How I connected an AI agent to GitHub with Nango and MCP (without touching a single OAuth token) published: false tags: ai, mcp, python, tutorial
Every time you connect an AI agent to an external API, you inherit the boring, risky part: OAuth flows, token storage, token refresh, and making sure nothing leaks. In this tutorial I built a small MCP server in Python that exposes GitHub to any MCP client, where my code never sees a GitHub token . Nango handles the auth. My server only knows a Nango secret key and a connection ID. Code:…
Connecting an AI agent to an external API often involves dealing with cumbersome OAuth flows, token storage, refresh mechanisms, and ensuring no leaks occur. This tutorial demonstrates how to create a small MCP server in Python that acts as an intermediary between any MCP client and GitHub, allowing the agent to access GitHub without ever handling a GitHub token. The auth process is handled by Nango. The code for this project can be found at https://github.com/sravya520/nango-github-mcp.
The MCP client interacts with three components: the MCP server (written in Python), the Nango proxy, and the GitHub API. The server exposes three tools: list_my_repos, list_open_issues, and create_issue. Step 1 involves connecting your GitHub account in Nango, which generates a connection ID. After that, Nango securely stores and refreshes the GitHub token for that specific connection.
When calling GitHub through Nango's proxy, three headers are sent: Authorization (Bearer secret key), Connection-Id, and Provider-Config-Key. A simple test of GET /user confirms the entire chain is functioning correctly. The server is implemented using the official MCP Python SDK, but a note to be aware that FastMCP was renamed to MCPServer in version 2.x of the SDK.
To make the agent's experience smoother, the docstring serves as the tool's instruction, allowing it to decide when to call the tool. The tool's output is capped at 20 items, and the list is read-only, preventing unintended modifications. Errors are handled more gracefully by raising a ToolError, which provides a readable message to the agent.
Tests were written to ensure the Nango headers, URL filtering, input validation, and error messages work as expected. The server should work with any MCP client since it adheres to standard MCP protocols. The tutorial's aim is to keep the agent side simple, with three tools and clear error messages, while Nango handles the complex OAuth and token management. The complete project, including code, tests, and setup instructions, is available at https://github.com/sravya520/nango-github-mcp.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.