git or gh credentials. Each session uses a short-lived GitHub App installation token for its MCP requests.
Connecting GitHub and changing an agent’s access need the organization developer or admin role. See Organizations and roles. You also need a GitHub account that can install the GitHub App on the target organization or user account. Some organizations require an owner to approve new apps.
Connect GitHub
- In Integrations, click Add integration, then choose GitHub. Authorize the GitHub user so Recursion can find the App installations that user can access.
- Choose an existing installation, or choose Install on another account and select the account and repositories in GitHub. If none are available, Recursion starts installation automatically. For an existing installation, use Manage repositories on GitHub to change its repository access in a separate tab. Return to Recursion and click Continue to connect with the updated access. Choosing an already installed account on GitHub’s App installation page opens its settings without returning to Recursion.
- Back in Integrations, select the tools available to the organization and save. The picker describes each tool and groups the current GitHub tools as Read-only or Changes data. Merging a pull request changes data; the Destructive category is reserved for tools that delete data, and none of the current GitHub tools do so. Use the group checkboxes or Select read-only, Select all, and Clear to choose several at once. You can change this selection later with Edit tools on the connection.
Assign GitHub to an agent
- In the agent’s Integrations section, click Add integration access and select the GitHub connection.
- In Tools, review each tool’s description and read-only or write classification. Use Select read-only, Select all, Clear, or the group checkboxes to choose a subset of the connection’s tools.
- In Repositories, choose specific repositories or All authorized repositories.
- Click Use this access, then save the agent version.
nativeIntegrations[].tools to the selected tool names. The permission field remains in the version contract for compatibility; the server derives its read or write value from the tools. You can discover supported tools through listIntegrationProviders and the connection’s enabled tools through listIntegrationConnections.
A new agent version or connection selection applies to new sessions. Running sessions may keep credentials and tool lists they already received until they refresh or end.
Name repositories as owner/name, up to 500, where owner is the connection’s own account. A repository of another owner is refused; grant it through the connection for that owner. A new agent version replaces the whole definition, so include every field you want to keep.
Verify access
Open the connection’s actions menu and click Test connection. Then start a new agent session and ask it to use one of the selected GitHub tools. A passing connection test proves GitHub issued a token; a successful tool call also proves that the tool, repository, and permission were available. GitHub MCP calls run outside the sandbox, so GitHub host allowlists for sandboxgit and gh are unnecessary for these calls.