Direct answer: Finta's Aurora catalog includes GitLab's MCP endpoint at https://gitlab.com/api/v4/mcp with dynamic OAuth. GitLab documents a beta MCP server that can expose authorized project, issue, merge-request, and API context, subject to instance, Duo, role, and OAuth configuration.
This guide is for teams using Finta as relationship intelligence around a capital, investor, customer, or company-building workflow. GitLab remains the source system for its records. Aurora can use only the context and actions exposed to the connected account.
How the GitLab connection works
| Connection detail | Current Finta guidance |
|---|---|
| Classification | Catalog MCP |
| Configured endpoint | https://gitlab.com/api/v4/mcp |
| Authentication and transport | Provider OAuth through Aurora; Streamable HTTP |
| Source of truth | GitLab remains authoritative for provider records, permissions, and action results. |
| Human control | Review external communication, record changes, financial actions, publishing, deletion, and other consequential work before execution. |
What you can use it for
- Search or read authorized GitLab projects, issues, and merge requests.
- Inspect source-linked development status for a defined product milestone.
- Prepare issue or merge-request updates for owner review.
- Use supported GitLab API operations only within the authenticated user's role and scopes.
These uses summarize the current provider documentation and Finta catalog purpose. The exact tool inventory varies by provider version, plan, workspace, user permissions, region, and authorization scopes.
Relationship intelligence workflows for GitLab
Prepare a diligence-ready release summary
Outcome: Have the engineering owner approve any external statement.
- Find the milestone's issues, merge requests, pipelines, and release references.
- Separate completed, open, and blocked work.
- Draft a source-linked summary that preserves uncertainty.
- Have the engineering owner approve any external statement.
Human decision: GitLab artifacts show engineering state, not customer adoption, revenue, or production reliability unless separate evidence supports those claims.
Route investor product feedback
Outcome: Create or update the work item only after approval.
- Check whether the feedback already maps to an issue or epic.
- Prepare a concise issue with the non-confidential context and source meeting reference.
- Ask the product owner to approve labels, assignment, and priority.
- Create or update the work item only after approval.
Human decision: Do not copy private investor conversations, sensitive roadmap commitments, or personal data into GitLab without permission.
How to connect GitLab to Aurora
- Confirm the target GitLab environment meets GitLab's current MCP beta prerequisites.
- In Aurora, open Apps and select GitLab.
- Authorize https://gitlab.com/api/v4/mcp with the intended GitLab identity.
- Review OAuth scopes, project visibility, and organization policies.
- Run a read-only project or issue lookup before any write test.
Open the official Finta apps directory to confirm the catalog entry before authorizing a provider account.
Permissions and approval boundary
GitLab access follows the user's role, OAuth scopes, and instance controls. Keep initial access read-only. Require approval before issue, comment, merge-request, branch, pipeline, or settings changes, and keep private source and security details within the authorized audience.
Limitations to understand
- GitLab's MCP server is beta and prerequisite settings can differ across GitLab.com, Self-Managed, and Dedicated.
- GitLab Duo availability, beta enablement, OAuth application settings, or admin policy may block connection.
- The catalog endpoint targets GitLab.com and does not by itself configure a self-managed instance.
- Available API operations are limited by role, scope, and server version.
Verification checklist
- Confirm the target GitLab environment, beta prerequisites, endpoint, and OAuth flow.
- Capture the authorized projects, scopes, and Aurora-discovered tools.
- Run a safe read-only issue or merge-request lookup and retain the receipt.
- Perform one controlled test issue action after approval and verify it in GitLab.
- Record instance type, Duo requirements, admin restrictions, and verification date.
Verification status: On 2026-08-22, Finta confirmed that this connector appears in the enabled production Aurora catalog and reviewed the configured endpoint, authentication type, and first-party sources listed below. This is not a claim that every provider tool or an authenticated end-to-end action has been tested for every account.
