Skip to content

I Keep getting permission denied for mcp servers using Claude Code GitHub Actions #647

Description

@Romarionijim

hello, I am trying to use claude code in github actions, as part of using it, we need to make use with mcp servers in the pipeline.

I keep getting that I need to provide permissions for the mcp servers, and there is no clear way in the docs how to do that in headless environment such as in GitHub actions, I tried a few ways but keep getting the same result at the end

is there a way to approve the mcp servers configured and auto approving them safely?

The mcp servers are configued, are logged, and they are up and running, so no issue on that side.

I HAVE ATTACHED THE WORKFLOW SNPPET, LOGS AND ERRORS AT THE END

I have tried a few ways trying to get a direction and workaround such as

- name: Setup MCP configuration
        shell: bash
        run: |
          # Create MCP config directory
          mkdir -p ~/.cursor
          cp .cursor/mcp.json ~/.cursor/mcp.json
          echo "MCP configuration copied to ~/.cursor/mcp.json"
          echo "MCP_CONFIG=$HOME/.cursor/mcp.json" >> $GITHUB_ENV
          cat $HOME/.cursor/mcp.json

      - name: Configure Claude MCP permissions
        run: |
          mkdir -p $HOME/.claude
          cat > $HOME/.claude/settings.json <<EOF
          {
            "permissions": {
              "allow": [
                "mcp__playwright__*",
                "mcp__context7__*",
                "mcp__github__*",
                "mcp__gcp__*",
                "mcp__atlassian__*"
              ],
              "deny": []
            },
            "permissionMode": "allowlist",
            "enableAllProjectMcpServers": true,
            "enabledMcpjsonServers": [
              "playwright",
              "context7",
              "github",
              "gcp",
              "atlassian"
            ]
          }
          EOF
        
      - uses: anthropics/claude-code-action@v1
        with:
          prompt: "please fetch jira ticket GROWDEV-22523 and display the ticket details and all the comments in it"
          settings: |
            {
              "permissions": {
                "allow": [
                  "mcp__playwright__*",
                  "mcp__context7__*",
                  "mcp__github__*",
                  "mcp__gcp__*",
                  "mcp__atlassian__*"
                ],
                "deny": []
              },
              "permissionMode": "allowlist",
              "enableAllProjectMcpServers": true,
              "enabledMcpjsonServers": [
                "playwright",
                "context7",
                "github",
                "gcp",
                "atlassian"
              ]
            }
          additional_permissions: |
            actions: read
          anthropic_api_key: ${{ secrets.GS_CLAUDE_API_KEY }}
          github_token: ${{ secrets.BOT_TOKEN }}
          claude_args: "--mcp-config ${{ env.MCP_CONFIG }} --model claude-sonnet-4-5-20250929 --max-turns 10"

the github actions logs:

✅ Installation complete!

Run # Run the base-action
Setting up Claude settings at: /home/runner/.claude/settings.json
Creating .claude directory...
Found existing settings: {
  "permissions": {
    "allow": [
      "mcp__*"
    ]
  },
  "enableAllProjectMcpServers": true
}
Processing settings input...
Parsed settings input as JSON
Merged settings with input settings
Updated settings with enableAllProjectMcpServers: true
Settings saved successfully
No marketplaces specified, skipping marketplace setup
No plugins specified, skipping plugins installation
Prompt file size: 96 bytes
Custom environment variables: GITHUB_ACTION_INPUTS
Custom Claude arguments: --mcp-config /home/runner/.cursor/mcp.json --model claude-sonnet-4-5-20250929 --max-turns 10
Running Claude with prompt from file: /home/runner/work/_temp/claude-prompts/claude-prompt.txt
Full command: claude -p --mcp-config /home/runner/.cursor/mcp.json --model claude-sonnet-4-5-20250929 --max-turns 10 --verbose --output-format stream-json
{
  "type": "system",
  "subtype": "init",
  "cwd": "/home/runner/work/gs-client/gs-client",
  "session_id": "28a88fef-c28c-4b98-b058-6fab9f34dd37",
  "tools": [
    "Task",
    "Bash",
    "Glob",
    "Grep",
    "ExitPlanMode",
    "Read",
    "Edit",
    "Write",
    "NotebookEdit",
    "WebFetch",
    "TodoWrite",
    "WebSearch",
    "BashOutput",
    "KillShell",
    "Skill",
    "SlashCommand",
    "mcp__playwright__browser_click",
    "mcp__playwright__browser_close",
    "mcp__playwright__browser_console_messages",
    "mcp__playwright__browser_drag",
    "mcp__playwright__browser_evaluate",
    "mcp__playwright__browser_file_upload",
    "mcp__playwright__browser_fill_form",
    "mcp__playwright__browser_handle_dialog",
    "mcp__playwright__browser_hover",
    "mcp__playwright__browser_install",
    "mcp__playwright__browser_navigate",
    "mcp__playwright__browser_navigate_back",
    "mcp__playwright__browser_network_requests",
    "mcp__playwright__browser_press_key",
    "mcp__playwright__browser_resize",
    "mcp__playwright__browser_select_option",
    "mcp__playwright__browser_snapshot",
    "mcp__playwright__browser_tabs",
    "mcp__playwright__browser_take_screenshot",
    "mcp__playwright__browser_type",
    "mcp__playwright__browser_wait_for",
    "ListMcpResourcesTool",
    "ReadMcpResourceTool",
    "mcp__context7__get-library-docs",
    "mcp__context7__resolve-library-id",
    "mcp__github__add_comment_to_pending_review",
    "mcp__github__add_issue_comment",
    "mcp__github__create_branch",
    "mcp__github__create_or_update_file",
    "mcp__github__create_pull_request",
    "mcp__github__create_repository",
    "mcp__github__delete_file",
    "mcp__github__get_commit",
    "mcp__github__get_file_contents",
    "mcp__github__get_label",
    "mcp__github__get_me",
    "mcp__github__get_release_by_tag",
    "mcp__github__get_tag",
    "mcp__github__get_team_members",
    "mcp__github__get_teams",
    "mcp__github__issue_read",
    "mcp__github__issue_write",
    "mcp__github__list_branches",
    "mcp__github__list_commits",
    "mcp__github__list_issue_types",
    "mcp__github__list_issues",
    "mcp__github__list_pull_requests",
    "mcp__github__list_releases",
    "mcp__github__list_tags",
    "mcp__github__pull_request_read",
    "mcp__github__pull_request_review_write",
    "mcp__github__push_files",
    "mcp__github__request_copilot_review",
    "mcp__github__search_code",
    "mcp__github__search_issues",
    "mcp__github__search_pull_requests",
    "mcp__github__search_repositories",
    "mcp__github__search_users",
    "mcp__github__sub_issue_write",
    "mcp__github__update_pull_request",
    "mcp__github__update_pull_request_branch",
    "mcp__atlassian__jira_add_comment",
    "mcp__atlassian__jira_add_worklog",
    "mcp__atlassian__jira_batch_create_issues",
    "mcp__atlassian__jira_batch_create_versions",
    "mcp__atlassian__jira_batch_get_changelogs",
    "mcp__atlassian__jira_create_issue",
    "mcp__atlassian__jira_create_issue_link",
    "mcp__atlassian__jira_create_remote_issue_link",
    "mcp__atlassian__jira_create_sprint",
    "mcp__atlassian__jira_create_version",
    "mcp__atlassian__jira_delete_issue",
    "mcp__atlassian__jira_download_attachments",
    "mcp__atlassian__jira_get_agile_boards",
    "mcp__atlassian__jira_get_all_projects",
    "mcp__atlassian__jira_get_board_issues",
    "mcp__atlassian__jira_get_issue",
    "mcp__atlassian__jira_get_link_types",
    "mcp__atlassian__jira_get_project_issues",
    "mcp__atlassian__jira_get_project_versions",
    "mcp__atlassian__jira_get_sprint_issues",
    "mcp__atlassian__jira_get_sprints_from_board",
    "mcp__atlassian__jira_get_transitions",
    "mcp__atlassian__jira_get_user_profile",
    "mcp__atlassian__jira_get_worklog",
    "mcp__atlassian__jira_link_to_epic",
    "mcp__atlassian__jira_remove_issue_link",
    "mcp__atlassian__jira_search",
    "mcp__atlassian__jira_search_fields",
    "mcp__atlassian__jira_transition_issue",
    "mcp__atlassian__jira_update_issue",
    "mcp__atlassian__jira_update_sprint",
    "mcp__gcp__get-billing-budget",
    "mcp__gcp__get-billing-info",
    "mcp__gcp__get-cost-forecast",
    "mcp__gcp__get-logs",
    "mcp__gcp__list-gke-clusters",
    "mcp__gcp__list-projects",
    "mcp__gcp__list-sql-instances",
    "mcp__gcp__run-gcp-code",
    "mcp__gcp__select-project"
  ],
  "mcp_servers": [
    {
      "name": "playwright",
      "status": "connected"
    },
    {
      "name": "context7",
      "status": "connected"
    },
    {
      "name": "github",
      "status": "connected"
    },
    {
      "name": "atlassian",
      "status": "connected"
    },
    {
      "name": "gcp",
      "status": "connected"
    }
  ],
  "model": "claude-sonnet-4-5-20250929",
  "permissionMode": "default",
  "slash_commands": [
    "compact",
    "context",
    "cost",
    "init",
    "output-style:new",
    "pr-comments",
    "release-notes",
    "todos",
    "review",
    "security-review",
    "mcp__github__AssignCodingAgent",
    "mcp__github__IssueToFixWorkflow"
  ],
  "apiKeySource": "ANTHROPIC_API_KEY",
  "claude_code_version": "2.0.28",
  "output_style": "default",
  "agents": [
    "general-purpose",
    "statusline-setup",
    "output-style-setup",
    "Explore",
    "Plan"
  ],
  "skills": [],
  "plugins": [],
  "uuid": "6607db81-32e9-4aad-a1f7-52dc2a59b574"
}
{
  "type": "assistant",
  "message": {
    "model": "claude-sonnet-4-5-20250929",
    "id": "msg_01NNAJsfdSD1TVSA5dVBK5px",
    "type": "message",
    "role": "assistant",
    "content": [
      {
        "type": "text",
        "text": "I'll fetch the Jira ticket GROWDEV-22523 and display its details along with all comments."
      }
    ],
    "stop_reason": null,
    "stop_sequence": null,
    "usage": {
      "input_tokens": 3,
      "cache_creation_input_tokens": 39124,
      "cache_read_input_tokens": 0,
      "cache_creation": {
        "ephemeral_5m_input_tokens": 39124,
        "ephemeral_1h_input_tokens": 0
      },
      "output_tokens": 3,
      "service_tier": "standard"
    }
  },
  "parent_tool_use_id": null,
  "session_id": "28a88fef-c28c-4b98-b058-6fab9f34dd37",
  "uuid": "c58c3c28-94da-46d0-882b-0f5aa807b297"
}
{
  "type": "assistant",
  "message": {
    "model": "claude-sonnet-4-5-20250929",
    "id": "msg_01NNAJsfdSD1TVSA5dVBK5px",
    "type": "message",
    "role": "assistant",
    "content": [
      {
        "type": "tool_use",
        "id": "toolu_01Mk9ZqzJksGQASJqoFNDzmM",
        "name": "mcp__atlassian__jira_get_issue",
        "input": {
          "issue_key": "GROWDEV-22523",
          "fields": "*all",
          "expand": "renderedFields",
          "comment_limit": 100
        }
      }
    ],
    "stop_reason": null,
    "stop_sequence": null,
    "usage": {
      "input_tokens": 3,
      "cache_creation_input_tokens": 39124,
      "cache_read_input_tokens": 0,
      "cache_creation": {
        "ephemeral_5m_input_tokens": 39124,
        "ephemeral_1h_input_tokens": 0
      },
      "output_tokens": 3,
      "service_tier": "standard"
    }
  },
  "parent_tool_use_id": null,
  "session_id": "28a88fef-c28c-4b98-b058-6fab9f34dd37",
  "uuid": "e07cac3b-57d6-4a09-be0b-dd7c8ee29f23"
}
{
  "type": "user",
  "message": {
    "role": "user",
    "content": [
      {
        "type": "tool_result",
        "content": "Claude requested permissions to use mcp__atlassian__jira_get_issue, but you haven't granted it yet.",
        "is_error": true,
        "tool_use_id": "toolu_01Mk9ZqzJksGQASJqoFNDzmM"
      }
    ]
  },
  "parent_tool_use_id": null,
  "session_id": "28a88fef-c28c-4b98-b058-6fab9f34dd37",
  "uuid": "7a882f16-4637-411e-a609-7cec84b90ce2"
}
{
  "type": "assistant",
  "message": {
    "model": "claude-sonnet-4-5-20250929",
    "id": "msg_01V4jfpJmyNk26eGy5YqyBer",
    "type": "message",
    "role": "assistant",
    "content": [
      {
        "type": "text",
        "text": "I need permission to access the Jira API. Please grant access to the Atlassian MCP server so I can fetch the ticket details for GROWDEV-22523."
      }
    ],
    "stop_reason": null,
    "stop_sequence": null,
    "usage": {
      "input_tokens": 7,
      "cache_creation_input_tokens": 193,
      "cache_read_input_tokens": 39124,
      "cache_creation": {
        "ephemeral_5m_input_tokens": 193,
        "ephemeral_1h_input_tokens": 0
      },
      "output_tokens": 1,
      "service_tier": "standard"
    }
  },
  "parent_tool_use_id": null,
  "session_id": "28a88fef-c28c-4b98-b058-6fab9f34dd37",
  "uuid": "5dbbb56b-7459-4edb-8381-afbbcf502105"
}
{
  "type": "result",
  "subtype": "success",
  "is_error": false,
  "duration_ms": 29660,
  "duration_api_ms": 53628,
  "num_turns": 4,
  "result": "I need permission to access the Jira API. Please grant access to the Atlassian MCP server so I can fetch the ticket details for GROWDEV-22523.",
  "session_id": "28a88fef-c28c-4b98-b058-6fab9f34dd37",
  "total_cost_usd": 0.16684794999999997,
  "usage": {
    "input_tokens": 10,
    "cache_creation_input_tokens": 39317,
    "cache_read_input_tokens": 39124,
    "output_tokens": 192,
    "server_tool_use": {
      "web_search_requests": 0
    },
    "service_tier": "standard",
    "cache_creation": {
      "ephemeral_1h_input_tokens": 0,
      "ephemeral_5m_input_tokens": 39317
    }
  },
  "modelUsage": {
    "claude-haiku-4-5-20251001": {
      "inputTokens": 491,
      "outputTokens": 148,
      "cacheReadInputTokens": 0,
      "cacheCreationInputTokens": 0,
      "webSearchRequests": 0,
      "costUSD": 0.0012309999999999999,
      "contextWindow": 200000
    },
    "claude-sonnet-4-5-20250929": {
      "inputTokens": 512,
      "outputTokens": 327,
      "cacheReadInputTokens": 39124,
      "cacheCreationInputTokens": 39317,
      "webSearchRequests": 0,
      "costUSD": 0.16561694999999999,
      "contextWindow": 200000
    }
  },
  "permission_denials": [
    {
      "tool_name": "mcp__atlassian__jira_get_issue",
      "tool_use_id": "toolu_01Mk9ZqzJksGQASJqoFNDzmM",
      "tool_input": {
        "issue_key": "GROWDEV-22523",
        "fields": "*all",
        "expand": "renderedFields",
        "comment_limit": 100
      }
    }
  ],
  "uuid": "899c6253-db7c-4001-8b47-3f1826435c45"
}
Log saved to /home/runner/work/_temp/claude-execution-output.json
Run # Try to format the turns, but if it fails, dump the raw JSON
Successfully formatted Claude Code report



the error that i get in the gh actions summary is


Claude Code Report
🚀 System Initialization
Available Tools: 117 tools loaded

I'll fetch the Jira ticket TICKET-22523 and display its details along with all comments.

Token usage: 39127 input, 3 output

🔧 mcp__atlassian__jira_get_issue
Parameters:

{
  "issue_key": "TICKET-22523",
  "fields": "*all",
  "expand": "renderedFields",
  "comment_limit": 100
}
❌ Error: Claude requested permissions to use mcp__atlassian__jira_get_issue, but you haven't granted it yet.

Token usage: 39127 input, 3 output

I need permission to access the Jira API. Please grant access to the Atlassian MCP server so I can fetch the ticket details for GROWDEV-22523.

Token usage: 39324 input, 1 output

✅ Final Result
I need permission to access the Jira API. Please grant access to the Atlassian MCP server so I can fetch the ticket details for GROWDEV-22523.

Cost: $0.1668 | Duration: 29.7s

I cannot list each and every tool that I wanna use in every mcp, how can I pre approve the mcp servers? I need this to work in order to achieve the goal that we are trying to make.

would appreciate for any help

i have tried this under .claude/settings.json

{
  "permissions": {
    "allow": [
      "Read",
      "Glob",
      "Grep",
      "Task",
      "mcp__playwright__*",
      "mcp__github__*",
      "mcp__gcp__*",
      "mcp__atlassian__*",
      "mcp__context7__*"
    ],
    "deny": [
      "Bash(command:rm -rf *)",
      "Bash(command:rm -rf/*)",
      "Bash(command:sudo *)",
      "Bash(command:chmod *)",
      "Bash(command:chown *)",
      "Write(file_path:**/.env*)",
      "Write(file_path:**/.ssh/**)",
      "Write(file_path:**/.aws/**)",
      "Write(file_path:**/.config/gcloud/**)",
      "Write(file_path:**/credentials*)",
      "Write(file_path:**/.zshrc*)",
      "Write(file_path:**/.bashrc*)",
      "Write(file_path:**/.bash_profile*)",
      "Write(file_path:**/.profile)",
      "Write(file_path:**/.zprofile)",
      "Write(file_path:**/.zshenv)",
      "Write(file_path:**/.bash_logout)",
      "Write(file_path:/etc/**)",
      "Write(file_path:/System/**)",
      "Write(file_path:/usr/bin/**)",
      "Write(file_path:/usr/sbin/**)",
      "Write(file_path:/bin/**)",
      "Write(file_path:/sbin/**)",
      "Edit(file_path:**/.env*)",
      "Edit(file_path:**/.ssh/**)",
      "Edit(file_path:**/.aws/**)",
      "Edit(file_path:**/.config/gcloud/**)",
      "Edit(file_path:**/credentials*)",
      "Edit(file_path:**/.zshrc*)",
      "Edit(file_path:**/.bashrc*)",
      "Edit(file_path:**/.bash_profile*)",
      "Edit(file_path:**/.profile)",
      "Edit(file_path:**/.zprofile)",
      "Edit(file_path:**/.zshenv)",
      "Edit(file_path:**/.bash_logout)",
      "Edit(file_path:/etc/**)",
      "Edit(file_path:/System/**)",
      "Edit(file_path:/usr/bin/**)",
      "Edit(file_path:/usr/sbin/**)",
      "Edit(file_path:/bin/**)",
      "Edit(file_path:/sbin/**)"
    ],
    "ask": [
      "Bash",
      "Write",
      "Edit"
    ]
  },
  "sandbox": {
    "enabled": true,
    "autoAllowBashIfSandboxed": false,
    "excludedCommands": [],
    "network": {
      "allowLocalBinding": true
    }
  },
  "enabledMcpjsonServers": [
    "playwright",
    "context7",
    "github",
    "gcp",
    "atlassian"
  ],
  "deniedMcpServers": []
}


Metadata

Metadata

Assignees

No one assigned

    Labels

    area:permissionsbugSomething isn't workingdocumentationImprovements or additions to documentationmcpp2Non-showstopper bug or popular feature request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions