How to Connect GitHub to Claude and Cursor for a Whole Team

Last updated ·Read as Markdown
Answer

Set up GitHub once in an MCP gateway instead of in each person's Claude and Cursor config. Create the GitHub integration, expose read tools only, have a GitHub organization owner approve the app if the organization restricts OAuth apps, and allow the integration for an engineering group. Each person authorizes with their own GitHub account and adds one MCP URL to both Claude and Cursor. With Metorial, that is a Magic MCP URL, and calls are logged per person.

Connecting GitHub to Claude for one developer takes a token and a config file. Connecting it to Claude and Cursor for forty people, without forty tokens, takes one gateway setup and one URL per person.

If your team
Use
Is on github.com
The GitHub.com auth method, with per-person sign-in
Is on GitHub Enterprise
The Enterprise auth method
Belongs to an organization that restricts OAuth apps
Owner approval first, then the group connects
Needs a scheduled agent with no person behind it
A dedicated machine account, as a pre-configured listing

What do you need before starting?

  • A GitHub organization owner, or someone who can request approval from one.
  • Claude and Cursor, or any other MCP client.
  • A Metorial account. The Dev plan is free.
  • A decision to start read-only.

How do you connect GitHub to Claude and Cursor?

1. Create the integration. In Metorial, open Integrations, select Create Integration, and choose GitHub. Under Auth Method, you will see GitHub.com, Enterprise, Personal Access Token (GitHub.com), and Personal Access Token (Enterprise). For a team, choose GitHub.com or Enterprise so each person signs in as themselves.

2. Limit the tools. Open Tool Filters. GitHub's tools are grouped into read-only tools, such as listing issues and pull requests or searching repositories, and write tools. Set the write group to Reject. Use Mixed later if you want to allow one write tool, such as creating issues.

3. Get organization approval. Where an organization restricts OAuth apps, a member's authorization becomes a request that an owner approves. Ask the owner to approve it before rollout so nobody hits a blocked screen.

4. Allow it for the engineering group. In Workforce, under Access, select Groups and create the group, then select Integrations and Add Integration. In the integration's Access section, select Add Group, set it to Allow, and save.

5. Publish it so people connect as themselves. Add the integration to a portal as a user-configured listing. Each person opens the portal, authorizes GitHub with their own account, and copies their Magic MCP URL.

6. Add the same URL to both clients. Paste it into Claude's MCP server settings and into Cursor's MCP settings. The same tools and the same permissions appear in each, so a person who uses both configures GitHub once.

7. Check the first call. Ask for something specific, such as "list the open pull requests in the payments repository". Then open Integrations, Connection Logs, Tool Calls and confirm the row names the tool, the arguments, and the person.

How much repository access does GitHub sign-in grant?

It depends on the kind of GitHub app behind the sign-in, and it is worth checking on the consent screen. GitHub documents the OAuth repo scope as full access to public and private repositories, and says it is not limited to selected repositories. GitHub Apps use fine-grained permissions and let whoever installs them pick the repositories. OAuth tokens are long-lived by default.

So the limits that always hold are the ones you set in Metorial: which tools exist, and which groups may use them. Beyond those, each person's agent reaches only what that person's GitHub account can reach.

Which tools should an engineering team start with?

Read tools cover most of the value: finding code, reading issues, summarizing pull requests, and checking recent commits. Start there for two weeks and look at Tool Calls to see what people asked for.

Then add writes selectively. Creating an issue is low risk and easy to revert. Tools that update a repository or review a pull request deserve a smaller group and a clear owner. See How to restrict AI agents to read-only tools for the pattern.

What if the organization blocks the app?

GitHub turns on OAuth app access restrictions by default for new organizations. Members cannot authorize an app on their own. They request approval, and owners are notified of pending requests and decide whether to grant or deny each one. Owners can also choose whether outside collaborators may request access. Send the owner the integration name and the tools you plan to expose, so the request can be approved in one pass.

What about personal access tokens?

A personal access token belongs to one person and ends up pasted into config files across laptops. Use one only for a single developer testing, or for a dedicated machine account whose owner is a team rather than a leaver. How to connect AI agents to company apps without sharing API keys covers why per-person sign-in is the better default.

Frequently asked questions

Should the team use personal access tokens?

Not for a team. A personal access token is tied to one person, lives wherever it was pasted, and usually carries more access than the task needs. Metorial offers token options for GitHub.com and Enterprise, but per-person sign-in with the GitHub.com or Enterprise method keeps access tied to each individual.

Does an organization owner need to approve this?

If the organization restricts OAuth app access, yes. GitHub enables those restrictions by default on new organizations, and members request approval while owners approve or deny the request. Approve once, then everyone in the group can connect.

Can we limit the agent to specific repositories?

Not through the OAuth `repo` scope, which GitHub says is not limited to selected repositories. GitHub Apps can be limited to selected repositories at installation. Metorial tool filters and each person's own repository access then narrow what the agent can do.

Does GitHub Enterprise work?

Metorial's GitHub integration lists separate Enterprise and Personal Access Token (Enterprise) authentication methods alongside the GitHub.com ones, so you choose the one that matches where your code lives.

How do we stop an agent from changing code?

Reject the write tools when you create the integration. Metorial groups GitHub tools into read-only and write tools, so a team can list issues, read pull requests, and search code without being able to update a repository.

Sources

  1. Metorial documentation: Create an integration
  2. GitHub Docs: Scopes for OAuth apps
  3. GitHub Docs: About OAuth app access restrictions
  4. GitHub Docs: Differences between GitHub Apps and OAuth apps

Ready to build with Metorial?

Connect any AI agent to any tool or data source. Govern every action.