Hosted MCP cannot resolve review threads with a fine-grained PAT that succeeds via GraphQL

Aberta
#3,249 0 comentários 0 reações 0 responsáveis Ver no GitHub

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
4/5
Tempo estimado
3-5 dias
Facilidade para iniciantes
35/100
Tipo de issue
Bug
Clareza
Razoavelmente clara
Status de atividade
Ativa
Stack de tecnologia
github, go

Direção de pesquisa

Comece pelo ponto de entrada da ferramenta hospedada de MCP para resolução de threads de revisão e reproduza a falha usando o endpoint, os toolsets e o fine-grained PAT listados. Compare o caminho de autorização da operação com a mutation GraphQL resolveReviewThread bem-sucedida. Está concluído quando a operação MCP resolver a thread de revisão com o mesmo token e preservar o comportamento existente de inline-reply.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

ai:bug-report-review:unable-to-process bug server

Summary

GitHub hosted remote MCP fails to resolve pull request review threads with a fine-grained personal access token, returning:

Resource not accessible by personal access token

The same token successfully performs both unresolveReviewThread and resolveReviewThread through GitHub GraphQL. This appears related to #2381, which reports a different hosted-MCP PR operation failing while the equivalent direct API request succeeds.

Environment

  • Server: GitHub-hosted remote MCP
  • Endpoint: https://api.githubcopilot.com/mcp/
  • Transport: Remote HTTP
  • Client: OpenCode
  • Authentication: fine-grained PAT supplied in the Authorization: Bearer header
  • MCP toolsets: repos,issues,pull_requests
  • Repository: crsiebler/pogo-gbl-analyzer
  • Token repository permission: Pull requests: Read and write
  • Approximate failure time: 2026-09-08 05:35 UTC

Reproduction

  1. Configure the hosted server with oauth: false, the endpoint above, an Authorization: Bearer {env:GITHUB_MCP_TOKEN} header, and X-MCP-Toolsets: repos,issues,pull_requests.
  2. Authenticate with a fine-grained PAT that has access to crsiebler/pogo-gbl-analyzer and Pull requests: Read and write.
  3. Read review threads for crsiebler/pogo-gbl-analyzer#10.
  4. Attempt to resolve PRRT_kwDOPgvNY86gGnRD with the MCP review-thread resolution tool.
  5. Observe:
failed to resolve review thread: Resource not accessible by personal access token

Expected Behavior

The MCP operation resolves the review thread, matching GitHub GraphQL behavior for the same token.

Actual Behavior

The MCP operation returns a personal-access-token authorization error. Other writes succeeded in the same MCP workflow: inline replies were posted to five pull request review-comment threads.

Direct GraphQL Verification

Using the same fine-grained PAT outside MCP, unresolving the thread succeeded:

GH_TOKEN=github_pat_REDACTED gh api graphql \
  -f query='mutation($threadId: ID!) {
    unresolveReviewThread(input: {threadId: $threadId}) {
      thread { id isResolved }
    }
  }' \
  -f threadId='PRRT_kwDOPgvNY86gGnRD'

Response:

{
  "data": {
    "unresolveReviewThread": {
      "thread": {
        "id": "PRRT_kwDOPgvNY86gGnRD",
        "isResolved": false
      }
    }
  }
}

Resolving it again with the same token also succeeded:

GH_TOKEN=github_pat_REDACTED gh api graphql \
  -f query='mutation($threadId: ID!) {
    resolveReviewThread(input: {threadId: $threadId}) {
      thread { id isResolved }
    }
  }' \
  -f threadId='PRRT_kwDOPgvNY86gGnRD'

Response:

{
  "data": {
    "resolveReviewThread": {
      "thread": {
        "id": "PRRT_kwDOPgvNY86gGnRD",
        "isResolved": true
      }
    }
  }
}

Impact

Agents can reply to inline review feedback but cannot complete the normal review workflow by resolving addressed threads through the hosted GitHub MCP server, despite the configured PAT being authorized for the underlying GraphQL mutation.

Notes

  • The token value is intentionally omitted.
  • The hosted endpoint does not expose a locally inspectable server version.
  • Inline reply timestamps immediately preceding the failure were 2026-09-08T05:35:45Z and 2026-09-08T05:35:46Z.
Linguagem predominante
Go
Estrelas
33.1k
Forks
5k
Merge médio
2d 15h
PRs com merge (30d)
27

Guia de contribuição

Abrir o guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de github/github-mcp-server

Todas as issues de github/github-mcp-server

Issues semelhantes

Mais issues de Go

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.