Table of contents

Developers building GitHub integrations in Cursor already have the repository open in one tab and the API docs in another.
The PR diff structure, issue field schema, and repository permission model only reveal themselves in real API responses, and the code that parses or generates them can only be correct once you've seen what the API actually returns.
Getting there means leaving Cursor, configuring OAuth separately, running test calls, and copying JSON back into the session where the integration is being built.
To help your developers inspect repository data, pull request structures, and issue schemas without leaving Cursor, we'll show you how to connect GitHub with Merge Agent Handler's GitHub MCP server.
Merge Agent Handler connects Cursor to the GitHub API through the Merge CLI.
Install the CLI, authenticate once, and run a single setup command from your project root.
That command writes a ## Merge CLI section to the project's .cursorrules file, which tells Cursor's agent when to call merge search-tools and merge execute-tool to reach GitHub.
One authentication is successfully completed, Merge handles GitHub OAuth credentials and token rotation so you never store a personal access token locally or configure auth state in the project.
Here's the registration command:
Related: The steps for connecting a GitHub MCP with Codex
Before getting started, you'll need the following:
pipx --version to confirm, or install via pip install pipx)If you want to connect Merge Agent Handler's GitHub MCP with internal or customer-facing agentic products, you can follow the steps in our docs.
Run the following to install the Merge CLI and confirm it's available: pipx install merge-api
Verify your installation: merge --version
Authenticate the CLI with your Merge Agent Handler account: merge login
This links the CLI to your account so it can make authorized requests to GitHub on your behalf.
Run the following from the root of the project where you want to use Merge tools:
This writes a ## Merge CLI section to .cursorrules so Cursor knows to use the CLI for third-party services. The command is idempotent, safe to re-run if you need to reset.
Related: How to use a GitHub MCP in Claude Code
Open a Cursor chat in your project and start with a query that reflects real development work.
For example: "Fetch the last 5 open pull requests from my repo and return the full JSON for each, including all fields, review status, labels, and file change data, so I can write accurate TypeScript interfaces for my PR analysis tool."
The first time you invoke a GitHub tool, a Magic Link will appear to complete connector authentication.

{{this-blog-only-cta}}
In case you have more questions on setting up and using the GitHub MCP in Cursor, we've addressed several more commonly-asked questions below.
With GitHub connected, Cursor can:
You can build a self-hosted MCP server on top of GitHub's REST or GraphQL API. GitHub's documentation is thorough, personal access tokens are quick to generate, and for a single developer working against their own repositories the setup takes minutes.
The challenge is shared deployment.
GitHub personal access tokens carry access to everything the account can reach. A self-hosted MCP server backed by a shared token gives all connected agents the same access level with no per-agent controls on which repositories or operations each one can reach. When the token expires or needs rotation, every agent that depends on it goes down at the same time.
GitHub does publish an official MCP server, but it doesn't include the access control or audit logging layer that enterprise teams need when agents are reading or writing against production repositories.
Merge Agent Handler handles GitHub authentication centrally.
You can control exactly which GitHub operations each agent is allowed to call: an agent that monitors pull request review lag can, for example, list and read pull requests, but never reaches write operations like merge or delete unless those are explicitly included.
Every call is also logged with the timestamp, tool name, and inputs.
For teams running agents against repositories that contain production code, that combination of scoped access and audit logging is the difference between a controlled deployment and an ungoverned one.
GitHub contains the live state of a software project: pull requests in review, open issues with labels and assignees, recent commit history, and workflow run results.
Developers writing integration code that depends on any of that state need access to real data to write code that works against it.
With the GitHub MCP connected, Cursor can pull that data inline during a coding session.
Use Merge Agent Handler’s 150+ connectors (including GitHub) to power reliable, secure, and powerful agents.