Skip to content

Custom member roles

A custom member role adds chosen permissions to one of GitLab’s base access levels. These actions list, create and delete custom roles, at the instance (an administrator’s) or in a top-level group.

  • “List the custom roles of group acme”
  • “Create a Developer-based role that can also manage vulnerabilities”
  • “Delete the unused custom role 9”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as member_role.create_group, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_member_role with action set to the action’s name, such as create_group, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_create_group_member_role, with its parameters as the arguments.

How many of these actions an instance serves at each tier, out of a total of 6:

  • Free: 0
  • Premium: 0
  • Ultimate: 6

Read-only actions: 2 of 6, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).

ActionIndividual
member_role.create_groupgitlab_create_group_member_role
member_role.create_instancegitlab_create_instance_member_role
member_role.delete_groupgitlab_delete_group_member_role
member_role.delete_instancegitlab_delete_instance_member_role
member_role.list_groupgitlab_list_group_member_roles
member_role.list_instancegitlab_list_instance_member_roles

Create a group-level custom member role. Returns: the created role with id, name, base_access_level, and its enabled permission flags. See also: member_role.list_group, member_role.delete_group, member_role.create_instance.

  • Meta-tool: gitlab_member_role, action create_group
  • Individual tool: gitlab_create_group_member_role
  • Tier: Ultimate
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
base_access_levelintegeryesBase access level (10=Guest, 15=Planner, 20=Reporter, 25=Security Manager, 30=Developer, 40=Maintainer, 50=Owner). 0, 5 and 60 are not valid
group_idstring/integeryesGroup ID or URL-encoded path
namestringyesName of the custom role
admin_cicd_variablesbooleannoAllow admin CI/CD variables
admin_compliance_frameworkbooleannoAllow admin compliance framework
admin_group_memberbooleannoAllow admin group members
admin_merge_requestbooleannoAllow admin merge requests
admin_push_rulesbooleannoAllow admin push rules
admin_terraform_statebooleannoAllow admin Terraform state
admin_vulnerabilitybooleannoAllow admin vulnerability
admin_web_hookbooleannoAllow admin webhooks
archive_projectbooleannoAllow archive project
descriptionstringnoDescription of the custom role
manage_deploy_tokensbooleannoAllow manage deploy tokens
manage_group_access_tokensbooleannoAllow manage group access tokens
manage_merge_request_settingsbooleannoAllow manage MR settings
manage_project_access_tokensbooleannoAllow manage project access tokens
manage_security_policy_linkbooleannoAllow manage security policy link
read_codebooleannoAllow read code
read_dependencybooleannoAllow read dependency
read_runnersbooleannoAllow read runners
read_vulnerabilitybooleannoAllow read vulnerability
remove_groupbooleannoAllow remove group
remove_projectbooleannoAllow remove project

Create an instance-level custom member role. Returns: the created role with id, name, base_access_level, and its enabled permission flags. See also: member_role.list_instance, member_role.delete_instance, member_role.create_group.

  • Meta-tool: gitlab_member_role, action create_instance
  • Individual tool: gitlab_create_instance_member_role
  • Tier: Ultimate
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
base_access_levelintegeryesBase access level (10=Guest, 15=Planner, 20=Reporter, 25=Security Manager, 30=Developer, 40=Maintainer, 50=Owner). 0, 5 and 60 are not valid
namestringyesName of the custom role
admin_cicd_variablesbooleannoAllow admin CI/CD variables
admin_compliance_frameworkbooleannoAllow admin compliance framework
admin_group_memberbooleannoAllow admin group members
admin_merge_requestbooleannoAllow admin merge requests
admin_push_rulesbooleannoAllow admin push rules
admin_terraform_statebooleannoAllow admin Terraform state
admin_vulnerabilitybooleannoAllow admin vulnerability
admin_web_hookbooleannoAllow admin webhooks
archive_projectbooleannoAllow archive project
descriptionstringnoDescription of the custom role
manage_deploy_tokensbooleannoAllow manage deploy tokens
manage_group_access_tokensbooleannoAllow manage group access tokens
manage_merge_request_settingsbooleannoAllow manage MR settings
manage_project_access_tokensbooleannoAllow manage project access tokens
manage_security_policy_linkbooleannoAllow manage security policy link
read_codebooleannoAllow read code
read_dependencybooleannoAllow read dependency
read_runnersbooleannoAllow read runners
read_vulnerabilitybooleannoAllow read vulnerability
remove_groupbooleannoAllow remove group
remove_projectbooleannoAllow remove project

Delete a group-level custom member role. Returns: a success confirmation naming the deleted role and group. See also: member_role.list_group, member_role.create_group.

  • Meta-tool: gitlab_member_role, action delete_group
  • Individual tool: gitlab_delete_group_member_role
  • Tier: Ultimate
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path
member_role_idintegeryesMember role ID to delete

Delete an instance-level custom member role. Returns: a success confirmation naming the deleted role. See also: member_role.list_instance, member_role.create_instance.

  • Meta-tool: gitlab_member_role, action delete_instance
  • Individual tool: gitlab_delete_instance_member_role
  • Tier: Ultimate
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
member_role_idintegeryesMember role ID to delete

List group-level custom member roles. Returns: each role with id, name, description, base_access_level, and its enabled permission flags. See also: member_role.list_instance, member_role.create_group, member_role.delete_group.

  • Meta-tool: gitlab_member_role, action list_group
  • Individual tool: gitlab_list_group_member_roles
  • Tier: Ultimate
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
group_idstring/integeryesGroup ID or URL-encoded path

List instance-level custom member roles. Returns: each role with id, name, description, base_access_level, and its enabled permission flags. See also: member_role.create_instance, member_role.delete_instance, member_role.list_group.

  • Meta-tool: gitlab_member_role, action list_instance
  • Individual tool: gitlab_list_instance_member_roles
  • Tier: Ultimate
  • Behavior: read-only, idempotent

No parameters.