Support multiple remote toolsets via URL for managed MCP clients without custom headers
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Anfängerfreundlichkeit
- 45/100
- Issue-Typ
- Feature
- Klarheit
- Größtenteils klar
- Aktivitätsstatus
- Aktiv
- Tech-Stack
- go
- Bereich
- api, backend-api-design
Rechercherichtung
Beginne damit, das URL-Routing des gehosteten Remote-Servers für /mcp/x/{toolset}, /readonly und /x/all nachzuverfolgen, und vergleiche es anschließend mit der bestehenden Validierung und Normalisierung von X-MCP-Toolsets. Definiere und dokumentiere eine URL-sichere Form für mehrere Toolsets, einschließlich der Priorität, wenn Header ebenfalls vorhanden sind. Als erledigt gilt die Aufgabe, wenn verwaltete Clients ein begrenztes, validiertes Bundle auswählen können, ohne /x/all zu verwenden.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Describe the feature or problem you’d like to solve
The hosted GitHub MCP server currently supports a single toolset by URL (/mcp/x/{toolset}) and multiple toolsets through the X-MCP-Toolsets request header.
That leaves managed MCP clients that expose the server endpoint and OAuth configuration but do not allow arbitrary per-request HTTP headers unable to select a bounded combination of toolsets. One concrete example is a ChatGPT custom/developer MCP app: its current app configuration flow exposes endpoint/metadata/authentication and tool scanning, but not an arbitrary X-MCP-Toolsets header field.
The practical choices are therefore currently:
- remain on the default toolset and lose useful optional capabilities;
- create several separate MCP app connections, one per
/x/{toolset}URL; or - use
/x/all, which exposes substantially more tools than needed and works against least-privilege/tool-surface minimization.
My concrete desired bundle is:
default,actions,projects,git,notifications,governance
The use case is an interactive GitHub MCP connection that needs ordinary repository/issue/PR operations plus CI inspection/control, Projects, repository tree access, notifications, and governance, while intentionally not exposing unrelated toolsets.
Proposed solution
Add a URL-addressable way to select multiple toolsets on the hosted remote server, while preserving the existing header behavior. For example, one of:
/mcp/x/default,actions,projects,git,notifications,governance/mcp?toolsets=default,actions,projects,git,notifications,governance- another documented, URL-safe equivalent.
Requirements I would suggest:
- use the same validation/normalization as
X-MCP-Toolsets; - support the
defaultpseudo-toolset plus additional toolsets; - reject unknown toolsets rather than silently broadening access;
- remain composable with
/readonlyand existing URL-addressable modes where applicable; - keep headers authoritative when both mechanisms are present, or document an unambiguous precedence rule;
- do not make
/x/allthe required workaround for managed clients.
Example prompts or workflows
A managed ChatGPT MCP app could point to one stable endpoint representing exactly the approved bundle, then scan tools normally. The same pattern would help other hosted/managed MCP clients that cannot inject custom headers.
Why this matters
GitHub already recommends selecting only the toolsets needed because tool-surface size affects model tool selection and security. URL-addressable multi-toolset selection lets managed clients follow that recommendation instead of choosing between missing capabilities, duplicated app connections, or all.
This request is separate from #3231 / PR #3232, which address patch-safe large-file updates.
- Vorherrschende Sprache
- Go
- Sterne
- 33.1k
- Forks
- 5k
- Ø Merge
- 2 T. 1 Std.
- Gemergte PRs (30 T.)
- 25
Beitragsleitfaden
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus github/github-mcp-server
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
github/github-mcp-server#3235 ·
-
enhancement
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 88/100
github/github-mcp-server#3042 · 2 Kommentare ·
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
github/github-mcp-server#3032 · 1 Reaktion ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 74/100
github/github-mcp-server#2803 · 1 Kommentar ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
github/github-mcp-server#2740 ·
Alle Issues in github/github-mcp-server
Ähnliche Issues
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 60/100
github/gh-aw-mcpg#13748 ·
-
agentic-workflows
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 65/100
-
needs-triage
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 65/100
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
googleapis/librarian#7670 · 2 Kommentare ·