--- topic: token-access description: Gitea MCP token scope inventory — what works with the configured token vs. what requires additional scopes --- # Gitea MCP Token Access ## Current token scope - write:issue - write:repository ## What works ### Repository discovery | Tool | Works | Notes | | -------------------------| ----------| ----------------------------| | `search_repos` | ✅ | Finds repos by keyword | | `list_my_repos` | ❌ | Needs `read:user` | | `list_org_repos` | ❌ | Needs `read:user` (inferred from `get_user_orgs` failure) | | `get_repository_tree` | ✅ | With `write:repository` | | `get_dir_contents` | ✅ | With `write:repository` | | `get_file_contents` | ✅ | With `write:repository` | | `create_or_update_file` | ✅ | Core `write:repository` op | | `delete_file` | ✅ | Core `write:repository` op | ### Issues | Tool | Works | Notes | | ------------------------------------------------------------------------| -------| -----------------------------| | `list_issues` | ✅ | Full list with state filter | | `search_issues` | ✅ | Cross-repo search | | `issue_read` (get) | ✅ | | | `issue_read` (get_comments) | ✅ | | | `issue_read` (get_labels) | ✅ | | | `issue_write` (create) | ✅ | Core `write:issue` op | | `issue_write` (update) | ✅ | | | `issue_write` (add_comment) | ✅ | | | `issue_write` (edit_comment) | ✅ | | | `issue_write` (add_labels, remove_label, replace_labels, clear_labels) | ✅ | | | `label_read` | ✅ | | | `label_write` | ✅ | | | `milestone_read` | ✅ | | | `milestone_write` | ✅ | | ### Pull Requests | Tool | Works | Notes | |---|---|---| | `list_pull_requests` | ✅ | | | `pull_request_read` (get, get_diff, get_files, get_status, get_reviews) | ✅ | | | `pull_request_write` (create, update, close, reopen, merge, update_branch) | ✅ | Needs `write:repository` | | `pull_request_review_write` | ✅ | | ### Branches & Commits | Tool | Works | Notes | |---|---|---| | `list_branches` | ✅ | | | `create_branch` | ✅ | `write:repository` | | `delete_branch` | ✅ | `write:repository` | | `list_commits` | ✅ | | | `get_commit` | ✅ | | ### Releases & Tags | Tool | Works | Notes | |---|---|---| | `list_releases`, `get_release`, `get_latest_release` | ✅ | | | `create_release`, `delete_release` | ✅ | `write:repository` | | `list_tags`, `get_tag`, `create_tag`, `delete_tag` | ✅ | `write:repository` | ### Actions (CI) | Tool | Works | Notes | |---|---|---| | `actions_config_read` (list_repo_secrets) | ❌ | "user should be the owner of the repo" — token auth not accepted for secrets | | `actions_config_write` | untested (write — not tested to avoid side effects) | | | `actions_run_read` (list_workflows) | ✅ empty | No workflows defined; returns `{total_count:0,workflows:[]}` | | `actions_run_read` (list_runs) | ❌ | "user should be the owner of the repo" — 403 | | `actions_run_write` | untested (write — not tested to avoid side effects) | | ### User & Identity | Tool | Works | Notes | |---|---|---| | `get_me` | ❌ | Needs `read:user` | | `search_users` | ❌ | Needs `read:user` | | `get_user_orgs` | ❌ | Needs `read:user` and `read:organization` | ### Other | Tool | Works | Notes | | ---------------------------------------| -----------------------------------------------------| ------------------------------------------| | `wiki_read` | ❌ | 404 — wiki not enabled for this repo | | `wiki_write` | untested (write — not tested to avoid side effects) | | | `notification_read` | ❌ | Needs `read:notification` scope | | `notification_write` | untested (write — not tested to avoid side effects) | | | `timetracking_read` (list_repo_times) | ✅ empty | No tracked times; returns string message | | `timetracking_write` | untested (write — not tested to avoid side effects) | | | `package_read` | ❌ | Needs `read:package` scope | | `package_write` | untested (write — not tested to avoid side effects) | |