Connect GitHub to Claude. For your whole team.
GitHub's official MCP server signs in one person with OAuth and ships write tools for issues, pull requests, files and merges unless you remember the read-only switch. Loopthink holds one fine-grained read token for the repositories you choose, gives every Claude user in your team their own login, and lets Engineering, Product and Management see exactly what their role allows.
Free for your own server · Team from €99 · EU-hosted
GitHub in a chat client, today.
Today a team that wants GitHub in an AI client either has every person sign in with their own GitHub account, which is fine for engineers and a paid seat for everyone else, or shares one token. A shared classic token reaches every repository its owner can see and can push, merge and delete. GitHub's audit log then shows the token's owner, not the person who typed the prompt.
One matrix for GitHub. Roles across, tools down.
| Tool | Engineering | Product | Management |
|---|---|---|---|
| Repositories & code | Engineering may use Repositories & code | Product may not use Repositories & code | Management may not use Repositories & code |
| Issues | Engineering may use Issues | Product may use Issues | Management may use Issues |
| Pull requests | Engineering may use Pull requests | Product may use Pull requests | Management may use Pull requests |
| Actions runs | Engineering may use Actions runs | Product may not use Actions runs | Management may use Actions runs |
| Security alerts | Engineering may use Security alerts | Product may not use Security alerts | Management may not use Security alerts |
| Write actions off by default | Engineering may not use Write actions | Product may not use Write actions | Management may not use Write actions |
Masked for every role: commit author emails, secrets and tokens quoted in issues, external contributors' names.
You set this once. Every Claude user in your team gets exactly this.
Once on the GitHub side, once in Claude.
On the GitHub side
Fine-grained personal access token, read permissions, selected repositories
- 1
GitHub → Settings → Developer settings → Personal access tokens → Fine-grained tokens → Generate new token. Resource owner: your organisation. Repository access: only the repositories your team should reach.
- 2
Permissions: Contents Read, Issues Read, Pull requests Read, Actions Read. Metadata is included. Nothing on Write. An organisation owner approves the token once.
- 3
Paste the token into Loopthink. Your team never sees it; each person signs in with their own identity.
In Claude
Custom connector, OAuth
- 1
An Owner opens Organization settings → Connectors → Add and pastes your Loopthink connector URL. On Free, Pro and Max: Customize → Connectors → + → Add custom connector.
- 2
Each team member opens Customize → Connectors, clicks Connect on Loopthink and signs in once with their own account.
- 3
In a chat, the + menu lists the connector. Toggle it on, ask away. No key, no config file.
Custom connectors are available on Free, Pro, Max, Team and Enterprise. On Team and Enterprise only Owners can add one; every member still connects individually, which is exactly what gives each call its own identity.
Steps checked against the vendor documentation on 17 September 2026: GitHub MCP server · Set up the GitHub MCP server · Fine-grained personal access tokens · Token permissions · Get started with custom connectors using remote MCP · Use connectors to extend Claude's capabilities
Loopthink sits in between: it holds the key, shows Claude a normal login, and applies your roles on every call.
Four checks between Claude and GitHub.
- 01
Identify
OIDC/SSO against your own IdP, including Microsoft Entra. The call runs as the person who made it, never as a shared service account.
- 02
Authorize
Per-role, per-tool, read or write. Anything not explicitly granted never shows up in the tool list in the first place.
- 03
Mask
Field-level masking and pseudonymization applied on your side, before the result travels. The model never sees the raw field. Composio, AnythingMCP and both provider tunnels have no field-level masking at all.
- 04
Log
Who asked, which tool, which records, which fields were masked. One audit trail across every AI client, exportable for review.
What people actually ask Claude about GitHub.
- Engineering
“Which pull requests have waited for a review for more than three days?”
- Product
“Which issues labelled customer-bug were closed this sprint, and which are still open?”
- Management
“How many releases shipped this quarter, and did any deploy workflow fail?”
Each question runs as the person who asked it, with that person's role. A Product colleague asking the Engineering question gets the tools their own role allows, not an error, not more.
Four ways to put GitHub into Claude.
| Native GitHub connector | Build it yourself | Enterprise gateways1 | Loopthink | |
|---|---|---|---|---|
| Per-user identity | One personal login, all its rights | Only if you build it | Yes | Yes, every call runs as the person who asked |
| Tool-level roles | No | Your code | Yes | Yes, write off by default |
| Field masking | No | Your code | Not documented | Yes, before the model sees the data |
| Published price | Included in your GitHub plan | Your engineers' time | Contact sales | Free, Team from €99 |
| EU company | No | Whatever you are | Mostly US | Yes, Germany |
Native GitHub connector: Official GitHub MCP server with OAuth. The signed-in person's rights across their repositories; write tools on unless the URL ends in /readonly.
1 MintMCP, MCP Manager, Pomerium
Coming from one of them? Composio alternative · MintMCP alternative · MCP Manager alternative · AnythingMCP alternative
Also for
Connect another system to Claude
Before you connect.
- Does every team member need their own GitHub account?
- No. Loopthink holds one key or token for GitHub. Your people sign in to Loopthink with their own identity, and every call to GitHub is logged under their name. Seats in GitHub stay where they are today.
- Who has to add the connector in Claude?
- One person with the right to add connectors in your Claude workspace, once. After that every team member enables it for themselves. Nobody pastes a key, nobody edits a config file.
- Where does the GitHub key live?
- In Loopthink, encrypted, in the EU. It never reaches Claude and never reaches the people using the connector. Rotate it in GitHub whenever you like and paste the new one once.
- Can somebody write to GitHub from the chat?
- Not unless you switch it on. Write actions are a separate row in the permission matrix and are off for every role by default. If a role needs one write tool, you grant that one tool to that one role.
- What does the model see?
- The result of the tool call, after masking. Fields you mark as personal, such as emails, names or card details, are masked before the answer travels to Claude. The model gets the numbers, not the people.
- Is there an audit trail?
- Yes. Who asked, which tool, which parameters, which fields were masked, when. One log across every client your team uses, exportable for review.
- What does it cost?
- Free for one person and your own MCP server, forever. Team starts at €99 per month and covers the built connector, per-person identity, roles, masking and audit for the whole team. Prices are on the pricing page, no call needed.
- We already run our own MCP server for GitHub. Does it still work?
- Yes. Point it at Loopthink and it inherits the same login, roles, masking and audit. Nothing on the server has to change.
GitHub in Claude, with rules.
One key in Loopthink, one login per person, one matrix that decides who may do what.
Free for your own server · Team from €99 · EU-hosted
