Skip to content

Tools by domain

One page per catalog group, each listing every action of the group with its canonical ID, the tools that reach it on each surface, the tier that serves it, its annotations and its parameters. The pages are generated from the catalog the server builds, so what they say about an action is what the server serves; only the overview and the sample questions of a page are written by hand.

On GitLab.com at Ultimate the catalog holds 1098 actions; a self-managed Ultimate instance serves 1092, a Premium one 1026 and a Free one 872.

  • Access tokens and credentials: Project, group and personal access tokens, deploy tokens, deploy keys, access requests and invitations.
  • Custom member roles: Custom member roles at instance and group level: list, create and delete them.
  • Enterprise users: The enterprise users of a top-level group: list and read them, disable their two-factor authentication and delete them.
  • Group SCIM identities: The SCIM identities a group’s identity provider provisions: list, read, update and delete them.
  • Groups: GitLab groups: their lifecycle, subgroups, members, sharing, labels, milestones, boards, badges, webhooks, epics, wikis, service accounts and more.
  • Project aliases: Project aliases, the short names an administrator gives projects to clone them by: list, read, create and delete them.
  • Project discovery: Resolve a git remote URL to the GitLab project behind it and its project ID.
  • Projects: GitLab projects: their lifecycle, members, sharing, webhooks, labels, milestones, boards, badges, mirrors, Pages, integrations, uploads, import and export, service accounts and more.
  • Users: GitLab users: accounts and their state, SSH and GPG keys, emails, personal access and impersonation tokens, status, to-do items, events, notification settings, namespaces and avatars.
  • Branches: Git branches in a GitLab project: create, list, read and delete them, protect them, and read the branch rules GitLab aggregates.
  • Project wikis: The pages of a project’s wiki and the files attached to it.
  • Repository files and commits: Repository content: the file tree, files, blame and history, commits, diffs, cherry-picks and reverts, comparisons, archives, changelogs, submodules and Markdown rendering.
  • Search: Search GitLab across the instance, a group or a project for code, merge requests, issues, commits, milestones, notes, projects, snippets, users and wiki pages.
  • Snippets: Personal and project snippets, their content, discussions, notes and award emoji.
  • Tags: Git tags in a GitLab project: create, list, read and delete them, read their signatures, and protect them.
  • External status checks: External status checks of a project and the status each one reports on a merge request.
  • Merge request review: Reviewing a merge request: its changes and diff versions, notes, threaded and inline discussions, and draft notes published as one review.
  • Merge requests: The merge request lifecycle: create, list, update, merge, rebase and delete, approvals and approval rules, dependencies, context commits, time tracking, award emoji and resource events.
  • Merge trains: Merge trains, GitLab’s queue of merge requests merged in order: list them and add a merge request to one.
  • Achievements: The achievements a namespace defines and the awards made from them, through GitLab’s GraphQL API.
  • Custom emoji: The custom emoji a group defines for its projects: list, add and delete them through GitLab’s GraphQL API.
  • Issues and work items: GitLab issues and work items: their lifecycle, notes, discussions, links, time tracking, award emoji, resource events, statistics and saved views.
  • CI/CD Catalog: Search and inspect the reusable components published to the GitLab CI/CD Catalog.
  • CI/CD variables: CI/CD variables at project, group and instance level: list, read, create, update and delete them.
  • Environments and deployments: Environments, protected environments, deploy freeze periods and deployments of a GitLab project.
  • Feature flags: A project’s feature flags and the user lists their strategies target.
  • Jobs: CI/CD jobs: list and read them, read their logs and artifacts, play, retry, cancel and erase them, and manage the CI/CD job token scope.
  • Model registry: Download the files of a model version from a project’s GitLab model registry.
  • Packages and container registry: The package registry and the container registry: publish and download generic packages, browse and delete packages, images and tags, and manage protection rules.
  • Pipelines: CI/CD pipelines: run, read, retry, cancel and delete them, read their variables and test reports, and manage schedules, trigger tokens and resource groups.
  • Releases: Releases of a GitLab project and the asset links attached to them.
  • Runners: CI/CD runners at instance, group and project level, their registration and authentication tokens, their jobs and managers, and runner controllers.
  • Templates and CI lint: GitLab’s built-in templates for CI/CD YAML, Dockerfiles, .gitignore files, licenses and projects, and the CI lint.
  • Audit events: List and read GitLab audit events at instance, group and project level.
  • Build attestations: List and download the build attestations (SLSA provenance) GitLab holds for a project’s artifacts.
  • Compliance policy settings: Read and update the instance’s compliance policy settings, the namespace that centrally manages security policies.
  • Dependencies and SBOM: List a project’s dependencies and create and download CycloneDX SBOM exports of a pipeline.
  • Security attributes: Security attributes that classify GitLab groups and projects under a security category, through GitLab’s GraphQL API.
  • Security categories: Security categories, which group the security attributes of a namespace, through GitLab’s GraphQL API.
  • Security findings: The security findings one pipeline’s scanners reported, through GitLab’s GraphQL API.
  • Security scan profiles: Attach and detach security scan profiles on projects and groups, and read which profiles a project runs, through GitLab’s GraphQL API.
  • Vulnerabilities: List, read and triage a project’s vulnerabilities, count them by severity and summarize a pipeline’s security reports, through GitLab’s GraphQL API.
  • DORA metrics: The four DORA metrics of a project or a group: deployment frequency, lead time for changes, time to restore service and change failure rate.
  • Orbit knowledge graph: Read-only queries against Orbit, GitLab.com’s experimental knowledge graph.
  • Administration: Instance administration in GitLab MCP Server: settings, license, system hooks, Sidekiq, imports, OAuth applications, Terraform states, cluster agents and more.
  • Geo sites: GitLab Geo replication sites: create, read, edit, delete and repair them, and read their replication status.
  • Repository storage moves: Move the repositories of projects, groups and snippets between storage shards, and follow the moves.
  • Guided creation flows: Guided flows that create an issue, a merge request, a project or a release by asking the user step by step.
  • Server diagnostics: Diagnostics of GitLab MCP Server itself: whether GitLab answers, the server and GitLab versions, and who the token belongs to.