Skip to content

CI/CD variables

CI/CD variables at the three scopes GitLab keeps them: a project, a group and the instance, each with the same five operations. A variable can be protected, masked or masked and hidden, and project and group variables can be scoped to an environment, so one key can hold a different value per environment. Instance variables need an administrator, and deleting a variable cannot be undone.

  • “List the CI/CD variables of project 42”
  • “Add a masked DEPLOY_TOKEN variable scoped to production”
  • “Which group variables does group platform define?”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as ci_variable.create, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_ci_variable with action set to the action’s name, such as create, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_ci_variable_create, with its parameters as the arguments.

Every tier serves the whole group, on self-managed instances and on GitLab.com alike.

Read-only actions: 6 of 15, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).

ActionIndividual
ci_variable.creategitlab_ci_variable_create
ci_variable.deletegitlab_ci_variable_delete
ci_variable.getgitlab_ci_variable_get
ci_variable.group_creategitlab_group_variable_create
ci_variable.group_deletegitlab_group_variable_delete
ci_variable.group_getgitlab_group_variable_get
ci_variable.group_listgitlab_group_variable_list
ci_variable.group_updategitlab_group_variable_update
ci_variable.instance_creategitlab_instance_variable_create
ci_variable.instance_deletegitlab_instance_variable_delete
ci_variable.instance_getgitlab_instance_variable_get
ci_variable.instance_listgitlab_instance_variable_list
ci_variable.instance_updategitlab_instance_variable_update
ci_variable.listgitlab_ci_variable_list
ci_variable.updategitlab_ci_variable_update

Create a CI/CD variable in a project with type, environment scope, and protected/masked/raw/masked_and_hidden flags. Returns: the created variable’s key, value (redacted when masked or hidden), type, flags, environment scope, and description. See also: ci_variable.list, ci_variable.get, ci_variable.update.

  • Meta-tool: gitlab_ci_variable, action create
  • Individual tool: gitlab_ci_variable_create
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
keystringyesVariable key name
project_idstring/integeryesProject ID or URL-encoded path
valuestringyesVariable value
descriptionstringnoVariable description
environment_scopestringnoEnvironment scope (default: *)
maskedbooleannoMask variable value in job logs
masked_and_hiddenbooleannoMask and hide variable value
protectedbooleannoOnly expose in protected branches/tags
rawbooleannoTreat variable value as raw string
variable_typestring (env_var, file)noVariable type: env_var or file

Delete a CI/CD variable by key, selecting an environment-scoped instance via the filter. Returns: a success confirmation message. See also: ci_variable.list, ci_variable.get.

  • Meta-tool: gitlab_ci_variable, action delete
  • Individual tool: gitlab_ci_variable_delete
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
keystringyesVariable key name
project_idstring/integeryesProject ID or URL-encoded path
environment_scopestringnoFilter by environment scope (shorthand for filter.environment_scope)
filterobjectnoFilter selecting the variable by environment scope. Mirrors the GitLab variable filter object

Get a single CI/CD variable by key, optionally selecting an environment-scoped instance via the filter. Returns: the variable’s key, value (redacted when masked or hidden), type, protected/masked/hidden/raw flags, environment scope, and description. See also: ci_variable.list, ci_variable.update, ci_variable.delete.

  • Meta-tool: gitlab_ci_variable, action get
  • Individual tool: gitlab_ci_variable_get
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
keystringyesVariable key name
project_idstring/integeryesProject ID or URL-encoded path
environment_scopestringnoFilter by environment scope (shorthand for filter.environment_scope)
filterobjectnoFilter selecting the variable by environment scope. Mirrors the GitLab variable filter object

Create a CI/CD variable in a group with type, environment scope, and protected/masked/raw/masked_and_hidden flags. Returns: the created variable’s key, value, type, flags, environment scope, and description. See also: ci_variable.group_list, ci_variable.group_get, ci_variable.group_update.

  • Meta-tool: gitlab_ci_variable, action group_create
  • Individual tool: gitlab_group_variable_create
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
keystringyesVariable key name
descriptionstringnoVariable description
environment_scopestringnoEnvironment scope (default: *)
maskedbooleannoMask variable value in job logs
masked_and_hiddenbooleannoMask and hide variable value
protectedbooleannoOnly expose in protected branches/tags
rawbooleannoTreat variable value as raw string
valuestringnoVariable value
variable_typestring (env_var, file)noVariable type: env_var or file

Delete a group CI/CD variable by key, selecting an environment-scoped instance via the filter. Returns: a success confirmation message. See also: ci_variable.group_list, ci_variable.group_get.

  • Meta-tool: gitlab_ci_variable, action group_delete
  • Individual tool: gitlab_group_variable_delete
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
keystringyesVariable key name
environment_scopestringnoFilter by environment scope (shorthand for filter.environment_scope)
filterobjectnoFilter selecting the variable by environment scope. Mirrors the GitLab variable filter object

Get a single group CI/CD variable by key, optionally selecting an environment-scoped instance via the filter. Returns: the variable’s key, value, type, protected/masked/hidden/raw flags, environment scope, and description. See also: ci_variable.group_list, ci_variable.group_update, ci_variable.group_delete.

  • Meta-tool: gitlab_ci_variable, action group_get
  • Individual tool: gitlab_group_variable_get
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
keystringyesVariable key name
environment_scopestringnoFilter by environment scope (shorthand for filter.environment_scope)
filterobjectnoFilter selecting the variable by environment scope. Mirrors the GitLab variable filter object

List a group’s CI/CD variables with order_by, sort, and offset or keyset pagination. Returns: each variable’s key, value, type, protected/masked/hidden/raw flags, environment scope, description, and pagination metadata. See also: ci_variable.group_get, ci_variable.group_create, ci_variable.group_update.

  • Meta-tool: gitlab_ci_variable, action group_list
  • Individual tool: gitlab_group_variable_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
order_bystringnoColumn by which to order keyset-paginated results
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction for keyset-paginated results (asc, desc)

Update a group CI/CD variable, selecting an environment-scoped instance via the filter. Returns: the updated variable’s key, value, type, protected/masked/hidden/raw flags, environment scope, and description. See also: ci_variable.group_get, ci_variable.group_list, ci_variable.group_delete.

  • Meta-tool: gitlab_ci_variable, action group_update
  • Individual tool: gitlab_group_variable_update
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
keystringyesVariable key name
descriptionstringnoUpdated variable description
environment_scopestringnoFilter by environment scope (shorthand for filter.environment_scope)
filterobjectnoFilter selecting the variable by environment scope. Mirrors the GitLab variable filter object
maskedbooleannoMask variable value in job logs
protectedbooleannoOnly expose in protected branches/tags
rawbooleannoTreat variable value as raw string
valuestringnoUpdated variable value
variable_typestring (env_var, file)noVariable type: env_var or file

Create an instance-level CI/CD variable with type and protected/masked/raw flags (admin-only). Returns: the created variable’s key, value (raw even when masked, because masking redacts CI job logs, not this API), type, flags, and description. See also: ci_variable.instance_list, ci_variable.instance_get, ci_variable.instance_update.

  • Meta-tool: gitlab_ci_variable, action instance_create
  • Individual tool: gitlab_instance_variable_create
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
keystringyesVariable key name
descriptionstringnoVariable description
maskedbooleannoMask variable value in job logs
protectedbooleannoOnly expose in protected branches/tags
rawbooleannoTreat variable value as raw string
valuestringnoVariable value
variable_typestring (env_var, file)noVariable type: env_var or file

Delete an instance-level CI/CD variable by key (admin-only). Returns: a success confirmation message. See also: ci_variable.instance_list, ci_variable.instance_get.

  • Meta-tool: gitlab_ci_variable, action instance_delete
  • Individual tool: gitlab_instance_variable_delete
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
keystringyesVariable key name

Get a single instance-level CI/CD variable by key (admin-only). Returns: the variable’s key, value (raw even when masked, because masking redacts CI job logs, not this API), type, protected/masked/raw flags, and description. See also: ci_variable.instance_list, ci_variable.instance_update, ci_variable.instance_delete.

  • Meta-tool: gitlab_ci_variable, action instance_get
  • Individual tool: gitlab_instance_variable_get
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
keystringyesVariable key name

List instance-level CI/CD variables with order_by, sort, and offset or keyset pagination (admin-only). Returns: each variable’s key, value (raw even when masked, because masking redacts CI job logs, not this API), type, protected/masked/raw flags, description, and pagination metadata. See also: ci_variable.instance_get, ci_variable.instance_create, ci_variable.instance_update, ci_variable.instance_delete.

  • Meta-tool: gitlab_ci_variable, action instance_list
  • Individual tool: gitlab_instance_variable_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
order_bystringnoColumn by which to order keyset-paginated results
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction for keyset-paginated results (asc, desc)

Update an instance-level CI/CD variable by key, with type and protected/masked/raw flags (admin-only). Returns: the updated variable’s key, value (raw even when masked, because masking redacts CI job logs, not this API), type, protected/masked/raw flags, and description. See also: ci_variable.instance_get, ci_variable.instance_list, ci_variable.instance_delete.

  • Meta-tool: gitlab_ci_variable, action instance_update
  • Individual tool: gitlab_instance_variable_update
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
keystringyesVariable key name
descriptionstringnoUpdated variable description
maskedbooleannoMask variable value in job logs
protectedbooleannoOnly expose in protected branches/tags
rawbooleannoTreat variable value as raw string
valuestringnoUpdated variable value
variable_typestring (env_var, file)noVariable type: env_var or file

List a project’s CI/CD variables with order_by, sort, and offset or keyset pagination. Returns: each variable’s key, type, protected/masked/hidden/raw flags, environment scope, description, and pagination metadata. See also: ci_variable.get, ci_variable.create, ci_variable.update.

  • Meta-tool: gitlab_ci_variable, action list
  • Individual tool: gitlab_ci_variable_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
order_bystringnoColumn by which to order keyset-paginated results
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction for keyset-paginated results (asc, desc)

Update a CI/CD variable, selecting an environment-scoped instance via the filter. Returns: the updated variable’s key, value (redacted when masked or hidden), type, protected/masked/hidden/raw flags, environment scope, and description. See also: ci_variable.get, ci_variable.list, ci_variable.delete.

  • Meta-tool: gitlab_ci_variable, action update
  • Individual tool: gitlab_ci_variable_update
  • Tier: Free
  • Behavior: writes, idempotent
ParameterTypeMandatoryDescription
keystringyesVariable key name
project_idstring/integeryesProject ID or URL-encoded path
descriptionstringnoUpdated variable description
environment_scopestringnoFilter by environment scope (shorthand for filter.environment_scope)
filterobjectnoFilter selecting the variable by environment scope. Mirrors the GitLab variable filter object
maskedbooleannoMask variable value in job logs
protectedbooleannoOnly expose in protected branches/tags
rawbooleannoTreat variable value as raw string
valuestringnoUpdated variable value
variable_typestring (env_var, file)noVariable type: env_var or file