# github_login

Authenticate via GitHub OAuth device flow. First call returns a code + URL to open; run it again after authorizing to finish. (Or set GITHUB_TOKEN to skip.)

Agent View of the PolicyLayer registry record for `github_login`. HTML page: https://policylayer.com/tools/io-github-abhishekkumar2021-github/github-login

## Facts

- Tool: `github_login`
- Server: GitHub (`@abhishekmcp/github`) — https://policylayer.com/tools/io-github-abhishekkumar2021-github.md
- Install: `npx -y @abhishekmcp/github`
- Homepage: https://github.com/Abhishekkumar2021/mcp-suite
- Risk category: Other (Low risk)
- Registry record: grade D, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "github_login",
    "arguments": {}
  }
}
```

## Why github_login is rated Low

This tool performs authentication/authorization setup, not data retrieval, modification, execution, destruction, or financial operations. It initiates an OAuth device flow and completes token acquisition. While it grants access to GitHub resources, the tool itself does not read, write, execute, or destroy anything — it is purely a credential/session establishment mechanism.

From the tool's own definition: "Authenticate via GitHub OAuth device flow. First call returns a code + URL to open; run it again after authorizing to finish."

## Use case

AI agents call github_login as a supporting operation in GitHub workflows.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches GitHub:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "github_login": {
      "limits": [
        {
          "counter": "github_login_rate",
          "window": "minute",
          "max": 60,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on GitHub (15)

- `github_logout` — Destructive — https://policylayer.com/tools/io-github-abhishekkumar2021-github/github-logout.md
- `get_file_contents` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/get-file-contents.md
- `get_issue` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/get-issue.md
- `get_pull_request` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/get-pull-request.md
- `get_repo` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/get-repo.md
- `list_issues` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/list-issues.md
- `list_notifications` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/list-notifications.md
- `list_pull_requests` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/list-pull-requests.md
- `rate_limit` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/rate-limit.md
- `search_code` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/search-code.md
- `search_issues` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/search-issues.md
- `search_repos` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/search-repos.md
- `whoami` — Read — https://policylayer.com/tools/io-github-abhishekkumar2021-github/whoami.md
- `add_issue_comment` — Write — https://policylayer.com/tools/io-github-abhishekkumar2021-github/add-issue-comment.md
- `create_issue` — Write — https://policylayer.com/tools/io-github-abhishekkumar2021-github/create-issue.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-abhishekkumar2021-github · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-abhishekkumar2021-github
