Hosted MCP cannot resolve review threads with a fine-grained PAT that succeeds via GraphQL
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 35/100
- Tipo de issue
- Bug
- Clareza
- Razoavelmente clara
- Status de atividade
- Ativa
- Stack de tecnologia
- github, go
- Domínio
- api, authentication, backend
Direção de pesquisa
Comece pelo ponto de entrada da ferramenta hospedada de MCP para resolução de threads de revisão e reproduza a falha usando o endpoint, os toolsets e o fine-grained PAT listados. Compare o caminho de autorização da operação com a mutation GraphQL resolveReviewThread bem-sucedida. Está concluído quando a operação MCP resolver a thread de revisão com o mesmo token e preservar o comportamento existente de inline-reply.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Summary
GitHub hosted remote MCP fails to resolve pull request review threads with a fine-grained personal access token, returning:
Resource not accessible by personal access token
The same token successfully performs both unresolveReviewThread and resolveReviewThread through GitHub GraphQL. This appears related to #2381, which reports a different hosted-MCP PR operation failing while the equivalent direct API request succeeds.
Environment
- Server: GitHub-hosted remote MCP
- Endpoint:
https://api.githubcopilot.com/mcp/ - Transport: Remote HTTP
- Client: OpenCode
- Authentication: fine-grained PAT supplied in the
Authorization: Bearerheader - MCP toolsets:
repos,issues,pull_requests - Repository:
crsiebler/pogo-gbl-analyzer - Token repository permission: Pull requests: Read and write
- Approximate failure time:
2026-09-08 05:35 UTC
Reproduction
- Configure the hosted server with
oauth: false, the endpoint above, anAuthorization: Bearer {env:GITHUB_MCP_TOKEN}header, andX-MCP-Toolsets: repos,issues,pull_requests. - Authenticate with a fine-grained PAT that has access to
crsiebler/pogo-gbl-analyzerand Pull requests: Read and write. - Read review threads for
crsiebler/pogo-gbl-analyzer#10. - Attempt to resolve
PRRT_kwDOPgvNY86gGnRDwith the MCP review-thread resolution tool. - Observe:
failed to resolve review thread: Resource not accessible by personal access token
Expected Behavior
The MCP operation resolves the review thread, matching GitHub GraphQL behavior for the same token.
Actual Behavior
The MCP operation returns a personal-access-token authorization error. Other writes succeeded in the same MCP workflow: inline replies were posted to five pull request review-comment threads.
Direct GraphQL Verification
Using the same fine-grained PAT outside MCP, unresolving the thread succeeded:
GH_TOKEN=github_pat_REDACTED gh api graphql \
-f query='mutation($threadId: ID!) {
unresolveReviewThread(input: {threadId: $threadId}) {
thread { id isResolved }
}
}' \
-f threadId='PRRT_kwDOPgvNY86gGnRD'
Response:
{
"data": {
"unresolveReviewThread": {
"thread": {
"id": "PRRT_kwDOPgvNY86gGnRD",
"isResolved": false
}
}
}
}
Resolving it again with the same token also succeeded:
GH_TOKEN=github_pat_REDACTED gh api graphql \
-f query='mutation($threadId: ID!) {
resolveReviewThread(input: {threadId: $threadId}) {
thread { id isResolved }
}
}' \
-f threadId='PRRT_kwDOPgvNY86gGnRD'
Response:
{
"data": {
"resolveReviewThread": {
"thread": {
"id": "PRRT_kwDOPgvNY86gGnRD",
"isResolved": true
}
}
}
}
Impact
Agents can reply to inline review feedback but cannot complete the normal review workflow by resolving addressed threads through the hosted GitHub MCP server, despite the configured PAT being authorized for the underlying GraphQL mutation.
Notes
- The token value is intentionally omitted.
- The hosted endpoint does not expose a locally inspectable server version.
- Inline reply timestamps immediately preceding the failure were
2026-09-08T05:35:45Zand2026-09-08T05:35:46Z.
- Linguagem predominante
- Go
- Estrelas
- 33.1k
- Forks
- 5k
- Merge médio
- 2d 15h
- PRs com merge (30d)
- 27
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de github/github-mcp-server
-
bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
github/github-mcp-server#3235 ·
-
enhancement
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
github/github-mcp-server#3042 · 2 comentários ·
-
bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
github/github-mcp-server#3032 · 1 reação ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
github/github-mcp-server#2803 · 1 comentário ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
github/github-mcp-server#2740 ·
Todas as issues de github/github-mcp-server
Issues semelhantes
-
kind/bug needs-triage
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 72/100
matrixorigin/matrixone#29223 ·
-
needs-acceptance wg/data-plane-networking
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
vllm-project/semantic-router#4024 · 1 comentário ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
-
bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 86/100
alexgorbatchev/dotfiles#107 ·
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 84/100