CLI & MCP for GitHits - The Code Context Layer for AI Coding Agents
- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Healthy fork ratio
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add githits-cli -- npx -y githits{
"mcpServers": {
"githits-cli": {
"command": "npx",
"args": ["-y", "githits"]
}
}
}MCP Servers overview
<p align="center"> <img src="./github-githits.png" alt="GitHits" width="100%" /> </p> <h1 align="center">GitHits CLI</h1> <p align="center"> The code context layer for AI coding agents. </p> <p align="center"> <a href="https://www.npmjs.com/package/githits"><img alt="npm version" src="https://img.shields.io/npm/v/githits.svg"></a> <a href="https://www.npmjs.com/package/githits"><img alt="npm downloads" src="https://img.shields.io/npm/dm/githits.svg"></a> <a href="https://github.com/githits-com/githits-cli/actions/workflows/main.yml"><img alt="Main" src="https://github.com/githits-com/githits-cli/actions/workflows/main.yml/badge.svg"></a> <a href="https://github.com/githits-com/githits-cli/blob/main/LICENSE"><img alt="License: Apache-2.0" src="https://img.shields.io/badge/license-Apache--2.0-blue.svg"></a> <a href="https://www.npmjs.com/package/githits"><img alt="Node" src="https://img.shields.io/node/v/githits.svg"></a> <a href="https://modelcontextprotocol.io/"><img alt="MCP" src="https://img.shields.io/badge/MCP-enabled-5C4EE5"></a> <a href="https://skills.sh/githits-com/githits-cli"><img alt="skills.sh" src="https://skills.sh/b/githits-com/githits-cli"></a> <a href="https://glama.ai/mcp/servers/githits-com/githits-cli"><img alt="githits-cli MCP server" src="https://glama.ai/mcp/servers/githits-com/githits-cli/badges/score.svg"></a> <a href="https://lobehub.com/mcp/githits-com-githits-cli"><img alt="MCP Badge" src="https://lobehub.com/badge/mcp/githits-com-githits-cli?style=plastic"></a> </p> <p align="center"> <a href="https://githits.com">Website</a> · <a href="https://docs.githits.com">Documentation</a> · <a href="https://github.com/githits-com/githits-cli/issues">Issues</a> </p> GitHits connects AI coding agents to public open-source evidence across the full software development lifecycle: discovery, planning, research, implementation, debugging, and maintenance. The CLI runs a local [MCP](https://modelcontextprotocol.io/) server that your coding tool starts on demand. Agents can then search indexed package and repository source, read exact files and documentation pages, inspect package health, compare dependency upgrades, and find source-cited examples from real open-source projects when model knowledge and local repository context are not enough. Want to use GitHits as part of your agent harness or software factory? Check out our [public API documentation](https://docs.githits.com/api/overview). ## Quick Start ```sh npx githits@latest init ``` `init` signs you in, detects supported coding tools, and configures GitHits for the tools you select. It uses the local stdio MCP except for Cursor, whose direct setup uses the hosted remote MCP. Automatic setup currently supports Claude Code, Cursor, Windsurf, VS Code / Copilot, Cline, Claude Desktop, Codex CLI, Pi, Gemini CLI, Google Antigravity, OpenCode, Hermes Agent, Zed, Junie, Qwen Code, Kiro, Kilo Code, Factory Droid, and Amazon Q CLI. After setup, open your coding agent and work normally. Many agents call GitHits when they need source-backed context. If your agent starts guessing, prompt it directly: ```text Use GitHits Code Navigation to inspect npm:express. Find how middleware errors are handled, read the relevant source, and explain the fix before editing code. ``` ## What GitHits Adds GitHits is designed for the point where an agent needs evidence from the broader open-source ecosystem, not just model memory or local repo context: | Capability | MCP tools | CLI commands | |---|---|---| | Tool orientation | `quick_start` | — | | Code examples | `get_example`, `search_language` | `githits example`, `githits languages` | | Code navigation | `search`, `search_status`, `code_files`, `code_read`, `code_grep` | `githits search`, `githits search-status`, `githits code ...` | | Documentation access | `docs_list`, `docs_read` | `githits docs ...` | | Package inspection | `pkg_info`, `pkg_vulns`, `pkg_deps`, `pkg_changelog`, `pkg_upgrade_review` | `githits pkg ...` | Use GitHits when your agent needs to: - discover, plan, or research how OSS projects solve a vague issue or unfamiliar error - find broad prior art or rare needle-in-the-haystack examples across repositories - inspect source, tests, symbols, or docs for a known package or repository - verify how a dependency actually behaves before changing code - debug stack traces that point into third-party code - review package health, licenses, vulnerabilities, dependencies, and changelogs - compare dependency upgrades using factual evidence ## Examples Find prior art across open source: ```sh npx githits@latest example "HTTP retries with exponential backoff in Python" ``` Search indexed code, docs, and symbols for a dependency: ```sh npx githits@latest search "router middleware" --in npm:express npx githits@latest search '"body parser" OR multer' --in npm:express --source docs npx githits@latest search "debounce" --in npm:lodash --source symbol ``` Read and grep dependency source without cloning: ```sh npx githits@latest code files npm:express lib npx githits@latest code read npm:express lib/router/index.js --lines 120-200 npx githits@latest code grep npm:express "router.use" lib --regex ``` Inspect package health and upgrade evidence: ```sh npx githits@latest pkg info npm:express npx githits@latest pkg vulns npm:lodash@4.17.20 --severity high npx githits@latest pkg deps npm:express@4.18.2 --depth 2 npx githits@latest pkg changelog npm:express --from 4.18.2 --to 5.2.1 npx githits@latest pkg upgrade-review npm:zod@4.3.6 --to 4.4.3 ``` Browse and read package documentation: ```sh npx githits@latest docs list npm:express npx githits@latest docs read <docs-read-target> --lines 20-80 ``` ## Experimental Tools GitHits 0.10 adds two opt-in local tools for early dogfooding: - `resolve_target` / `githits resolve` turns a fuzzy or ambiguous package, repository, or documentation-site name into grouped canonical targets with related project identities kept together. - `code_diff` / `githits code diff` compares repository trees resolved from exact package versions or public GitHub refs. They are hidden and disabled by default. They are available only through the local `githits` CLI and local stdio MCP server; the hosted MCP and plugin or extension installs keep the stable tool set. Enable them in the GitHits host config, then restart the coding agent so it restarts the local MCP server: ```toml # macOS/Linux: ~/.config/githits/config.toml # Windows: %APPDATA%\githits\config.toml [experimental] tools = true ``` See [Experimental tools](docs/experimental-tools.md) for platform-specific config discovery, CLI examples, limitations, and how to disable the tools. ## Supported Sources GitHits works with package and repository targets such as: - package specs: `npm:react`, `npm:react@18.2.0`, `pypi:requests`, `crates:serde` - GitHub repos: `https://github.com/expressjs/express`, `github:expressjs/express#main` Package inspection supports npm, PyPI, Hex, Crates, NuGet, Maven, Packagist, RubyGems, Go, Swift, vcpkg, and Zig. Advisory data is unavailable for vcpkg and Zig; dependency graph support varies by registry. ## License Filtering Code example search supports license filtering: - `strict` is the default and filters repositories with copyleft or undeclared licenses - `custom` uses your account blocklist configured at [githits.com](https://githits.com) - `yolo` disables license filtering ```sh npx githits@latest example "async file reading" --lang python --license strict ``` ## Authentication Normal local setup is handled by: ```sh npx githits@latest init ``` For manual login: ```sh npx githits@latest login ``` Browser OAuth is recommended for local development. Credentials are stored in the system keychain by default and refreshed automatically. Useful flags: - `init --no-browser` or `login --no-browser` prints the login URL instead of launching a browser - `init --port <port>` or `login --port <port>` fixes the loopback callback port - `login --force` re-authenticates even if you are already logged in The OAuth callback always listens on the machine where GitHits is running. When GitHits runs over SSH and the browser runs locally, forward the selected port from the browser machine: ```sh ssh -N -L 8765:127.0.0.1:8765 user@remote-host ``` With that tunnel open, run GitHits on the remote machine using the same port: ```sh npx githits@latest init --no-browser --port 8765 ``` Open the URL printed by GitHits in the local browser. Replace `user@remote-host` with the SSH destination you normally use. The same flags work with `githits login` after setup. Browser OAuth is interactive. For CI and other unattended environments, supply `GITHITS_API_TOKEN` through the environment's secret manager. ### Keychain Prompts and File Storage GitHits uses the system keychain by default because OAuth credentials include a refresh token. On macOS this means Keychain Access; on Windows it means Credential Manager; on Linux it means the available Secret Service or keyring backend. If macOS shows a prompt such as "githits wants to access ... in your keychain", choose **Always Allow** when you trust the installed `githits` CLI. GitHits cannot customize that operating-system prompt; it is generated by macOS. GitHits also writes a small non-secret metadata file so recent startup checks do not need to read the keychain. The keychain is only read when GitHits needs the token, for example during a tool call, token refresh, `githits auth status`, or a login check after metadata is stale or expired. If your agent keeps showing keychain prompts even after **Always Allow**, switch OAuth storage to file mode: ```toml # macOS/Linux: ~/.config/githits/config.toml, or $XDG_CONFIG_HOME/githits/config.toml # Windows: %APPDATA%\githits\config.toml [auth] storage = "file" ``` The config directory may be empty until you create `config.toml` or GitHits writes auth metadata. O
What people ask about githits-cli
What is githits-com/githits-cli?
+
githits-com/githits-cli is mcp servers for the Claude AI ecosystem. CLI & MCP for GitHits - The Code Context Layer for AI Coding Agents It has 102 GitHub stars and its last recorded update is dated 2026-09-10.
How do I install githits-cli?
+
You can install githits-cli by cloning the repository (https://github.com/githits-com/githits-cli) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is githits-com/githits-cli safe to use?
+
Our security agent has analyzed githits-com/githits-cli and assigned a Trust Score of 100/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.
Who maintains githits-com/githits-cli?
+
githits-com/githits-cli is maintained by githits-com. The last recorded GitHub activity is dated 2026-09-10, with 13 open issues.
Are there alternatives to githits-cli?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy githits-cli to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/githits-com-githits-cli)<a href="https://claudewave.com/repo/githits-com-githits-cli"><img src="https://claudewave.com/api/badge/githits-com-githits-cli" alt="Featured on ClaudeWave: githits-com/githits-cli" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
The fastest path to AI-powered full stack observability, even for lean teams.
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!