{"slug": "how-to-connect-githits-mcp-to-coderabbit", "title": "How to connect GitHits MCP to CodeRabbit", "summary": "GitHits published a guide on October 5, 2026 detailing how to connect its MCP server to CodeRabbit so pull-request reviews can draw on open-source code and package data. The setup requires a GitHits personal token and a CodeRabbit custom MCP connection configured with the server URL https://mcp.githits.com, Streamable HTTP transport, and an Authorization header carrying a Bearer token, after which GitHits is added to the organization's Base Scope. The guide notes CodeRabbit's default MCP setting of auto disables MCP for public repositories, and that expired tokens are the likely cause when a previously working connection stops.", "body_md": "[Back to blog](https://githits.com/blog/)\n\nOctober 5, 2026 · 4 min read\n\n# How to connect GitHits MCP to CodeRabbit\n\nConnect GitHits MCP to CodeRabbit so reviews can draw on open-source code and package data.\n\nWhen a pull request touches a dependency, CodeRabbit can check how that library actually behaves, what changed between versions, and how other projects use the same API.\n\n## Before you start\n\nYou need a GitHits account and admin access to your CodeRabbit organization.\n\n## Part A: Create a GitHits token\n\n### 1. Open Account settings\n\nIn the GitHits dashboard, click your profile in the top-right corner, then click **Account settings**.\n\n### 2. Create a personal token\n\nClick **Personal tokens** and create a new token:\n\n- **Name** :`coderabbit`\n- **Expires** : Pick an expiry. It can’t be changed later.\n\nClick **Create token**.\n\n### 3. Copy the token\n\nCopy the token and store it somewhere safe. You can’t view it again after you close the dialog.\n\n## Part B: Connect GitHits MCP in CodeRabbit\n\n### 4. Add a custom connection\n\nIn CodeRabbit, click **Settings**, then **Connections**, then **Add connection**. Under **Custom**, choose **Custom**.\n\n### 5. Configure the MCP connection\n\nSelect the **MCP** tab, not **Direct connection**. Then fill in the form:\n\n| Field | Value | \n|---|---|\n| **Access mode** | **Read-only** | \n| **Server name** | `GitHits` | \n| **Server URL** | `https://mcp.githits.com` | \n| **Transport** | **Streamable HTTP** | \n| **Authentication** | **API token** | \n| **Auth header** | `Authorization` | \n| **API token** | `Bearer YOUR_GITHITS_TOKEN` | \n\nIn **API token**, type the word `Bearer`, a space, and then your token. Without the `Bearer` prefix and space, the connection fails.\n\nClick **Discover tools** to check the connection, then click **Save**. Leave **Add this to the Base Scope** unchecked if your organization has no Base Scope yet. You will add GitHits to one in the next step.\n\n### 6. Add GitHits to the Base Scope\n\nThe Base Scope makes GitHits available to reviews by default.\n\nGo to **Settings**, then **Scopes**, and click **Set up Base Scope**. Under **Connections**, check **GitHits** in **MCP servers**. Leave **Environment** set to **Standard CodeRabbit environment** and click **Save Base Scope**.\n\n## Troubleshooting\n\n- **Add this to the Base Scope shows an error.** No Base Scope exists yet. Save the connection without it, then follow step 6.\n- **Discover tools fails.** Check that the token starts with`Bearer` and a space. Use the eye icon to reveal the field.\n- **It worked before and stopped.** The token may have expired. Create a new one in GitHits and update the connection.\n- **GitHits is not used on a public repo.** CodeRabbit’s default MCP setting,`auto` , turns MCP off for public repositories. See the`.coderabbit.yaml` example below.\n\n## Examples\n\nCodeRabbit calls connected MCP tools on its own during reviews and in PR chat. Tools it used during a review are listed under “Additional context used” in the walkthrough. You can also ask for GitHits context directly by mentioning `@coderabbitai` in a PR comment.\n\n**Check how a library API behaves**\n\n@coderabbitai Use GitHits to check how pRetry in p-retry handles AbortError in the version this PR installs. Does our error handling match the source?\n\n**Review a dependency upgrade**\n\n@coderabbitai Use GitHits to review the upgrade from express 4.21.2 to 5.1.0. Summarize breaking changes from the changelog and any known vulnerabilities.\n\n**Vet a new dependency**\n\n@coderabbitai This PR adds drizzle-orm. Use GitHits to check its license, runtime dependencies, and known vulnerabilities.\n\n**Compare against how other projects do it**\n\n@coderabbitai Use GitHits to find how other open-source projects configure Hono middleware for auth, and tell me if our approach differs.\n\n**Ask for GitHits checks on every review**\n\nPath instructions in `.coderabbit.yaml` tell CodeRabbit what to focus on for matching files. Point them at your dependency manifests:\n\n```\nreviews:\n  path_instructions:\n    - path: \"**/package.json\"\n      instructions: |\n        When dependencies are added or upgraded, use GitHits to check the\n        changelog between versions, known vulnerabilities, and license.\n\nknowledge_base:\n  mcp:\n    usage: enabled\n```\n\n`usage: enabled` turns on MCP for all repositories, including public ones.", "url": "https://wpnews.pro/news/how-to-connect-githits-mcp-to-coderabbit", "canonical_source": "https://githits.com/blog/connect-githits-to-coderabbit/", "published_at": "2026-10-05 00:00:00+00:00", "updated_at": "2026-10-06 06:19:03.615759+00:00", "lang": "en", "topics": ["agent-protocols", "ai-tools", "developer-tools", "ai-agents"], "entities": ["GitHits", "CodeRabbit", "GitHits MCP", "p-retry", "express", "drizzle-orm", "Hono"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/how-to-connect-githits-mcp-to-coderabbit", "markdown": "https://wpnews.pro/news/how-to-connect-githits-mcp-to-coderabbit.md", "text": "https://wpnews.pro/news/how-to-connect-githits-mcp-to-coderabbit.txt", "jsonld": "https://wpnews.pro/news/how-to-connect-githits-mcp-to-coderabbit.jsonld"}}