trackmcp
Back to directory
goern

forgejo-mcp

View on GitHub

MIRROR ONLY!! This Model Context Protocol (MCP) server provides tools and resources for interacting with the Forgejo (specifically Codeberg.org) REST API.

13 stars GoWeb & Internet Tools Updated Oct 15, 2025

Documentation

Forgejo MCP Server

> πŸ“¦ This project has moved. Development, issues, releases, and container

> images now live at

> ****.

> The Codeberg repository at `codeberg.org/goern/forgejo-mcp` remains only as a

> read-only mirror, and its container registry no longer publishes images β€”

> pull from `git.b4mad.industries/agentic-forges/forgejo-mcp` instead. Issue

> numbers are preserved across the move. Contributions from humans and

> AI agents are welcome at the new location.

>

> ```bash

> git clone https://git.b4mad.industries/agentic-forges/forgejo-mcp.git

> ```

>

> If you have a remote or a bookmark pointing at `forgejo.b4mad.net`, that is

> the same forge under its previous name β€” renamed 2026-07-29, not moved

> again. The old name still resolves and serves port 2222 with the same host

> key, so existing clones keep working; repoint them at your leisure:

>

> ```bash

> git remote set-url origin \

> ssh://git@git.b4mad.industries:2222/agentic-forges/forgejo-mcp.git

> ssh-keyscan -p 2222 git.b4mad.industries >> ~/.ssh/known_hosts

> ```

Connect your AI assistant to Forgejo repositories. Manage issues, pull requests, files, and more through natural language.

What It Does

Forgejo MCP Server is an integration plugin that connects Forgejo with Model Context Protocol (MCP) systems. Once configured, you can interact with your Forgejo repositories through any MCP-compatible AI assistant like Claude, Cursor, or VS Code extensions.

Example commands you can use:

  • "List all my repositories"
  • "Create an issue titled 'Bug in login page'"
  • "Show me open pull requests in my-org/my-repo"
  • "Get the contents of README.md from the main branch"
  • "Show me the latest Actions workflow runs in agentic-forges/forgejo-mcp"

Quick Start

1. Install

Option A: Using Go (Recommended)

bash
git clone https://git.b4mad.industries/agentic-forges/forgejo-mcp.git
cd forgejo-mcp
go install .

Ensure `$GOPATH/bin` (typically `~/go/bin`) is in your PATH.

> Note: `go install` from the module path works from the first release

> after the module was renamed (see Known Issues):

>

> ```bash

> go install git.b4mad.industries/agentic-forges/forgejo-mcp/v2@latest

> ```

Option B: Download Binary

Download the latest release from the releases page.

For Arch Linux, use your favorite AUR helper:

bash
yay -S forgejo-mcp      # builds from source
yay -S forgejo-mcp-bin  # uses pre-built binary

Option C: Nix / NixOS

You can run the server directly using the Nix package manager:

bash
nix-shell -p forgejo-mcp

Or using Flakes:

bash
nix run nixpkgs#forgejo-mcp

> Note: `forgejo-mcp` is currently only available in the `unstable` channel and is not yet part of the 25.11 stable release.

Option D: Container image

A signed multi-stage OCI image is published on every release to

`git.b4mad.industries/agentic-forges/forgejo-mcp`. Run the server without building from source:

bash
# Latest release
podman run --rm -i \
  -e FORGEJO_ACCESS_TOKEN="" \
  git.b4mad.industries/agentic-forges/forgejo-mcp:latest \
  --transport stdio --url https://your-forgejo-instance.org

# Or pin a specific version
podman run --rm -i git.b4mad.industries/agentic-forges/forgejo-mcp:v2.24.0 --help
TagMeaning
`vMAJOR.MINOR.PATCH`Immutable β€” the exact release (e.g. `v2.24.0`). Use in production.
`latest`Moving β€” tracks the most recent release. Convenience only.

The image is single-arch (`linux/amd64`), signed with cosign, and carries an

attached CycloneDX SBOM. See Verify the container image

to check the signature and provenance before running.

2. Get Your Access Token

1. Log into your Forgejo instance

2. Go to Settings β†’ Applications β†’ Access Tokens

3. Create a new token with the permissions you need (repo, issue, etc.)

3. Configure Your AI Assistant

Add this to your MCP configuration file:

For stdio mode (most common):

json
{
  "mcpServers": {
    "forgejo": {
      "command": "forgejo-mcp",
      "args": [
        "--transport", "stdio",
        "--url", "https://your-forgejo-instance.org"
      ],
      "env": {
        "FORGEJO_ACCESS_TOKEN": "",
        "FORGEJO_USER_AGENT": "forgejo-mcp/1.0.0"
      }
    }
  }
}

For streamable HTTP mode (recommended for remote/Claude.ai):

json
{
  "mcpServers": {
    "forgejo": {
      "url": "http://localhost:8080/mcp"
    }
  }
}

When using streamable HTTP mode, start the server first:

bash
forgejo-mcp --transport http --url https://your-forgejo-instance.org --token

Multi-tenant HTTP mode (optional):

You can run a single centralized `forgejo-mcp` instance and let each client provide its own token via the standard HTTP `Authorization` header. This enables serving multiple users or agents from one server.

1. Start the server (optionally without any global token):

bash
forgejo-mcp --transport http --url https://your-forgejo-instance.org

2. Clients include their specific token in each request:

    See demos/multi-tenant-http.md for a copy-pasteable walkthrough.

    > Design rationale, token-resolution rules, and request-isolation guarantees: see the `stateless-http-auth` OpenSpec change (`openspec/changes/archive/`).

    For SSE mode (legacy HTTP-based):

    json
    {
      "mcpServers": {
        "forgejo": {
          "url": "http://localhost:8080/sse"
        }
      }
    }

    When using SSE mode, start the server first:

    bash
    forgejo-mcp --transport sse --url https://your-forgejo-instance.org --token

    4. Start Using It

    Open your MCP-compatible AI assistant and try:

    code
    List all my repositories

    Available Tools

    ToolDescription
    User
    `get_my_user_info`Get information about the authenticated user
    `check_notifications`Check and list user notifications
    `get_notification_thread`Get detailed info on a single notification thread
    `mark_notification_read`Mark a single notification thread as read
    `mark_all_notifications_read`Acknowledge all notifications
    `list_repo_notifications`Filter notifications scoped to a single repository
    `mark_repo_notifications_read`Mark all notifications in a specific repo as read
    `search_users`Search for users
    Repositories
    `list_my_repos`List all repositories you own
    `get_repo`Get a single repository by owner and name
    `create_repo`Create a new repository
    `fork_repo`Fork a repository
    `edit_repo`Edit repository settings. Only fields you pass change; omitted fields are left unchanged. Providing no fields is an error.
    `search_repos`Search for repositories
    Topics
    `list_repo_topics`List a repository's topics. Bounded by `page` (default 1) + `limit` (default 100); returns `{topics, page, limit, count}`.
    `set_repo_topics`Replace all topics. `topics` is a required comma-separated string; an empty string clears. Invalid names are rejected before the request.
    `add_repo_topic`Add one topic
    `delete_repo_topic`Delete one topic
    Branches
    `list_branches`List all branches in a repository
    `create_branch`Create a new branch
    `delete_branch`Delete a branch
    Branch Protection
    `list_branch_protections`List a repository's branch protection rules. Bounded by `page` (1-based) + `limit` (page size); the response echoes `page`/`limit` so callers can fetch the next page.
    `get_branch_protection`Get a single rule by `rule` name
    `create_branch_protection`Create a rule. Requires `branch_name`; `status_check_contexts` is a comma-separated list of required checks (e.g. `"ci/build,ci/test"`).
    `edit_branch_protection`Edit a rule by `rule` name. Only fields you pass change; omitted fields are left unchanged.
    `delete_branch_protection`Delete a rule by `rule` name
    Webhooks
    `list_repo_hooks`List repository webhooks. Bounded by `page` (default 1) + `limit` (default 30, no server-imposed ceiling); returns `total_count` when Forgejo reports `X-Total-Count`.
    `get_repo_hook`Get a single repository webhook by ID
    `create_repo_hook`Create a repository webhook. The secret is accepted but never echoed in the response.
    `edit_repo_hook`Edit a repository webhook. Only fields you pass change; omitted fields are left unchanged.
    `delete_repo_hook`Delete a repository webhook by ID
    `test_repo_hook`Trigger a test delivery for a repository webhook β€” WARNING: triggers a live HTTP delivery
    Files
    `get_file_content`Get the content of a file. Optional `start_line`/`end_line` request a 1-indexed inclusive line range (clamps to file extent; ignored when `with_metadata=true`).
    `create_file`Create a new file
    `update_file`Update an existing file
    `delete_file`Delete a file
    Commits
    `list_repo_commits`List commits in a repository
    Issues
    `list_repo_issues`List issues in a repository (page/limit). Optional `sort` orders server-side: `relevance`, `latest`, `oldest`, `recentupdate`, `leastupdate`, `mostcomment`, `leastcomment`, `nearduedate`, `farduedate` (the last two are the due-date directions).
    `search_issues`Search issues across every repository of one owner (page/limit); returns `{issues,page,limit,count,has_next,total_count}` β€” `total_count` is present only when Forgejo reports `X-Total-Count`
    `get_issue_by_index`Get a specific issue
    `create_issue`Create a new issue
    `add_issue_labels`Add labels to an issue (requires numeric label IDs)
    `remove_issue_labels`Remove labels from an issue (requires numeric label IDs)
    `update_issue`Update an existing issue (requires numeric milestone ID). `due_date` sets the deadline (RFC3339); `clear_due_date=true` removes it. The two are mutually exclusive β€” setting both is an error, and omitting both leaves the deadline unchanged.
    `issue_state_change`Open or close an issue
    `list_issue_dependencies`List issues the given issue depends on. Bounded by `page` (1-based) + `limit` (page size); the response echoes `page`/`limit` so callers can fetch the next page.
    `list_issue_dependents`List issues that depend on the given issue. Bounded by `page` (1-based) + `limit` (page size); the response echoes `page`/`limit` so callers can fetch the next page.
    `add_issue_dependency`Make one issue depend on another
    `remove_issue_dependency`Remove a dependency from an issue
    `list_repo_milestones`List milestones with their IDs (use with `update_issue`)
    `list_repo_labels`List labels with their IDs. Merges org-level labels for org-owned repos (set `include_org_labels=false` to opt out). Each entry carries a `scope` field (`"repo"` or `"org"`).
    `list_org_labels`List organization-level labels with their IDs (use with `add_issue_labels`, `remove_issue_labels`).
    `create_repo_label`Create a repository label (`name`, `color` as 6-digit hex, optional `description`). Returns numeric `id` for immediate use in `add_issue_labels`.
    `edit_repo_label`Edit a repository label (PATCH β€” only supplied fields change: `name`, `color`, `description`).
    `delete_repo_label`Delete a repository label. Refuses by default when the label is in use (reports count); set `delete_mode=force` to override.
    `get_repo_label`Get a single repository label by numeric `id`.
    `create_org_label`Create an organization-level label. Same fields as `create_repo_label`.
    `edit_org_label`Edit an organization-level label (PATCH semantics).
    `delete_org_label`Delete an organization-level label. In-use guard counts across visible org repos (best-effort); `delete_mode=force` overrides.
    `get_org_label`Get a single organization-level label by numeric `id`.
    Comments
    `list_issue_comments`List comments on an issue or PR
    `get_issue_comment`Get a specific comment
    `create_issue_comment`Add a comment to an issue or PR
    `edit_issue_comment`Edit a comment
    `delete_issue_comment`Delete a comment
    Pull Requests
    `list_repo_pull_requests`List pull requests in a repository
    `get_pull_request_by_index`Get a specific pull request
    `create_pull_request`Create a new pull request
    `update_pull_request`Update an existing pull request
    `list_pull_reviews`List reviews for a pull request
    `get_pull_review`Get a specific pull request review
    `list_pull_review_comments`List comments on a pull request review
    `list_pull_request_files`List changed files in a pull request (paginated). Use the returned filenames as the `file_path` argument to `get_pull_request_diff`.
    `get_pull_request_diff`Get the unified diff of a pull request. Optional `file_path` returns only that file's hunks (matches on either pre- or post-rename path).
    `merge_pull_request`Merge a pull request (style: merge/rebase/rebase-merge/squash; optional title/message/delete-branch/force-merge/wait-for-checks).
    `create_pull_review`Create a review on a pull request (state: APPROVED/REQUEST_CHANGES/COMMENT) with optional inline comments.
    Actions
    `dispatch_workflow`Trigger a workflow run via `workflow_dispatch` event
    `list_workflow_runs`List workflow runs with optional filtering by status, event, or SHA
    `get_workflow_run`Get details of a specific workflow run by ID
    `list_action_run_jobs`List jobs for a Forgejo v16+ workflow run with client-side `page` and `limit` bounds
    `get_action_job_logs`Read a Forgejo v16+ job log with resumable `offset` and `max_bytes` bounds; defaults to the tail
    `cancel_workflow_run`Cancel a pending or running workflow run. Already-finished runs also return success (HTTP 204); the run is left unchanged
    `delete_workflow_run`Delete a completed workflow run. A live run is an API error. Removes the run and its job logs; Forgejo marks that run's artifacts deleted
    `list_action_run_artifacts`List artifacts of a workflow run. Server-paged via `page`/`limit` (default 30, max 50); optional `name` filter. Envelope `{artifacts, page, limit, count, total_count?}`
    `get_action_artifact`Get metadata for one Actions artifact. Does not download the zip
    Organizations
    `search_org_teams`Search for teams in an organization
    Time Tracking
    `list_issue_tracked_times`List tracked time entries on an issue or PR
    `list_repo_tracked_times`List tracked time entries across a repository
    `list_my_tracked_times`List your own tracked time entries
    `add_issue_time`Log time against an issue or PR (accepts seconds or duration like `15m`)
    `reset_issue_time`Delete ALL tracked time entries on an issue or PR (destructive)
    `delete_issue_time_entry`Delete a single tracked time entry by ID
    `start_issue_stopwatch`Start a stopwatch on an issue or PR
    `stop_issue_stopwatch`Stop a running stopwatch and record the elapsed time
    `cancel_issue_stopwatch`Cancel a running stopwatch without recording
    `list_my_stopwatches`List currently running stopwatches
    Attachments
    `list_issue_attachments`List attachments on an issue or PR
    `get_issue_attachment`Get metadata for a single issue/PR attachment
    `download_issue_attachment`Download an issue/PR attachment (inline if `)
    -`FORGEJO_MCP_ALLOW_FILE_PATH_UPLOAD`Allow `file_path` attachment uploads to read the host filesystem (`1`/`true`/`yes`/`on`; off by default)
    -`FORGEJO_MCP_UPLOAD_ROOT`Confine `file_path` uploads to this directory (default: anywhere the process can read)

    Command-line arguments take priority over environment variables.

    Uploading attachments from the host filesystem

    `create_issue_attachment`, `create_comment_attachment`, and

    `create_release_attachment` accept either base64 `content` or a `file_path` on

    the machine running `forgejo-mcp`. The path form avoids base64-expanding a large

    release artifact through the MCP transport.

    It is off by default, because it hands whatever drives the MCP client the

    ability to read any file the server process can read β€” a prompt-injected agent

    could upload `~/.ssh/id_ed25519` as a public release asset. Turn it on

    deliberately, and prefer confining it:

    bash
    export FORGEJO_MCP_ALLOW_FILE_PATH_UPLOAD=1
    export FORGEJO_MCP_UPLOAD_ROOT=/home/you/build/dist   # optional but recommended

    With `FORGEJO_MCP_UPLOAD_ROOT` set, a path that resolves outside that directory

    β€” by being absolute, by `..`, or through a symlink β€” is rejected before anything

    is read. Base64 `content` uploads are unaffected by either variable.

    Verifying Releases

    Release archives are accompanied by a `checksums.txt` file and an optional

    `checksums.txt.sig` produced by cosign

    with the project's release keypair. Verifying both files lets you confirm

    that the binary you downloaded was built by the project's release pipeline

    and has not been tampered with in transit.

    > Heads up: cosign signing was introduced mid-2026. Tags released

    > before signing was wired up ship without a `.sig` file β€” verification

    > applies from `v2.23.x` onward only, and only when the

    > `COSIGN_PRIVATE_KEY` secret was configured at release time.

    1. Install cosign

    Follow the upstream

    cosign installation guide

    for your platform. Quick paths:

    bash
    # Linux/macOS β€” pinned binary
    COSIGN_VERSION=v2.4.1
    curl -sSfL -o /usr/local/bin/cosign \
      "https://github.com/sigstore/cosign/releases/download/${COSIGN_VERSION}/cosign-linux-amd64"
    chmod +x /usr/local/bin/cosign
    
    # macOS via Homebrew
    brew install cosign
    
    # Arch Linux
    sudo pacman -S cosign

    Confirm:

    bash
    cosign version

    2. Fetch the public key

    The normative source for the cosign public key is the

    `op1st-emea-b4mad`

    GitOps repo β€” same source of truth that provisions the

    `cosign-signing-key-artifacts` Secret in the `op1st-pipelines` namespace

    where the release pipeline runs. This is the artifact-signing key that

    signs release blobs (`checksums.txt.sig`); it is distinct from the

    image-signing key `cosign-signing-key-images.pub` used in Β§5–§6 below.

    Two ways to fetch it:

    Branch-tip (live, follows future key rotations):

    bash
    curl -sSfL -o cosign.pub \
      https://codeberg.org/operate-first/op1st-emea-b4mad/raw/branch/main/manifests/applications/op1st-pipelines-tokens/cosign-signing-key-artifacts.pub

    Commit-pinned (tamper-evident, recommended for CI/scripts):

    bash
    curl -sSfL -o cosign.pub \
      https://codeberg.org/operate-first/op1st-emea-b4mad/raw/commit/cd3715fa8283a2069a2e3e299744a7b55b1b0260/manifests/applications/op1st-pipelines-tokens/cosign-signing-key-artifacts.pub

    The commit-pinned permalink hashes its content into the URL β€” if anyone

    ever rewrites the file at that commit, your download fails or mismatches.

    Pin to the latest commit that you trust before adopting the key in

    automation.

    3. Download the release artifacts

    Pick the tag you installed (e.g. `v2.23.1`) and grab the checksum file,

    its signature, and the binary archive:

    bash
    TAG=v2.23.1
    VERSION="${TAG#v}"
    BASE="https://git.b4mad.industries/agentic-forges/forgejo-mcp/releases/download/${TAG}"
    
    curl -sSfLO "${BASE}/forgejo-mcp_${VERSION}_checksums.txt"
    curl -sSfLO "${BASE}/forgejo-mcp_${VERSION}_checksums.txt.sig"
    curl -sSfLO "${BASE}/forgejo-mcp_${VERSION}_linux_amd64.tar.gz"   # adjust os/arch

    4. Verify the signature, then the checksum

    Cosign verifies that `checksums.txt` was signed by the holder of the

    private key matching `cosign.pub`. Once the checksum file is trusted, a

    plain `sha256sum -c` check confirms the archive's integrity.

    bash
    # Verify checksums.txt against the signature.
    cosign verify-blob \
      --key cosign.pub \
      --signature "forgejo-mcp_${VERSION}_checksums.txt.sig" \
      "forgejo-mcp_${VERSION}_checksums.txt"
    # Expected: "Verified OK"
    
    # Verify the downloaded archive against the (now-trusted) checksums.
    sha256sum --ignore-missing -c "forgejo-mcp_${VERSION}_checksums.txt"
    # Expected: ": OK"

    The checksum chain transitively covers the SBOMs and other per-archive

    assets β€” verifying `checksums.txt` once is sufficient for everything

    listed inside it.

    5. Verify SLSA provenance for the release-tools image

    The release-tools container image (used internally by the Tekton release

    pipeline) carries SLSA v1.0 provenance generated by [Tekton

    Chains](https://tekton.dev/docs/chains/). This attestation binds the image

    digest to the exact PipelineRun, git commit, and builder identity that

    produced it β€” providing supply-chain provenance beyond what the cosign

    signature alone can attest.

    Fetch the `cosign-signing-key-images` public key (a separate key from the

    artifact-signing key above):

    bash
    curl -sSfL -o cosign-images.pub \
      https://codeberg.org/operate-first/op1st-emea-b4mad/raw/branch/main/manifests/applications/op1st-pipelines-tokens/cosign-signing-key-images.pub

    Verify the attestation against a specific image tag:

    bash
    IMAGE_TAG=v1.0.0   # substitute the release-tools tag you want to verify
    cosign verify-attestation \
      --type slsaprovenance \
      --key cosign-images.pub \
      "codeberg.org/operate-first/release-tools:${IMAGE_TAG}" \
      | jq .

    A successful run prints the decoded in-toto statement (JSON). Check that

    `predicate.buildDefinition.externalParameters.runSpec.params` references the

    expected git revision, and `predicate.runDetails.builder.id` shows the

    Tekton Chains builder.

    > Note: SLSA provenance attestations are available from releases built

    > after forgejo-mcp-46j (Tekton Chains support) landed. Earlier image tags

    > carry only the cosign signature; they have no `verify-attestation` payload.

    6. Verify the container image

    The `git.b4mad.industries/agentic-forges/forgejo-mcp` application image (Option D)

    is signed by the same `cosign-signing-key-images` key as the release-tools

    image, carries an attached CycloneDX SBOM, and gets SLSA v1.0 provenance from

    Tekton Chains. Reuse the `cosign-images.pub` key fetched above.

    Verify the signature:

    bash
    IMAGE_TAG=v2.24.0   # substitute the release you are pulling
    cosign verify \
      --key cosign-images.pub \
      "git.b4mad.industries/agentic-forges/forgejo-mcp:${IMAGE_TAG}" \
      | jq .

    Verify the SLSA provenance attestation:

    bash
    cosign verify-attestation \
      --type slsaprovenance \
      --key cosign-images.pub \
      "git.b4mad.industries/agentic-forges/forgejo-mcp:${IMAGE_TAG}" \
      | jq .

    Verify and download the signed CycloneDX SBOM attestation:

    bash
    cosign verify-attestation \
      --type cyclonedx \
      --key cosign-images.pub \
      "git.b4mad.industries/agentic-forges/forgejo-mcp:${IMAGE_TAG}" \
      | jq -r '.payload | @base64d | fromjson | .predicate' > forgejo-mcp.cdx.json

    > The SBOM is now a signed in-toto attestation (`cosign attest`), not an

    > unsigned `attach sbom` artifact. `cosign download sbom` no longer applies.

    Because the publish pipeline pushes by digest and only promotes the

    `vX.Y.Z` / `latest` tags *after* signing and SBOM attachment succeed, any tag

    you can pull is guaranteed to be signed.

    Troubleshooting verification

    • `Error: no matching signatures` β€” the `.sig` file is from a

    different release, or `cosign.pub` is the wrong key. Re-download both

    from the same tag.

    • `Error: cannot read file: checksums.txt.sig` β€” release predates

    cosign signing, or signing was skipped that run because the secret was

    unset. Fall back to the checksum-only check (`sha256sum -c`), which

    still detects in-transit corruption but not tampering.

    • Mismatch between `cosign.pub` and the signature β€” confirm you

    fetched the public key from a commit that includes the key in use at

    the time of the release. If in doubt, fetch from `branch/main`.

    Troubleshooting

    Enable debug mode to see detailed logs:

    bash
    forgejo-mcp --transport sse --url  --token  --debug

    Or set the environment variable:

    bash
    export FORGEJO_DEBUG=true

    Custom User-Agent: If your Forgejo instance or proxy blocks the default `go-http-client` user agent, set a custom one:

    bash
    # Via environment variable
    export FORGEJO_USER_AGENT="forgejo-mcp/1.0.0"
    
    # Or via CLI flag
    forgejo-mcp --user-agent "forgejo-mcp/1.0.0" --transport sse --url  --token

    Getting Help

    This repository is also mirrored on Radicle β€” a peer-to-peer code collaboration network. Clone via:

    bash
    rad clone rad:z4PdPpsH9iJQcWfqTbxpFcWaZ9zPL

    For Developers

    See DEVELOPER.md for build instructions, architecture overview, and contribution guidelines.

    Known Issues

    • `go install ...@latest` needs a post-rename release β€” The Go module path

    was `codeberg.org/goern/forgejo-mcp/v2` until the forge move; Go resolves

    modules by the path declared in `go.mod`, so the

    `git.b4mad.industries/...` path only becomes installable once a release is

    tagged carrying the renamed `go.mod`. Until then, use the clone-and-build

    workflow shown in Quick Start. The old

    `go install codeberg.org/goern/forgejo-mcp/v2@latest` still resolves against

    the read-only Codeberg mirror, but that mirror lags behind the current

    release β€” do not rely on it. The earlier `replace`-directive blocker

    (#67) is

    gone; `go.mod` no longer contains one.

    Contributors

    forgejo-mcp is shaped by everyone who files issues, writes code, reviews PRs, and pushes the project forward. Thank you all. πŸ™

    Code contributors

    ContributorHighlights
    goern (Christoph GΓΆrn)Project creator and maintainer
    Ronmi RenCo-creator; SSE/HTTP transport, issue blocking, CI/CD improvements, logo, Glama spec
    twstagg (Tristin Stagg)User agent configuration support (PR #89)
    mattdm (Matthew Miller)Logging improvements, FORGEJO_* migration, README, URL refactor
    byteflavour`check_notifications` + full notification management API (PR #84, #86); stateless per-request auth for HTTP/SSE transports (PR #138); NixOS installation docs (PR #146); feature requests #80, #85
    jesterretPull request reviews and comments support (PR #51)
    appleboyCustom SSE port support, bug fixes
    ignasgil`remove_issue_labels` tool (PR #96)
    dmikushin (Dmitry Mikushin)Fix string-encoded number parameter parsing from MCP clients (PR #93)
    jiriks74mcp-go v0.44.0 dependency update (PR #90)
    th (Tomi Haapaniemi)`update_pull_request` tool
    hiifongEarly bug fixes and updates
    Lunny XiaoEarly contributions
    techknowlogickEarly contributions
    yp05327Early contributions
    mw75Owner/org support for repo creation (PR #18)
    Dax KelsonIssue comment management (PR #34)
    Guruprasad KulkarniArch Linux AUR installation docs (PR #69)
    Mario WolffContributions
    Massimo FraschettiContributions
    synath (David Paul Turley)Repository-scoped token support via `ServerVersion` probe (PR #112); merge status-code check (PR #113); Claude Desktop Extension (.mcpb) packaging (PR #118)
    BrilliantKahn`get_file_content` plain-text default (PR #116); `list_repo_contents` and `get_repo_tree` tools (PR #117). First-ever open source contribution β€” welcome aboard! πŸŽ‰
    pisco (Marco Pisco)`file_path` uploads for issue, comment, and release attachments, with streaming multipart so large release assets no longer round-trip through base64 (PR #481)

    Community contributors

    Issue reporters and discussion participants who shaped the direction of the project:

    ContributorContributions
    byteflavourFiled #80 (milestone/label discovery), #85 (notification API proposal); active reviewer in discussions
    choucavalierFiled #82 (fix skill), #70 (macOS arm64 releases), #62 (binary releases & mise support)
    MalcolmMielleFiled #59 (PR review tools β€” since implemented)
    redbeardFiled #60 (Actions support β€” since implemented)
    c6sepl6pFiled #72 (base64 encoding), #54 (merge pull request β€” since implemented)
    malikFiled #73 (version flag), #47 (Nix build fix)
    a2800276Filed #74 (OpenAI compatibility)
    simenandreFiled #49 (go install support)
    BasdPFiled #42 (Projects support)
    BoBeR182Filed #32 (wiki support)
    ignasgilFiled #95 (`remove_issue_labels` feature request)
    VokuarFiled #99 (streamable HTTP transport support)
    janbaerFiled #98 (reply to review comment)
    fraschm98Early issue reports
    heathen711Filed #106 (issue/comment attachments β€” since implemented); shaped the 1 MiB inline cap + `browser_download_url` fall-through design
    chris420 (Chris Oloff)Filed #452 (org-wide issue search β€” since implemented as `search_issues`); design review on PR #458 that replaced the next-page probe with instance-ceiling enforcement, and caught the response envelope misreporting its own `limit`

    Cyborg contributors

    This project also received contributions from AI coding agents β€” submitted as regular PRs, reviewed by humans:

    AgentRoleContributions
    brenner-axiom (b4-dev, B4arena)AI dev agentOrganization management tools (PR #94); showboat demos (PR #97); `list_repo_milestones`, `list_repo_labels` tools (PR #83); race condition fix (PR #78); contributors docs (PR #87, #88); filed #76; code reviews
    opencodeAI dev agentPull request reviews and comments support (PR #51)
    claude-codeAI dev agent`get_file_content` plain-text default and `list_repo_contents`/`get_repo_tree` tools, paired with BrilliantKahn (PR #116, #117)
    b4mad-release-agentRelease automationAutomated changelog and release tagging
    the #B4mad Renovate botDependency updatesAutomated dependency upgrades

    Want to contribute? Open an issue or pull request β€” all are welcome.

    License

    This project is open source. See the repository for license details.

    Frequently asked questions

    What is forgejo-mcp?

    forgejo-mcp is MIRROR ONLY!! This Model Context Protocol (MCP) server provides tools and resources for interacting with the Forgejo (specifically Codeberg.org) REST API.

    How do I install forgejo-mcp?

    Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.

    Is forgejo-mcp open source?

    Yes β€” it is hosted on GitHub at https://github.com/goern/forgejo-mcp and has 13 stars.

    Related MCP tools

    Run your own MCP server? See who uses it and what to fix.

    Measure it with TrackMCP