Search public open-source code, documentation, metadata, vulnerabilities, changelogs, and examples.
com.githits/githits (MCP) — GitHits
GitHits (CLI) provides a “code context layer for AI coding agents.” The MCP server is positioned to search public open-source code and related materials, including documentation, metadata, vulnerabilities, changelogs, and examples. It supports index- and context-oriented workflows via MCP and remote-MCP patterns.
GitHits connects AI coding agents to public open-source evidence across the
full software development lifecycle: discovery, planning, research,
implementation, debugging, and maintenance.
The CLI runs a local MCP server that your
coding tool starts on demand. Agents can then search indexed package and
repository source, read exact files and documentation pages, inspect package
health, compare dependency upgrades, and find source-cited examples from real
open-source projects when model knowledge and local repository context are not
enough.
Want to use GitHits as part of your agent harness or software factory? Check out
our public API documentation.
Quick Start
sh
npx githits@latest init
init signs you in, detects supported coding tools, and configures GitHits for
the tools you select. It uses the local stdio MCP except for Cursor, whose
direct setup uses the hosted remote MCP.
Automatic setup currently supports Claude Code, Cursor, Windsurf,
VS Code / Copilot, Cline, Claude Desktop, Codex CLI, Pi, Gemini CLI,
Google Antigravity, OpenCode, Hermes Agent, Zed, Junie, Qwen Code,
Kiro, Kilo Code, Factory Droid, and Amazon Q CLI.
After setup, open your coding agent and work normally. Many agents call GitHits
when they need source-backed context. If your agent starts guessing, prompt it
directly:
text
Use GitHits Code Navigation to inspect npm:express. Find how middleware
errors are handled, read the relevant source, and explain the fix before
editing code.
What GitHits Adds
GitHits is designed for the point where an agent needs evidence from the
broader open-source ecosystem, not just model memory or local repo context:
GitHits 0.10 adds two opt-in local tools for early dogfooding:
resolve_target / githits resolve turns a fuzzy or ambiguous package,
repository, or documentation-site name into grouped canonical targets with
related project identities kept together.
code_diff / githits code diff compares repository trees resolved from
exact package versions or public GitHub refs.
They are hidden and disabled by default. They are available only through the
local githits CLI and local stdio MCP server; the hosted MCP and plugin or
extension installs keep the stable tool set. Enable them in the GitHits host
config, then restart the coding agent so it restarts the local MCP server:
Package inspection supports npm, PyPI, Hex, Crates, NuGet, Maven, Packagist,
RubyGems, Go, Swift, vcpkg, and Zig. Advisory data is unavailable for vcpkg and
Zig; dependency graph support varies by registry.
License Filtering
Code example search supports license filtering:
strict is the default and filters repositories with copyleft or undeclared licenses
custom uses your account blocklist configured at githits.com
yolo disables license filtering
sh
npx githits@latest example "async file reading" --lang python --license strict
Authentication
Normal local setup is handled by:
sh
npx githits@latest init
For manual login:
sh
npx githits@latest login
Browser OAuth is recommended for local development. Credentials are stored in
the system keychain by default and refreshed automatically. Useful flags:
init --no-browser or login --no-browser prints the login URL instead of launching a browser
init --port <port> or login --port <port> fixes the loopback callback port
login --force re-authenticates even if you are already logged in
The OAuth callback always listens on the machine where GitHits is running.
When GitHits runs over SSH and the browser runs locally, forward the selected
port from the browser machine:
sh
ssh -N -L 8765:127.0.0.1:8765 user@remote-host
With that tunnel open, run GitHits on the remote machine using the same port:
sh
npx githits@latest init --no-browser --port 8765
Open the URL printed by GitHits in the local browser. Replace
user@remote-host with the SSH destination you normally use. The same flags
work with githits login after setup.
Browser OAuth is interactive. For CI and other unattended environments, supply
GITHITS_API_TOKEN through the environment's secret manager.
Keychain Prompts and File Storage
GitHits uses the system keychain by default because OAuth credentials include a
refresh token. On macOS this means Keychain Access; on Windows it means
Credential Manager; on Linux it means the available Secret Service or keyring
backend.
If macOS shows a prompt such as "githits wants to access ... in your keychain",
choose Always Allow when you trust the installed githits CLI. GitHits
cannot customize that operating-system prompt; it is generated by macOS.
GitHits also writes a small non-secret metadata file so recent startup checks do
not need to read the keychain. The keychain is only read when GitHits needs the
token, for example during a tool call, token refresh, githits auth status, or a
login check after metadata is stale or expired.
If your agent keeps showing keychain prompts even after Always Allow, switch
OAuth storage to file mode:
toml
# macOS/Linux: ~/.config/githits/config.toml, or $XDG_CONFIG_HOME/githits/config.toml# Windows: %APPDATA%\githits\config.toml[auth]storage = "file"
The config directory may be empty until you create config.toml or GitHits
writes auth metadata. Older macOS installs may have used
~/Library/Application Support/githits; GitHits still reads that location for
migration, but new auth config and file storage use ~/.config/githits.
You can also opt in for one process:
sh
GITHITS_AUTH_STORAGE=file githits login --force
File mode stores OAuth credentials as JSON files under the GitHits config
directory. The files are written with private permissions where the platform
supports it, but they are not encrypted. Any process that can read files as your
operating-system user may be able to read the tokens.
Use file mode only on machines where you trust local user-account access. For CI
and automation, prefer GITHITS_API_TOKEN instead of browser OAuth.
Inspect auth and runtime state with:
sh
npx githits@latest auth status
npx githits@latest doctor
See the authentication docs for
keychain behavior, file storage mode, CI setup, and troubleshooting.
Manual MCP Setup
If your coding tool is not auto-configured by init, add GitHits to its MCP
configuration manually:
Your tool runs this command over stdio. No background daemon or global install
is required.
To remove configuration written by init:
sh
npx githits@latest uninstall
This removes GitHits MCP configuration and guidance written by init, while
preserving stored credentials. Run npx githits@latest logout separately to
remove credentials. The compatibility form npx githits@latest init uninstall
accepts the same --yes, --project, and --keep-guidance options.
Project Setup
For project-local MCP config, run:
sh
npx githits@latest init --project
Project setup is available only for tools with verified project-local MCP
support. Project config contains no secrets, but it may be committed like other
tooling configuration, so review generated files before adding them to source
control.
Agent-safe non-interactive setup uses staged discovery and explicit install:
The repository and published package provide the plugin and extension assets
used by compatible hosts. Git-based installs also retain the context-file
symlinks (CLAUDE.md and GEMINI.md) to the canonical AGENTS.md:
.plugin/plugin.json
.claude-plugin/plugin.json
.claude-plugin/marketplace.json
.codex-plugin/plugin.json
.cursor-plugin/plugin.json
.mcp.json
gemini-extension.json
plugin.json (Google Antigravity)
mcp_config.json (Google Antigravity)
AGENTS.md
CLAUDE.md
GEMINI.md
skills/
The root skill tree is shared by all supported hosts. Every plugin and extension
install uses the hosted remote MCP, including Claude, Codex, Cursor, Gemini CLI,
Google Antigravity, and VS Code/GitHub Copilot OpenPlugin. Direct githits init
setup is a separate path: it installs local stdio configurations for supported
tools except Cursor, which remains remote-only. The repository root is a native
Antigravity plugin through plugin.json, mcp_config.json, and the shared
skills/ tree. Generated manifests are refreshed with bun run plugins:generate
and validated with bun run plugins:check.
Guided init installs the four canonical skills (githits-code, githits-mcp,
githits-onboarding, and githits-package) only for selected agents. Shared
skill-capable agents use ~/.agents/skills/ at user scope or .agents/skills/
at project scope; native-only agents use their verified native skill directory.
Compatible agents reading a shared root can discover those skills. A later
guided run repairs missing skills, and migration removes only the historical
Cline or Junie githits-mcp/SKILL.md after the complete shared set is verified.
For Claude Code marketplace installs:
sh
claude plugin marketplace add githits-com/githits-cli
claude plugin install githits@githits-plugins
githits init Connect GitHits to your coding agents
githits uninstall Remove GitHits MCP configuration and guidance
githits init uninstall Compatibility alias for `githits uninstall`
githits login Sign in to your GitHits account
githits logout Remove stored credentials
githits mcp Show setup instructions or start the local MCP server
githits mcp start Always start the local MCP server over stdio
githits example Find real-world implementations from open source
githits languages List or filter supported programming languages
githits doctor Diagnose configuration and auth state
githits resolve Experimental: resolve a fuzzy name to canonical targets
githits settings View and update preferences, privacy, and terms
githits search Explore repository code, dependencies, docs, and symbols
githits search-status Check the status of a previous indexed search
githits code List, read, grep, or experimentally diff indexed source
githits pkg Inspect package metadata, vulnerabilities, deps, and changelogs
githits docs Browse and read package documentation
githits auth Manage authentication
githits auth status Show authentication status