Skip to content

Access tokens and credentials

The credentials that give someone or something access to a project or a group: project, group and personal access tokens (list, read, rotate and revoke, and create for projects and groups), deploy tokens, deploy keys, the access requests users file to join, and the invitations sent to them. Rotating a token issues a new value and revokes the old one in one call: the token keeps its name, scopes and role, but whatever holds the old value, a CI/CD variable for instance, has to be updated with the token the call returns. Revoking or deleting a credential is destructive.

Creating a personal access token is a user action rather than one of these (see Users), and so are SSH keys and impersonation tokens. Project and group members are managed on the Projects and Groups pages, and the CI/CD job token scope on Jobs.

  • “List the access tokens of project 42”
  • “Rotate the deploy-bot project token before it expires”
  • “Create a read-only deploy token for my-group/my-app”
  • “Approve the pending access requests on group platform”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as access.approve_group, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_access with action set to the action’s name, such as approve_group, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_access_request_approve_group, with its parameters as the arguments.

Every tier serves the whole group, on self-managed instances and on GitLab.com alike.

Read-only actions: 19 of 48, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions). A parameter followed by a tier in parentheses is served only from that tier on.

ActionIndividual
access.approve_groupgitlab_access_request_approve_group
access.approve_projectgitlab_access_request_approve_project
access.deny_groupgitlab_access_request_deny_group
access.deny_projectgitlab_access_request_deny_project
access.deploy_key_addgitlab_deploy_key_add
access.deploy_key_add_instancegitlab_deploy_key_add_instance
access.deploy_key_deletegitlab_deploy_key_delete
access.deploy_key_enablegitlab_deploy_key_enable
access.deploy_key_getgitlab_deploy_key_get
access.deploy_key_list_allgitlab_deploy_key_list_all
access.deploy_key_list_projectgitlab_deploy_key_list_project
access.deploy_key_list_user_projectgitlab_deploy_key_list_user_project
access.deploy_key_updategitlab_deploy_key_update
access.deploy_token_create_groupgitlab_deploy_token_create_group
access.deploy_token_create_projectgitlab_deploy_token_create_project
access.deploy_token_delete_groupgitlab_deploy_token_delete_group
access.deploy_token_delete_projectgitlab_deploy_token_delete_project
access.deploy_token_get_groupgitlab_deploy_token_get_group
access.deploy_token_get_projectgitlab_deploy_token_get_project
access.deploy_token_list_allgitlab_deploy_token_list_all
access.deploy_token_list_groupgitlab_deploy_token_list_group
access.deploy_token_list_projectgitlab_deploy_token_list_project
access.invite_groupgitlab_group_invite
access.invite_list_groupgitlab_group_invite_list_pending
access.invite_list_projectgitlab_project_invite_list_pending
access.invite_projectgitlab_project_invite
access.request_groupgitlab_access_request_request_group
access.request_list_groupgitlab_access_request_list_group
access.request_list_projectgitlab_access_request_list_project
access.request_projectgitlab_access_request_request_project
access.token_group_creategitlab_group_access_token_create
access.token_group_getgitlab_group_access_token_get
access.token_group_listgitlab_group_access_token_list
access.token_group_revokegitlab_group_access_token_revoke
access.token_group_rotategitlab_group_access_token_rotate
access.token_group_rotate_selfgitlab_group_access_token_rotate_self
access.token_personal_getgitlab_personal_access_token_get
access.token_personal_listgitlab_personal_access_token_list
access.token_personal_revokegitlab_personal_access_token_revoke
access.token_personal_revoke_selfgitlab_personal_access_token_revoke_self
access.token_personal_rotategitlab_personal_access_token_rotate
access.token_personal_rotate_selfgitlab_personal_access_token_rotate_self
access.token_project_creategitlab_project_access_token_create
access.token_project_getgitlab_project_access_token_get
access.token_project_listgitlab_project_access_token_list
access.token_project_revokegitlab_project_access_token_revoke
access.token_project_rotategitlab_project_access_token_rotate
access.token_project_rotate_selfgitlab_project_access_token_rotate_self

Approve a pending group access request, granting the user membership. Returns: the membership it became, with id, username, name, the granted access level, the state, and the membership fields GitLab sends with it. See also: access.request_list_group, access.deny_group, group.members.

  • Meta-tool: gitlab_access, action approve_group
  • Individual tool: gitlab_access_request_approve_group
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or path
user_idintegeryesUser ID of the access requester
access_levelintegernoAccess level to grant (0=No access, 5=Minimal access, 10=Guest, 15=Planner (Premium), 20=Reporter, 25=Security Manager (Premium), 30=Developer, 40=Maintainer, 50=Owner). Default 30

Approve a pending project access request, granting the user membership. Returns: the membership it became, with id, username, name, the granted access level, the state, and the membership fields GitLab sends with it. See also: access.request_list_project, access.deny_project, project.members.

  • Meta-tool: gitlab_access, action approve_project
  • Individual tool: gitlab_access_request_approve_project
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
user_idintegeryesUser ID of the access requester
access_levelintegernoAccess level to grant (0=No access, 5=Minimal access, 10=Guest, 15=Planner (Premium), 20=Reporter, 25=Security Manager (Premium), 30=Developer, 40=Maintainer, 50=Owner). Default 30

Deny a pending group access request, removing it without granting membership. Returns: a success status and confirmation message. See also: access.request_list_group, access.approve_group, group.members.

  • Meta-tool: gitlab_access, action deny_group
  • Individual tool: gitlab_access_request_deny_group
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or path
user_idintegeryesUser ID of the access requester

Deny a pending project access request, removing it without granting membership. Returns: a success status and confirmation message. See also: access.request_list_project, access.approve_project, project.members.

  • Meta-tool: gitlab_access, action deny_project
  • Individual tool: gitlab_access_request_deny_project
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
user_idintegeryesUser ID of the access requester

Add a new SSH deploy key to a project. Returns: the created deploy key with id, title, fingerprint, can_push, and expiry. See also: access.deploy_key_get, access.deploy_key_list_project, access.deploy_key_enable.

  • Meta-tool: gitlab_access, action deploy_key_add
  • Individual tool: gitlab_deploy_key_add
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
keystringyesPublic SSH key content
project_idstring/integeryesProject ID or path
titlestringyesDeploy key title
can_pushbooleannoWhether the key can push to the project
expires_atstringnoExpiry date (YYYY-MM-DD)

Create an instance-level deploy key (admin only). Returns: the created instance deploy key with id, title, fingerprint, expiry, and project access arrays. See also: access.deploy_key_list_all, access.deploy_key_enable.

  • Meta-tool: gitlab_access, action deploy_key_add_instance
  • Individual tool: gitlab_deploy_key_add_instance
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
keystringyesPublic SSH key content
titlestringyesDeploy key title
expires_atstringnoExpiry date (YYYY-MM-DD)

Delete a deploy key from a project (removes it from all projects where it is enabled). Returns: a success confirmation. See also: access.deploy_key_get, access.deploy_key_list_project.

  • Meta-tool: gitlab_access, action deploy_key_delete
  • Individual tool: gitlab_deploy_key_delete
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
deploy_key_idintegeryesDeploy key ID returned by deploy key operations. Do not use deploy_token_id
project_idstring/integeryesProject ID or path

Enable an existing deploy key for a project. Returns: the enabled deploy key with id, title, fingerprint, and can_push. See also: access.deploy_key_list_all, access.deploy_key_list_project, access.deploy_key_get.

  • Meta-tool: gitlab_access, action deploy_key_enable
  • Individual tool: gitlab_deploy_key_enable
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
deploy_key_idintegeryesDeploy key ID to enable. Do not use deploy_token_id
project_idstring/integeryesProject ID or path

Get a single project deploy key by id. Returns: the deploy key with title, key, fingerprint, fingerprint_sha256, can_push, created_at, and expires_at. See also: access.deploy_key_list_project, access.deploy_key_update, access.deploy_key_delete.

  • Meta-tool: gitlab_access, action deploy_key_get
  • Individual tool: gitlab_deploy_key_get
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
deploy_key_idintegeryesDeploy key ID returned by deploy key operations. Do not use deploy_token_id
project_idstring/integeryesProject ID or path

List ALL instance-level SSH deploy keys in one call (admin only). Use this instead of access.deploy_key_list_project when you need every key on the instance. Returns: instance deploy keys with id, title, fingerprint, expiry, projects_with_write_access, projects_with_readonly_access, and pagination metadata. See also: access.deploy_key_add_instance, access.deploy_key_enable, access.deploy_key_list_project.

  • Meta-tool: gitlab_access, action deploy_key_list_all
  • Individual tool: gitlab_deploy_key_list_all
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
order_bystringnoColumn to order results by (e.g. id, title, created_at)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
publicbooleannoFilter by public keys
sortstring (asc, desc)noSort direction (asc, desc)

List a project’s SSH deploy keys with ordering and pagination. Returns: deploy keys with id, title, fingerprint, can_push, expiry, and pagination metadata. See also: access.deploy_key_get, access.deploy_key_add, access.deploy_key_enable.

  • Meta-tool: gitlab_access, action deploy_key_list_project
  • Individual tool: gitlab_deploy_key_list_project
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
order_bystringnoColumn to order results by (e.g. id, title, created_at)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction (asc, desc)

List the deploy keys across a user’s projects (admin only) with ordering and pagination. Returns: deploy keys with id, title, fingerprint, can_push, expiry, and pagination metadata. See also: access.deploy_key_list_project, access.deploy_key_get, user.get.

  • Meta-tool: gitlab_access, action deploy_key_list_user_project
  • Individual tool: gitlab_deploy_key_list_user_project
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
user_idstring/integeryesUser ID or username
order_bystringnoColumn to order results by (e.g. id, title, created_at)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction (asc, desc)

Update a project deploy key’s title or push permission. Returns: the updated deploy key. See also: access.deploy_key_get, access.deploy_key_list_project, access.deploy_key_delete.

  • Meta-tool: gitlab_access, action deploy_key_update
  • Individual tool: gitlab_deploy_key_update
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
deploy_key_idintegeryesDeploy key ID returned by deploy key operations. Do not use deploy_token_id
project_idstring/integeryesProject ID or path
can_pushbooleannoWhether the key can push to the project
titlestringnoNew deploy key title

Create a deploy token for a group. Returns: the created deploy token including its one-time secret token value, plus id, name, username, scopes, and expiry. See also: access.deploy_token_list_group, access.deploy_token_get_group, access.deploy_token_delete_group.

  • Meta-tool: gitlab_access, action deploy_token_create_group
  • Individual tool: gitlab_deploy_token_create_group
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
namestringyesDeploy token name
expires_atstringnoExpiry date (YYYY-MM-DD)
scopesstring[]noArray of scopes (read_repository, read_registry, write_registry, read_package_registry, write_package_registry)
usernamestringnoUsername for the deploy token

Create a deploy token for a project. Returns: the created deploy token including its one-time secret token value, plus id, name, username, scopes, and expiry. See also: access.deploy_token_list_project, access.deploy_token_get_project, access.deploy_token_delete_project.

  • Meta-tool: gitlab_access, action deploy_token_create_project
  • Individual tool: gitlab_deploy_token_create_project
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
namestringyesDeploy token name
project_idstring/integeryesProject ID or URL-encoded path
expires_atstringnoExpiry date (YYYY-MM-DD)
scopesstring[]noArray of scopes (read_repository, read_registry, write_registry, read_package_registry, write_package_registry)
usernamestringnoUsername for the deploy token

Permanently delete a group deploy token by ID. Returns: a success confirmation. Deletion is irreversible. See also: access.deploy_token_list_group, access.deploy_token_get_group, access.deploy_token_create_group.

  • Meta-tool: gitlab_access, action deploy_token_delete_group
  • Individual tool: gitlab_deploy_token_delete_group
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
deploy_token_idintegeryesDeploy token ID
group_idstring/integeryesGroup ID or URL-encoded path

Permanently delete a project deploy token by ID. Returns: a success confirmation. Deletion is irreversible. See also: access.deploy_token_list_project, access.deploy_token_get_project, access.deploy_token_create_project.

  • Meta-tool: gitlab_access, action deploy_token_delete_project
  • Individual tool: gitlab_deploy_token_delete_project
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
deploy_token_idintegeryesDeploy token ID
project_idstring/integeryesProject ID or URL-encoded path

Get a single group deploy token by ID. Returns: the deploy token with id, name, username, scopes, revoked/expired state, and expiry. See also: access.deploy_token_list_group, access.deploy_token_create_group, access.deploy_token_delete_group.

  • Meta-tool: gitlab_access, action deploy_token_get_group
  • Individual tool: gitlab_deploy_token_get_group
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
deploy_token_idintegeryesDeploy token ID
group_idstring/integeryesGroup ID or URL-encoded path

Get a single project deploy token by ID. Returns: the deploy token with id, name, username, scopes, revoked/expired state, and expiry. See also: access.deploy_token_list_project, access.deploy_token_create_project, access.deploy_token_delete_project.

  • Meta-tool: gitlab_access, action deploy_token_get_project
  • Individual tool: gitlab_deploy_token_get_project
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
deploy_token_idintegeryesDeploy token ID
project_idstring/integeryesProject ID or URL-encoded path

List ALL deploy tokens across the GitLab instance in one call (admin only). Use this instead of access.deploy_token_list_project or access.deploy_token_list_group when you need every instance-wide token. Returns: deploy tokens with id, name, username, scopes, revoked/expired state, and pagination metadata. See also: access.deploy_token_list_project, access.deploy_token_list_group, access.deploy_token_create_project.

  • Meta-tool: gitlab_access, action deploy_token_list_all
  • Individual tool: gitlab_deploy_token_list_all
  • Tier: Free
  • Behavior: read-only, idempotent

No parameters.

List deploy tokens owned by a group. Returns: deploy tokens with id, name, username, scopes, revoked/expired state, expiry, and pagination metadata. See also: access.deploy_token_get_group, access.deploy_token_create_group, access.deploy_token_delete_group.

  • Meta-tool: gitlab_access, action deploy_token_list_group
  • Individual tool: gitlab_deploy_token_list_group
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
order_bystringnoFor keyset pagination, the column to order results by
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort order for keyset pagination: ‘asc’ or ‘desc’

List deploy tokens owned by a project. Returns: deploy tokens with id, name, username, scopes, revoked/expired state, expiry, and pagination metadata. See also: access.deploy_token_get_project, access.deploy_token_create_project, access.deploy_token_delete_project.

  • Meta-tool: gitlab_access, action deploy_token_list_project
  • Individual tool: gitlab_deploy_token_list_project
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
order_bystringnoFor keyset pagination, the column to order results by
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort order for keyset pagination: ‘asc’ or ‘desc’

Invite a user to a group by email or user ID with an access level. Returns: an invitation result with status, per-email messages, and any users queued for administrator approval. See also: access.invite_list_group, group.group_member_add, access.request_group.

  • Meta-tool: gitlab_access, action invite_group
  • Individual tool: gitlab_group_invite
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
access_levelintegeryesAccess level (0=No access, 5=Minimal access, 10=Guest, 15=Planner (Premium/Ultimate), 20=Reporter, 25=Security Manager (Premium/Ultimate), 30=Developer, 40=Maintainer, 50=Owner)
group_idstring/integeryesGroup ID or URL-encoded path
emailstringnoEmail address to invite (either email or user_id required)
expires_atstringnoExpiration date for the invitation (YYYY-MM-DD)
idstring/integernoGroup ID or URL-encoded path sent in the request body (mirrors the GitLab id parameter. Usually equal to group_id)
invite_sourcestringnoSource of the invitation that starts the member creation process
member_role_id (Ultimate)integernoCustom role to assign the new member (Ultimate only)
user_idintegernoUser ID to invite (either email or user_id required)

List a group’s pending invitations. Returns: pending invitations with invite email, access level, creator, creation and expiry dates, plus pagination metadata. See also: access.invite_group, group.members.

  • Meta-tool: gitlab_access, action invite_list_group
  • Individual tool: gitlab_group_invite_list_pending
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
order_bystringnoColumn to order keyset-paginated results by
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
querystringnoFilter invitations by email or name
sortstring (asc, desc)noSort order for keyset-paginated results: ‘asc’ or ‘desc’

List a project’s pending invitations. Returns: pending invitations with invite email, access level, creator, creation and expiry dates, plus pagination metadata. See also: access.invite_project, project.members.

  • Meta-tool: gitlab_access, action invite_list_project
  • Individual tool: gitlab_project_invite_list_pending
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
order_bystringnoColumn to order keyset-paginated results by
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
querystringnoFilter invitations by email or name
sortstring (asc, desc)noSort order for keyset-paginated results: ‘asc’ or ‘desc’

Invite a user to a project by email or user ID with an access level. Returns: an invitation result with status, per-email messages, and any users queued for administrator approval. See also: access.invite_list_project, project.member_add, access.request_project.

  • Meta-tool: gitlab_access, action invite_project
  • Individual tool: gitlab_project_invite
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
access_levelintegeryesAccess level (0=No access, 5=Minimal access, 10=Guest, 15=Planner (Premium/Ultimate), 20=Reporter, 25=Security Manager (Premium/Ultimate), 30=Developer, 40=Maintainer, 50=Owner)
project_idstring/integeryesProject ID or URL-encoded path
emailstringnoEmail address to invite (either email or user_id required)
expires_atstringnoExpiration date for the invitation (YYYY-MM-DD)
idstring/integernoProject ID or URL-encoded path sent in the request body (mirrors the GitLab id parameter. Usually equal to project_id)
invite_sourcestringnoSource of the invitation that starts the member creation process
member_role_id (Ultimate)integernoCustom role to assign the new member (Ultimate only)
user_idintegernoUser ID to invite (either email or user_id required)

Request access to a group as the authenticated user. Returns: the created access request with id, username, name, requested state, and requested_at timestamp. See also: access.request_list_group, access.approve_group, access.deny_group.

  • Meta-tool: gitlab_access, action request_group
  • Individual tool: gitlab_access_request_request_group
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or path

List pending access requests for a group. Returns: access requests with id, username, name, state, whether the account is locked, the address the user publishes, the requested_at timestamp, and pagination metadata. A pending request carries no access level: GitLab grants one when it is approved. See also: access.approve_group, access.deny_group, group.members.

  • Meta-tool: gitlab_access, action request_list_group
  • Individual tool: gitlab_access_request_list_group
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or path
order_bystringnoColumn to order results by for keyset-paginated result sets (e.g. id)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort order: asc or desc

List pending access requests for a project. Returns: access requests with id, username, name, state, whether the account is locked, the address the user publishes, the requested_at timestamp, and pagination metadata. A pending request carries no access level: GitLab grants one when it is approved. See also: access.approve_project, access.deny_project, project.members.

  • Meta-tool: gitlab_access, action request_list_project
  • Individual tool: gitlab_access_request_list_project
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path
order_bystringnoColumn to order results by for keyset-paginated result sets (e.g. id)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort order: asc or desc

Request access to a project as the authenticated user. Returns: the created access request with id, username, name, requested state, and requested_at timestamp. See also: access.request_list_project, access.approve_project, access.deny_project.

  • Meta-tool: gitlab_access, action request_project
  • Individual tool: gitlab_access_request_request_project
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or path

Use for GitLab group access tokens: this action creates a group-scoped API token.

  • Meta-tool: gitlab_access, action token_group_create
  • Individual tool: gitlab_group_access_token_create
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
namestringyesToken name
scopesstring[]yesToken scopes: api, read_api, read_repository, write_repository, etc.
access_levelintegernoAccess level: 5 (Minimal access), 10 (guest), 15 (Planner, Premium/Ultimate), 20 (reporter), 25 (Security Manager, Premium/Ultimate), 30 (developer), 40 (maintainer), 50 (owner). 60=Admin is not valid for group access tokens
descriptionstringnoToken description
expires_atstringnoExpiry date in YYYY-MM-DD format

Use for GitLab group access tokens: this action gets a group-scoped API token.

  • Meta-tool: gitlab_access, action token_group_get
  • Individual tool: gitlab_group_access_token_get
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
token_idintegeryesAccess token ID

Use for GitLab group access tokens: this action lists group-scoped API tokens.

  • Meta-tool: gitlab_access, action token_group_list
  • Individual tool: gitlab_group_access_token_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
created_afterstringnoReturn tokens created on or after this date (YYYY-MM-DD)
created_beforestringnoReturn tokens created on or before this date (YYYY-MM-DD)
expires_afterstringnoReturn tokens that expire on or after this date (YYYY-MM-DD)
expires_beforestringnoReturn tokens that expire on or before this date (YYYY-MM-DD)
last_used_afterstringnoReturn tokens last used on or after this date (YYYY-MM-DD)
last_used_beforestringnoReturn tokens last used on or before this date (YYYY-MM-DD)
order_bystringnoColumn to order results by (e.g. created_at, expires_at, last_used_at)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
revokedbooleannoFilter by revoked status: true to return only revoked tokens, false for non-revoked
searchstringnoFilter tokens by name (partial match)
sortstring (created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc)noSort order: created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc
statestring (active, inactive)noToken state filter: active, inactive

Use for GitLab group access tokens: this action revokes a group-scoped API token.

  • Meta-tool: gitlab_access, action token_group_revoke
  • Individual tool: gitlab_group_access_token_revoke
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
token_idintegeryesAccess token ID to revoke

Use for GitLab group access tokens: this action rotates a group-scoped API token.

  • Meta-tool: gitlab_access, action token_group_rotate
  • Individual tool: gitlab_group_access_token_rotate
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
token_idintegeryesAccess token ID
expires_atstringnoNew expiry date in YYYY-MM-DD format

Use for GitLab group access tokens: this action rotates the group-scoped token that authenticates this request itself, with no token_id parameter.

  • Meta-tool: gitlab_access, action token_group_rotate_self
  • Individual tool: gitlab_group_access_token_rotate_self
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
expires_atstringnoNew expiry date in YYYY-MM-DD format

Use for GitLab personal access tokens: this action gets a personal-scoped API token.

  • Meta-tool: gitlab_access, action token_personal_get
  • Individual tool: gitlab_personal_access_token_get
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
token_idintegernoAccess token ID (required, use 0 for current token)

Use for GitLab personal access tokens: this action lists personal-scoped API tokens.

  • Meta-tool: gitlab_access, action token_personal_list
  • Individual tool: gitlab_personal_access_token_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
created_afterstringnoReturn tokens created on or after this date (YYYY-MM-DD)
created_beforestringnoReturn tokens created on or before this date (YYYY-MM-DD)
expires_afterstringnoReturn tokens that expire on or after this date (YYYY-MM-DD)
expires_beforestringnoReturn tokens that expire on or before this date (YYYY-MM-DD)
last_used_afterstringnoReturn tokens last used on or after this date (YYYY-MM-DD)
last_used_beforestringnoReturn tokens last used on or before this date (YYYY-MM-DD)
order_bystringnoColumn to order results by (e.g. created_at, expires_at, last_used_at)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
revokedbooleannoFilter by revoked status: true to return only revoked tokens, false for non-revoked
searchstringnoSearch by token name
sortstring (created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc)noSort order: created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc
statestring (active, inactive)noToken state filter: active, inactive
user_idintegernoFilter by user ID (admin only)

Use for GitLab personal access tokens: this action revokes a personal-scoped API token.

  • Meta-tool: gitlab_access, action token_personal_revoke
  • Individual tool: gitlab_personal_access_token_revoke
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
token_idintegeryesAccess token ID to revoke

Use for GitLab personal access tokens: this action revokes the personal-scoped token that authenticates this request itself, with no token_id parameter.

  • Meta-tool: gitlab_access, action token_personal_revoke_self
  • Individual tool: gitlab_personal_access_token_revoke_self
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent

No parameters.

Use for GitLab personal access tokens: this action rotates a personal-scoped API token.

  • Meta-tool: gitlab_access, action token_personal_rotate
  • Individual tool: gitlab_personal_access_token_rotate
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
token_idintegeryesAccess token ID
expires_atstringnoNew expiry date in YYYY-MM-DD format

Use for GitLab personal access tokens: this action rotates the personal-scoped token that authenticates this request itself, with no token_id parameter.

  • Meta-tool: gitlab_access, action token_personal_rotate_self
  • Individual tool: gitlab_personal_access_token_rotate_self
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
expires_atstringnoNew expiry date in YYYY-MM-DD format

Use for GitLab project access tokens: this action creates a project-scoped API token.

  • Meta-tool: gitlab_access, action token_project_create
  • Individual tool: gitlab_project_access_token_create
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
namestringyesToken name
project_idstring/integeryesProject ID or URL-encoded path
scopesstring[]yesToken scopes: api, read_api, read_repository, write_repository, etc.
access_levelintegernoAccess level: 5 (Minimal access), 10 (guest), 15 (Planner, Premium/Ultimate), 20 (reporter), 25 (Security Manager, Premium/Ultimate), 30 (developer), 40 (maintainer). 50=Owner and 60=Admin are not valid for project access tokens
descriptionstringnoToken description
expires_atstringnoExpiry date in YYYY-MM-DD format

Use for GitLab project access tokens: this action gets a project-scoped API token.

  • Meta-tool: gitlab_access, action token_project_get
  • Individual tool: gitlab_project_access_token_get
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
token_idintegeryesAccess token ID

Use for GitLab project access tokens: this action lists project-scoped API tokens.

  • Meta-tool: gitlab_access, action token_project_list
  • Individual tool: gitlab_project_access_token_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
order_bystringnoColumn to order results by (e.g. created_at, expires_at, last_used_at)
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc)noSort order: created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc
statestring (active, inactive)noToken state filter: active, inactive

Use for GitLab project access tokens: this action revokes a project-scoped API token.

  • Meta-tool: gitlab_access, action token_project_revoke
  • Individual tool: gitlab_project_access_token_revoke
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
token_idintegeryesAccess token ID to revoke

Use for GitLab project access tokens: this action rotates a project-scoped API token.

  • Meta-tool: gitlab_access, action token_project_rotate
  • Individual tool: gitlab_project_access_token_rotate
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
token_idintegeryesAccess token ID
expires_atstringnoNew expiry date in YYYY-MM-DD format

Use for GitLab project access tokens: this action rotates the project-scoped token that authenticates this request itself, with no token_id parameter.

  • Meta-tool: gitlab_access, action token_project_rotate_self
  • Individual tool: gitlab_project_access_token_rotate_self
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
expires_atstringnoNew expiry date in YYYY-MM-DD format