Tags
Tag management in one project: list, read, create and delete tags, read the GPG or X.509 signature of a tag, and protect tag patterns with the access level allowed to create them, then read or remove that protection. Deleting a tag also removes the release attached to it.
Sample questions
Section titled “Sample questions”- “List the tags of project 42”
- “Create tag v2.0.0 on main”
- “Is tag v1.9.0 signed?”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such astag.create, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_tagwithactionset to the action’s name, such ascreate, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_tag_create, with its parameters as the arguments.
Availability
Section titled “Availability”Every tier serves the whole group, on self-managed instances and on GitLab.com alike.
Read-only actions: 5 of 9, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions).
| Action | Individual |
|---|---|
tag.create | gitlab_tag_create |
tag.delete | gitlab_tag_delete |
tag.get | gitlab_tag_get |
tag.get_protected | gitlab_tag_get_protected |
tag.get_signature | gitlab_tag_get_signature |
tag.list | gitlab_tag_list |
tag.list_protected | gitlab_tag_list_protected |
tag.protect | gitlab_tag_protect |
tag.unprotect | gitlab_tag_unprotect |
tag.create
Section titled “tag.create”Create a new tag in a project pointing at a ref. Returns: the created tag with target, message, protection flag, and the associated commit object. See also:
tag.get,tag.delete,release.create.
- Meta-tool:
gitlab_tag, actioncreate - Individual tool:
gitlab_tag_create - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
ref | string | yes | Commit SHA, branch name, or another tag to create the tag from |
tag_name | string | yes | Name of the tag |
message | string | no | Creates an annotated tag with this message |
tag.delete
Section titled “tag.delete”Delete a tag from a project permanently. Returns: a success confirmation naming the tag and project. See also:
tag.get,tag.list,tag.unprotect.
- Meta-tool:
gitlab_tag, actiondelete - Individual tool:
gitlab_tag_delete - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
tag_name | string | yes | Name of the tag to delete |
tag.get
Section titled “tag.get”Get a single tag from a project by name. Returns: the tag with target, message, protection flag, the full associated commit object, release note, and creation time. See also:
tag.list,tag.get_signature,release.get.
- Meta-tool:
gitlab_tag, actionget - Individual tool:
gitlab_tag_get - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
tag_name | string | yes | Tag name to retrieve |
tag.get_protected
Section titled “tag.get_protected”Get a single protected tag or wildcard rule by name. Returns: the protected tag with its create access levels (access level, user, group, and deploy key descriptions). See also:
tag.list_protected,tag.protect,tag.unprotect.
- Meta-tool:
gitlab_tag, actionget_protected - Individual tool:
gitlab_tag_get_protected - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
tag_name | string | yes | Name of the protected tag |
tag.get_signature
Section titled “tag.get_signature”Get the X.509 signature of a tag. Returns: the signature type, verification status, and the X.509 certificate with issuer detail. See also:
tag.get,tag.list.
- Meta-tool:
gitlab_tag, actionget_signature - Individual tool:
gitlab_tag_get_signature - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
tag_name | string | yes | Tag name to retrieve signature for |
tag.list
Section titled “tag.list”List tags in one project with optional search and offset or keyset pagination. Returns: matching tags with target, message, protection flag, the associated commit object, release note, and pagination metadata. See also:
tag.get,tag.create,release.list.
- Meta-tool:
gitlab_tag, actionlist - Individual tool:
gitlab_tag_list - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
order_by | string (name, updated, version) | no | Order tags by name, updated (default), or version, which sorts by semantic version number |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
search | string | no | Search query to filter tags by name |
sort | string (asc, desc) | no | Sort direction (asc, desc) |
tag.list_protected
Section titled “tag.list_protected”List protected tags in one project with offset or keyset pagination. Returns: protected tag patterns with their create access levels and pagination metadata. See also:
tag.get_protected,tag.protect,tag.list.
- Meta-tool:
gitlab_tag, actionlist_protected - Individual tool:
gitlab_tag_list_protected - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
order_by | string | no | Column to order keyset-paginated results by |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
sort | string (asc, desc) | no | Sort direction (asc, desc) |
tag.protect
Section titled “tag.protect”Protect a tag or wildcard pattern with create access levels. Returns: the protected tag with its resolved create access levels. See also:
tag.unprotect,tag.list_protected,tag.get_protected.
- Meta-tool:
gitlab_tag, actionprotect - Individual tool:
gitlab_tag_protect - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
tag_name | string | yes | Tag name or wildcard pattern (e.g. ‘v*’) |
allowed_to_create | object[] | no | Granular create permissions (user_id, group_id, deploy_key_id, access_level) |
create_access_level | integer | no | Access level allowed to create (0=No access, 30=Developer, 40=Maintainer) |
tag.unprotect
Section titled “tag.unprotect”Remove protection from a tag or wildcard pattern. Returns: a success confirmation naming the tag and project. See also:
tag.protect,tag.list_protected,tag.get_protected.
- Meta-tool:
gitlab_tag, actionunprotect - Individual tool:
gitlab_tag_unprotect - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
tag_name | string | yes | Name of the protected tag to unprotect |