# GitLab MCP connector

Connect GitLab to Elaichi and Claude, ChatGPT, Cursor, or any MCP client can read your projects, branches and merge requests, draft commits and reviews, and leave comments, with each person signed in as themselves and every call logged.

Source: https://elaichi.ai/connectors/gitlab/

## Facts

| | |
| --- | --- |
| Application | GitLab |
| Category | Application Development |
| AI tools | 47 |
| Authentication | Connects over OAuth |
| Bring your own OAuth app | No |
| Native MCP | Yes. GitLab builds and runs this MCP server. Elaichi adds sign-in, access controls and an audit log on top |
| Support for its tools | support.gitlab.com/hc/en-us |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once GitLab is connected

- Summarize the open merge requests on the billing project.
- Which commits landed on main since the last release?
- Open a branch for the login fix and draft a merge request.

## Connect GitLab in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick GitLab.
2. Optionally set Share with, then press Connect.
3. Approve it in GitLab. GitLab's own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which GitLab tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## GitLab MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## GitLab MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## GitLab MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect GitLab to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a GitLab tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with GitLab through Elaichi

### Get the gist of a merge request first

Engineering. Ask for a summary of a GitLab merge request, the commits behind it and the discussion so far, before you open the diff yourself.

### Start a fix without leaving the chat

Engineering. Have the agent open a branch in the right GitLab project, commit the change you describe, and draft the merge request for you to check.

### Catch up on what is waiting for review

Engineering management. List the open merge requests across your GitLab projects, see who they are assigned to and how long they have been sitting.

### Draft release notes from the commit history

Release. Pull the commits that landed since the last GitLab release and turn them into notes a customer could read.

### Find out whether a fix has merged

Support. Ask whether the merge request for a customer's bug has been accepted in GitLab and which release it went out in.

### Check who has access to a project

Security. List the members of a GitLab project and their roles when an auditor asks, or when a contractor engagement ends.

## Elaichi vs Zapier MCP vs Composio for GitLab

All three can connect GitLab to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over GitLab tools | Allow or restrict single GitLab tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per GitLab call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect GitLab to Claude?

Connect GitLab in Elaichi first, which opens GitLab's own sign-in page so you authorize it with your usual account. There is no OAuth application to register and no client ID or secret to generate. Then in Claude go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp as the endpoint. GitLab is then available in Claude the next time you start a conversation.

### Does GitLab work with ChatGPT and Cursor as well as Claude?

Yes. Once GitLab is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect GitLab once and every client you use picks it up.

### What can an AI agent actually do with my GitLab data?

An agent connected to GitLab through Elaichi can look up projects, branches, commits, releases and repository files, list and summarize merge requests, and tell you who is a member of a project. It can also open a branch, add a commit, create or update a merge request, leave a review or a comment, accept a merge request, fork a repository, and start a session with GitLab Duo. Short, concrete asks such as "list open merge requests on the billing project" work better than long paragraphs.

### Does connecting GitLab give the AI access to every project?

No. The AI acts as the person who signed in to GitLab, so it can only see the projects, groups and repositories that person can already see. Elaichi can narrow that access further by restricting which actions a team may use, but it can never widen it beyond what GitLab itself allows that person.

### Can my team share one GitLab connection?

Yes. One person connects GitLab in Elaichi and shares the connection with a team, and nobody else on that team ever handles a token or a credential. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person behind every commit, comment or merge.

### Can I stop an agent from merging or changing things in GitLab?

Yes. Restrictions in Elaichi apply per action, so you can allow reading merge requests and commits in GitLab while blocking accepting a merge request, adding a commit or forking a repository. A restricted action is never advertised to Claude, ChatGPT or Cursor at all, so no prompt, however it is worded, can reach it.

### What happens to a GitLab connection when someone leaves?

Offboarding a person in Elaichi ends their access to GitLab through every AI client at once. If they had shared a GitLab connection with a team, that connection keeps working for everyone else. Disconnecting GitLab once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client at the same time.

### Does the GitLab MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. GitLab is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for GitLab?

Yes. Both let Claude, ChatGPT or Cursor use GitLab. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every GitLab call.

### How is Elaichi different from Composio for GitLab?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to GitLab: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 47 GitLab tools

Every tool below is callable through https://api.elaichi.ai/mcp once GitLab is connected, subject to the toolbox it is in and the restrictions on the caller.

- **Get mcp server version** (Get). Returns the current version of the GitLab MCP server.
- **Get project** (Get). Returns metadata for a single GitLab project: numeric ID, full path, default branch, visibility, and web URL.
- **Add commit** (Add). Adds a commit with one or more file actions to a branch in a single call.
- **Save merge request** (Merge). Creates or updates a merge request in a GitLab project. The presence of `merge_request_iid` selects the operation: omit it to create a merge request, or provide it to update an existing one.
- **Get merge request** (Get). Retrieves a merge request and, optionally, its diffs, commits, notes, pipelines, discussions, approvals, or conflicts. Only the base merge request is returned unless you request associated data with the `include` parameter.
- **List duo agents and flows** (List). Lists the GitLab Duo agents and flows enabled in a project, so you can discover what is available instead of guessing a flow name. Which agents and flows a project offers is configured per project, and their IDs differ between projects. Each entry includes `can_start_session`,…
- **Start duo session** (Start). Starts an asynchronous GitLab Duo Agent Platform session to accomplish a goal in a project. Returns a `workflow_id` immediately. Use `get_duo_session` with that ID to track progress and retrieve the final result. The session runs in a CI job that can push commits and open…
- **List duo sessions** (List). Lists your GitLab Duo Agent Platform sessions, excluding Duo Chat sessions. Each session includes its individual status, goal preview, flow definition, and creation timestamp. Project sessions also include a session URL. The goal preview might be truncated.
- **Get duo session** (Get). Checks the status of a GitLab Duo Agent Platform session. Running sessions include a suggested polling delay, which is longer while the session waits for its CI job to start. Finished sessions and completed chat turns include the latest agent answer. Any merge request, work…
- **Send duo session input** (Send). Answers a GitLab Duo Agent Platform session that is waiting for input: approves or rejects a pending plan or tool call, or replies to a question the agent asked. Works for sessions started from `ai_catalog_item_consumer_id` and for those started from `agent`. A session accepts…
- **List merge requests** (List). Lists or searches merge requests in a GitLab project or group, returning compact merge request metadata. Group scope always includes merge requests from every project in the group and its subgroups, but excludes merge requests from archived projects. A group result also…
- **Save note** (Action). Adds a comment to a GitLab merge request or work item, or replies to an existing discussion thread, as the authenticated user.
- **Save merge request review** (Merge). Writes merge request review artifacts as the authenticated user. Each call performs exactly one operation, selected with the `method` parameter. Methods: create_note: Adds a top-level comment. reply_discussion: Replies in an existing discussion. create_diff_note: Comments on a…
- **List project members** (List). Lists the members of a GitLab project with their role and access level.
- **Get user** (Get). Gets a single GitLab user. Use this tool to resolve a username, or your own account, to a numeric user ID. For example, use it before you set assignees or reviewers with other tools. Provide exactly one of `username`, `id`, or `me`.
- **Accept merge request** (Accept). Merges a merge request, or schedules it to merge automatically. Without `strategy`, the merge starts immediately and completes asynchronously. With `strategy`, auto-merge is armed and the merge request merges once its checks pass. To approve a merge request instead, use the…
- **Add branch** (Add). Adds a branch to a GitLab project from a source ref.
- **Fork repository** (Action). Forks a GitLab project into a namespace. The fork is created asynchronously. The response contains the new project attributes, including an `import_status` field, such as `scheduled`, that shows fork progress. The call fails due to reasons based on the following statuses: -…
- **List branches** (List). Lists the branches of a GitLab project, optionally filtered by name.
- **Get repository file** (Get). Retrieves the contents of a single file from a repository at a specific ref. Content comes from the repository, not from your local filesystem. The file is returned as committed at `ref`, so uncommitted changes in a local checkout are not included.
- **List repository tree** (List). Lists the files and directories in a GitLab repository at a given path and ref. Returns entry metadata only, never file contents. To read the contents of a file, use `get_repository_file`.
- **Get commit** (Get). Retrieves a single commit's metadata, and optionally its diff or notes.
- **List commits** (List). Lists the commits of a GitLab project, optionally filtered by ref, author, path, or date. Returns compact commit metadata. To get the diff or notes of a single commit, use `get_commit`.
- **List releases** (List). Lists releases in a GitLab project, most recently released first.
- **List tags** (List). Lists tags in a GitLab project, most recently updated first. If `search` matches a tag name exactly, GitLab lists that tag first.
- **Get pipeline** (Get). Retrieves a pipeline, and optionally its jobs, downstream pipelines, bridge (trigger) jobs, or the artifacts its jobs produced.
- **Get job** (Get). Gets a CI/CD job's metadata, and optionally its trace/log or the artifacts it produced.
- **Get artifact file** (Get). Reads a file from inside the artifacts archive of a CI/CD job as text. To discover what a job or pipeline produced, use the `get_job` or `get_pipeline` tool with `include: artifacts`.
- **List pipelines** (List). Lists pipelines in a GitLab project, with optional filters.
- **Save pipeline** (Action). Runs, retries, cancels, or renames a CI/CD pipeline in a GitLab project. To delete a pipeline, use the `manage_pipeline` tool instead. To list pipelines, use the `list_pipelines` tool instead.
- **Manage pipeline** (Action). Updates pipeline metadata or deletes a pipeline in a GitLab project. To create, retry, or cancel a pipeline, use the `save_pipeline` tool instead. To list pipelines, use the `list_pipelines` tool instead.
- **Get work item** (Get). Retrieves a single work item (issue, epic, task, incident, objective, or key result) with its type, dates, assignees, labels, milestone, and parent. Optionally includes its notes or the merge requests related to it. Widgets the work item type does not support are omitted.
- **Link work items** (Action). Links a work item to one or more other work items with a relationship type.
- **Get saved view work items** (Get). Retrieves a saved view and its list of work items from a namespace. The tool applies the filters and the sort order in the saved view to the returned work items.
- **List vulnerabilities** (List). Lists security vulnerabilities in a GitLab project, with optional filters and cursor pagination. Returns paginated vulnerability metadata. To get full details for a single vulnerability, use `get_vulnerability`. Requires the security dashboard feature to be enabled.
- **Get vulnerability** (Get). Returns comprehensive details for a single vulnerability, including title, state, description, severity, and identifiers.
- **Save vulnerability** (Action). Performs write operations on a vulnerability in a GitLab project.
- **Save work item** (Action). Creates or updates a GitLab work item, such as an issue, task, or epic. Omit `work_item_iid` to create a new work item. Provide `work_item_iid` or a work item URL to update an existing one. Send only the fields you intend to set, and omit the rest. The tool names…
- **List work items** (List). Lists or searches work items (issues, incidents, test cases, requirements, tasks, tickets, objectives, key results, epics) in a group or project. Group scope includes work items of descendant projects and subgroups. Each result contains only the ID, IID, title, state, web URL,…
- **Get work item types** (Get). Lists the work item types available in a namespace (group or project), including system-defined types (such as Issue, Epic, and Task) and custom types. Each returned type includes its global ID, name, icon, and the widget types enabled on it, so you can avoid setting fields…
- **List projects** (List). Without `group_id`, lists projects where you have at least the Guest role by default; pass `min_access_level` to raise the threshold. With `group_id`, lists every project in that group and its subgroups regardless of access level; adding `min_access_level` or `visibility`…
- **List groups** (List). Lists groups, for navigating the group hierarchy and discovering group IDs and full paths to use with other tools. Without `group_id`, this tool lists top-level groups where you are a member. With `group_id`, it lists the direct subgroups of that group, regardless of…
- **Search** (Search). Searches for a term across the entire GitLab instance with the search API. This tool is available for global, group, and project search. Available scopes depend on the search type.
- **Search labels** (Search). Searches for labels in a GitLab project or group.
- **List wiki pages** (List). Lists the wiki pages in a GitLab project or group.
- **Semantic search** (Search). Searches relevant content in a GitLab project by meaning rather than by keyword. Use this tool when you do not know the exact symbol or file name, or to discover how a behavior is implemented across a codebase. For more information, including setup and enablement, see semantic…
- **Attach scan profile** (Action). Attaches the given security scan profile to the specified projects, or to all projects under the specified groups.
