Direct answer: Finta's Aurora catalog lists GitHub's remote MCP endpoint at https://api.githubcopilot.com/mcp/ using bearer authentication. GitHub documents configurable toolsets for repositories, issues, pull requests, users, Actions, and security, with the available surface determined by token scopes and server configuration.
This guide is for teams using Finta as relationship intelligence around a capital, investor, customer, or company-building workflow. GitHub remains the source system for its records. Aurora can use only the context and actions exposed to the connected account.
How the GitHub connection works
| Connection detail | Current Finta guidance |
|---|---|
| Classification | Catalog MCP |
| Configured endpoint | https://api.githubcopilot.com/mcp/ |
| Authentication and transport | User-supplied bearer or personal access token; Streamable HTTP |
| Source of truth | GitHub remains authoritative for provider records, permissions, and action results. |
| Human control | Review external communication, record changes, financial actions, publishing, deletion, and other consequential work before execution. |
What you can use it for
- Search and read authorized repository content, issues, pull requests, and user context.
- Inspect release, Actions, and security context when the relevant toolsets and scopes are enabled.
- Prepare issue or pull-request updates for review before a write tool is used.
- Operate in GitHub's documented read-only mode for research and diligence tasks.
- Restrict the exposed surface by selecting only the toolsets needed for the workflow.
These uses summarize the current provider documentation and Finta catalog purpose. The exact tool inventory varies by provider version, plan, workspace, user permissions, region, and authorization scopes.
Relationship intelligence workflows for GitHub
Verify a product milestone before an investor update
Outcome: Have the product owner approve the investor-facing wording.
- Find the relevant release, pull request, issue, and deployment evidence.
- Separate merged work from open or blocked work.
- Prepare a source-linked milestone summary with explicit unknowns.
- Have the product owner approve the investor-facing wording.
Human decision: Repository state supports a claim, but it does not prove production adoption, customer value, or financial impact.
Track a technical diligence request
Outcome: Create or update the issue only after the engineering owner approves it.
- Search existing issues and documentation for the diligence question.
- Identify the repository owner and any security-sensitive material.
- Prepare a narrowly scoped issue or response with source links.
- Create or update the issue only after the engineering owner approves it.
Human decision: Never expose secrets, private code, vulnerability details, or customer data to an unauthorized audience.
How to connect GitHub to Aurora
- In Aurora, open Apps and select GitHub.
- Provide the approved bearer credential for https://api.githubcopilot.com/mcp/ using the catalog connection flow.
- Grant only the repositories, organizations, and scopes needed for the intended workflow.
- Confirm the discovered GitHub toolsets in Aurora.
- Begin with a read-only repository or issue search against a controlled test target.
Open the official Finta apps directory to confirm the catalog entry before authorizing a provider account.
Permissions and approval boundary
Use a least-privilege GitHub credential and prefer read-only toolsets. Require explicit owner approval before creating or editing issues, comments, branches, pull requests, releases, workflows, or security settings. Treat private repository content and security findings as confidential.
Limitations to understand
- The Finta catalog specifies bearer authentication even though GitHub supports other authentication patterns in some MCP clients.
- Available tools depend on enabled toolsets, token scopes, repository policies, and organization controls.
- Code search and repository status can be incomplete outside the authorized scope.
- A merged pull request does not prove a production deployment or business outcome.
Verification checklist
- Reconcile the catalog bearer flow with GitHub's current remote MCP authentication guidance.
- Capture endpoint, token scopes, repository scope, read-only setting, and discovered toolsets.
- Run a safe read-only repository or issue search and retain the receipt.
- Perform one controlled test issue action only after human approval and verify the audit trail.
- Record organization restrictions, unsupported toolsets, and verification date before publication.
Verification status: On 2026-08-22, Finta confirmed that this connector appears in the enabled production Aurora catalog and reviewed the configured endpoint, authentication type, and first-party sources listed below. This is not a claim that every provider tool or an authenticated end-to-end action has been tested for every account.
Official provider sources
- GitHub official MCP documentation (docs.github.com)
- GitHub official MCP documentation 2 (github.com)
- GitHub official MCP documentation 3 (github.com)
