Skip to content

Tags

Tag management in one project: list, read, create and delete tags, read the GPG or X.509 signature of a tag, and protect tag patterns with the access level allowed to create them, then read or remove that protection. Deleting a tag also removes the release attached to it.

  • “List the tags of project 42”
  • “Create tag v2.0.0 on main”
  • “Is tag v1.9.0 signed?”
  • Dynamic, the default surface: call gitlab_execute_action with action set to the action’s ID, such as tag.create, and its parameters in params. gitlab_find_action finds an ID from a description of the task.
  • Meta (GITLAB_MCP_TOOL_SURFACE=meta): call gitlab_tag with action set to the action’s name, such as create, and its parameters in params.
  • Individual (GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such as gitlab_tag_create, with its parameters as the arguments.

Every tier serves the whole group, on self-managed instances and on GitLab.com alike.

Read-only actions: 5 of 9, the ones a deployment in read-only mode keeps.

The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).

ActionIndividual
tag.creategitlab_tag_create
tag.deletegitlab_tag_delete
tag.getgitlab_tag_get
tag.get_protectedgitlab_tag_get_protected
tag.get_signaturegitlab_tag_get_signature
tag.listgitlab_tag_list
tag.list_protectedgitlab_tag_list_protected
tag.protectgitlab_tag_protect
tag.unprotectgitlab_tag_unprotect

Create a new tag in a project pointing at a ref. Returns: the created tag with target, message, protection flag, and the associated commit object. See also: tag.get, tag.delete, release.create.

  • Meta-tool: gitlab_tag, action create
  • Individual tool: gitlab_tag_create
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
refstringyesCommit SHA, branch name, or another tag to create the tag from
tag_namestringyesName of the tag
messagestringnoCreates an annotated tag with this message

Delete a tag from a project permanently. Returns: a success confirmation naming the tag and project. See also: tag.get, tag.list, tag.unprotect.

  • Meta-tool: gitlab_tag, action delete
  • Individual tool: gitlab_tag_delete
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
tag_namestringyesName of the tag to delete

Get a single tag from a project by name. Returns: the tag with target, message, protection flag, the full associated commit object, release note, and creation time. See also: tag.list, tag.get_signature, release.get.

  • Meta-tool: gitlab_tag, action get
  • Individual tool: gitlab_tag_get
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
tag_namestringyesTag name to retrieve

Get a single protected tag or wildcard rule by name. Returns: the protected tag with its create access levels (access level, user, group, and deploy key descriptions). See also: tag.list_protected, tag.protect, tag.unprotect.

  • Meta-tool: gitlab_tag, action get_protected
  • Individual tool: gitlab_tag_get_protected
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
tag_namestringyesName of the protected tag

Get the X.509 signature of a tag. Returns: the signature type, verification status, and the X.509 certificate with issuer detail. See also: tag.get, tag.list.

  • Meta-tool: gitlab_tag, action get_signature
  • Individual tool: gitlab_tag_get_signature
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
tag_namestringyesTag name to retrieve signature for

List tags in one project with optional search and offset or keyset pagination. Returns: matching tags with target, message, protection flag, the associated commit object, release note, and pagination metadata. See also: tag.get, tag.create, release.list.

  • Meta-tool: gitlab_tag, action list
  • Individual tool: gitlab_tag_list
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
order_bystring (name, updated, version)noOrder tags by name, updated (default), or version, which sorts by semantic version number
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
searchstringnoSearch query to filter tags by name
sortstring (asc, desc)noSort direction (asc, desc)

List protected tags in one project with offset or keyset pagination. Returns: protected tag patterns with their create access levels and pagination metadata. See also: tag.get_protected, tag.protect, tag.list.

  • Meta-tool: gitlab_tag, action list_protected
  • Individual tool: gitlab_tag_list_protected
  • Tier: Free
  • Behavior: read-only, idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
order_bystringnoColumn to order keyset-paginated results by
pageintegernoPage number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward.
page_tokenstringnoKeyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’.
paginationstringnoPagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost.
per_pageintegernoItems per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large.
sortstring (asc, desc)noSort direction (asc, desc)

Protect a tag or wildcard pattern with create access levels. Returns: the protected tag with its resolved create access levels. See also: tag.unprotect, tag.list_protected, tag.get_protected.

  • Meta-tool: gitlab_tag, action protect
  • Individual tool: gitlab_tag_protect
  • Tier: Free
  • Behavior: writes, not idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
tag_namestringyesTag name or wildcard pattern (e.g. ‘v*’)
allowed_to_createobject[]noGranular create permissions (user_id, group_id, deploy_key_id, access_level)
create_access_levelintegernoAccess level allowed to create (0=No access, 30=Developer, 40=Maintainer)

Remove protection from a tag or wildcard pattern. Returns: a success confirmation naming the tag and project. See also: tag.protect, tag.list_protected, tag.get_protected.

  • Meta-tool: gitlab_tag, action unprotect
  • Individual tool: gitlab_tag_unprotect
  • Tier: Free
  • Behavior: writes, destructive (needs confirmation), idempotent
ParameterTypeMandatoryDescription
project_idstring/integeryesProject ID or URL-encoded path
tag_namestringyesName of the protected tag to unprotect