio, sse and streamable-http; binaries mcp-gitlab and zereight-mcp-gitlab.

  2. [2]

    npm downloads API: last weekנקרא בתאריך 2026-08-03

    114,673 downloads for the week 2026-07-27 to 2026-08-02, against 5,632 for @modelcontextprotocol/server-gitlab in the same week.

  3. [3]

    GitHub: zereight/gitlab-mcpנקרא בתאריך 2026-08-03

    1,870 stars, license MIT, archived false, last push 2026-08-03, owner type User, read from the GitHub REST API.

  4. [4]

    GitLab MCP Server READMEנקרא בתאריך 2026-08-03

    Source for the recommended zereight-mcp-gitlab binary name over the older mcp-gitlab, and for the stdio, SSE and Streamable HTTP transport options.

  5. [5]

    GitLab MCP Server docs: environment variablesנקרא בתאריך 2026-08-03

    GITLAB_PERSONAL_ACCESS_TOKEN, GITLAB_API_URL pointing at the API root ending in /api/v4, and GITLAB_READ_ONLY_MODE=true to restrict the server to read-only tools.

  6. [6]

    GitLab MCP Server docs: Claude Code setup guideנקרא בתאריך 2026-08-03

    The claude mcp add command with --transport stdio, --scope local and the two --env values.

  7. [7]

    GitLab MCP Server docs: Cursor setup guideנקרא בתאריך 2026-08-03

    The .cursor/mcp.json block, plus the guide's own note that it is a best-effort community pattern rather than repository-verified official Cursor documentation.

  8. [8]

    npm registry: @modelcontextprotocol/server-gitlabנקרא בתאריך 2026-08-03

    The retired official reference server: latest version 2025.4.25, carrying the npm notice "Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."

  9. [9]

    GitHub: modelcontextprotocol/servers-archivedנקרא בתאריך 2026-08-03

    archived true, described as "Reference MCP servers that are no longer maintained", last push 2025-05-28, read from the GitHub REST API.

  10. [10]

    GitLab docs: Personal access tokensנקרא בתאריך 2026-08-03

    The creation path quoted in the walkthrough: avatar, Edit profile, then Access and Personal access tokens in the left sidebar, then Generate token.

  11. [11]

    GitLab docs: Access token scopesנקרא בתאריך 2026-08-03

    api "Grants complete read and write access to the API for the token's scope"; read_api "Grants read access to the API for the token's scope".

  12. [12]

    modelcontextprotocol.io: Connect to local MCP serversנקרא בתאריך 2026-08-03

    The claude_desktop_config.json shape and where the file lives.

  13. [13]

    Claude Code docs: MCPנקרא בתאריך 2026-08-03

    The claude mcp add syntax for local stdio servers, including --env and --scope.

  14. [14]

    Cursor docs: Model Context Protocolנקרא בתאריך 2026-08-03

    The mcp.json shape and file locations.

  15. [15]

    Routines: Connectorsנקרא בתאריך 2026-08-03

    How Routines runs one-click OAuth connectors and any MCP server.

העמוד הזה מתאר את GitLab כפי שהתנהג בריצה מתוארכת אחת על Mac אחד. גרסאות משתנות: אם משהו כאן כבר לא תואם למה שאתם רואים, תאריך הלכידה בראש העמוד אומר בן כמה הצילום.

מאחורי המדריך הזה

Routines, האפליקציה שמאחורי המדריך הזה, מריצה שרתי MCP כמו זה בלי טרמינל: כך עובדים המחברים. הפתקים שלכם נשארים קובצי markdown על ה-Mac שלכם, אין חשבון ענן לשלם, והיא עובדת גם בלי אינטרנט. להורדת Routines