<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Sravya Dangeti</title>
    <description>The latest articles on DEV Community by Sravya Dangeti (@sravya_dangeti).</description>
    <link>https://dev.to/sravya_dangeti</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3270311%2Fb3744650-227f-4fe3-8207-ea92e54289ac.png</url>
      <title>DEV Community: Sravya Dangeti</title>
      <link>https://dev.to/sravya_dangeti</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/sravya_dangeti"/>
    <language>en</language>
    <item>
      <title>How I connected an AI agent to GitHub with Nango and MCP (without touching a single OAuth token) published: false tags: ai, mcp, python, tutorial</title>
      <dc:creator>Sravya Dangeti</dc:creator>
      <pubDate>Mon, 28 Sep 2026 16:16:28 +0000</pubDate>
      <link>https://dev.to/sravya_dangeti/how-i-connected-an-ai-agent-to-github-with-nango-and-mcp-without-touching-a-single-oauth-token-14j1</link>
      <guid>https://dev.to/sravya_dangeti/how-i-connected-an-ai-agent-to-github-with-nango-and-mcp-without-touching-a-single-oauth-token-14j1</guid>
      <description>&lt;p&gt;Every time you connect an AI agent to an external API, you inherit the boring, risky part: OAuth flows, token storage, token refresh, and making sure nothing leaks.&lt;/p&gt;

&lt;p&gt;In this tutorial I built a small MCP server in Python that exposes GitHub to any MCP client, where &lt;strong&gt;my code never sees a GitHub token&lt;/strong&gt;. Nango handles the auth. My server only knows a Nango secret key and a connection ID.&lt;/p&gt;

&lt;p&gt;Code: &lt;a href="https://github.com/sravya520/nango-github-mcp" rel="noopener noreferrer"&gt;https://github.com/sravya520/nango-github-mcp&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  How it works
&lt;/h2&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;MCP client  -&amp;gt;  my MCP server (Python)  -&amp;gt;  Nango proxy (adds GitHub auth)  -&amp;gt;  GitHub API
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;The server exposes three tools:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;What it does&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;list_my_repos&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Lists my repos, most recently updated first&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;list_open_issues&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Lists open issues in a repo (skips pull requests)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;create_issue&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Creates an issue in a repo&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Step 1: Connect GitHub in Nango
&lt;/h2&gt;

&lt;p&gt;Nango's getting-started flow creates a GitHub integration (&lt;code&gt;github-getting-started&lt;/code&gt;) and has you authorize your GitHub account. That gives you a &lt;strong&gt;connection ID&lt;/strong&gt;. From then on, Nango stores and refreshes the GitHub token for that connection.&lt;/p&gt;

&lt;p&gt;Put your values in a &lt;code&gt;.env&lt;/code&gt; file and add &lt;code&gt;.env&lt;/code&gt; to &lt;code&gt;.gitignore&lt;/code&gt;:&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;NANGO_SECRET_KEY=your-secret-key
NANGO_CONNECTION_ID=your-connection-id
NANGO_PROVIDER_CONFIG_KEY=github-getting-started
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;
&lt;h2&gt;
  
  
  Step 2: Call GitHub through Nango's proxy
&lt;/h2&gt;

&lt;p&gt;Instead of calling &lt;code&gt;api.github.com&lt;/code&gt; with a token, you call Nango's proxy with three headers. Nango finds the connection, adds the GitHub token and forwards the request.&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;def nango_request(method, endpoint, params=None, json=None):
    headers = {
        "Authorization": f"Bearer {os.getenv('NANGO_SECRET_KEY')}",
        "Connection-Id": os.getenv("NANGO_CONNECTION_ID"),
        "Provider-Config-Key": os.getenv("NANGO_PROVIDER_CONFIG_KEY"),
    }
    response = httpx.request(
        method, f"https://api.nango.dev/proxy{endpoint}",
        headers=headers, params=params, json=json, timeout=20,
    )
    ...
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;A one-line smoke test (&lt;code&gt;GET /user&lt;/code&gt;) confirms the whole chain works:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fckhbqoqm4m9mgrtguum6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fckhbqoqm4m9mgrtguum6.png" alt="Smoke test: connected to GitHub as sravya520" width="798" height="238"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 3: Turn the calls into MCP tools
&lt;/h2&gt;

&lt;p&gt;I used the official MCP Python SDK. One thing that caught me out: in &lt;strong&gt;version 2.x, &lt;code&gt;FastMCP&lt;/code&gt; was renamed to &lt;code&gt;MCPServer&lt;/code&gt;&lt;/strong&gt;, so older tutorials fail on import.&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;from mcp.server.mcpserver import MCPServer

mcp = MCPServer("github-via-nango")

@mcp.tool(annotations=READ_ONLY)
def list_my_repos(limit: int = 10) -&amp;gt; list[dict]:
    """List the user's GitHub repositories, most recently updated first.
    Use this first to find a repo's full name (owner/name)."""
    repos = nango_request("GET", "/user/repos",
                          params={"sort": "updated", "per_page": _clamp(limit)})
    return [{"full_name": r["full_name"], "url": r["html_url"]} for r in repos]
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;Three small choices make agents behave better:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;The docstring is the instruction.&lt;/strong&gt; The agent reads it to decide when to call the tool. "Use this first to find a repo's full name" helps it chain tools in the right order.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Small results.&lt;/strong&gt; Lists are capped at 20 items so the agent's context stays small.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tool annotations.&lt;/strong&gt; Read tools are marked read-only and &lt;code&gt;create_issue&lt;/code&gt; is not, so clients can treat writes more carefully.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Step 4: Make errors readable for the agent
&lt;/h2&gt;

&lt;p&gt;This was my biggest lesson. In the MCP SDK, if a tool raises a normal Python exception, the agent only sees &lt;strong&gt;"Error executing tool"&lt;/strong&gt;. It has no idea what went wrong.&lt;/p&gt;

&lt;p&gt;Only errors raised as &lt;code&gt;ToolError&lt;/code&gt; pass their message through. So my error class extends it:&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;from mcp.server.mcpserver.exceptions import ToolError

class NangoError(ToolError):
    """A readable error the agent can show to the user."""
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;Now a bad repo name produces an answer the agent can act on (see the screenshot in the next step). I wrote a test that locks this in, plus seven others covering the Nango headers and URL, filtering out pull requests, input validation and error messages.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 5: Test it over real MCP
&lt;/h2&gt;

&lt;p&gt;VS Code is an MCP host. When I added the server, it started it and showed it as Running, with all three tools:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftho2b5yv5xlokhp0rzj2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftho2b5yv5xlokhp0rzj2.png" alt="VS Code showing github-via-nango Running" width="767" height="100"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;To test the protocol directly, I wrote a small Python client (&lt;code&gt;client_demo.py&lt;/code&gt; in the repo). It launches the server over stdio, lists the tools, and calls them the way an agent would:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0xl7ggb1auxeuh1lbykk.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0xl7ggb1auxeuh1lbykk.png" alt="client_demo.py: tools listed and repos returned" width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;And the error case, where the message comes through clearly:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Foxqaytatjkxbm0pd6jo4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Foxqaytatjkxbm0pd6jo4.png" alt="client_demo.py: readable error for a bad repo name" width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What I tested, and what I didn't:&lt;/strong&gt; &lt;code&gt;list_my_repos&lt;/code&gt; ran live over MCP, through Nango to GitHub, and the bad-repo error came back over MCP too. &lt;code&gt;list_open_issues&lt;/code&gt; and &lt;code&gt;create_issue&lt;/code&gt; are covered by the unit tests, but I did not run them against my live account.&lt;/p&gt;

&lt;h2&gt;
  
  
  Problems I hit (so you don't have to)
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;401 Unauthorized from Nango.&lt;/strong&gt; Nango has separate environments, each with its own secret key, so copy the key from the environment where your connection lives. Also check your &lt;code&gt;.env&lt;/code&gt; for stray lines: &lt;code&gt;python-dotenv&lt;/code&gt; warned me about a parse error on line 4.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;"Command not found" in the VS Code MCP setup.&lt;/strong&gt; &lt;code&gt;command&lt;/code&gt; is the program that runs the server (Python). The server file goes in &lt;code&gt;args&lt;/code&gt;. I had typed the server's name into &lt;code&gt;command&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Wiring an AI client is the fiddly part.&lt;/strong&gt; Copilot's agent mode was out of quota, and Claude Code's panel did not pick up my server even though &lt;code&gt;claude mcp list&lt;/code&gt; showed it connected. Rather than keep debugging, I tested with the script above. Because the server speaks standard MCP, it should work with any MCP client.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Why I like this approach
&lt;/h2&gt;

&lt;p&gt;The agent side stays simple: three small tools and clear errors. All the hard auth work (OAuth, storage, refresh) lives in Nango. Adding another API like Notion or Slack would mostly mean a new integration in Nango and a few more tools, not a new auth system.&lt;/p&gt;

&lt;p&gt;Code, tests and setup: &lt;a href="https://github.com/sravya520/nango-github-mcp" rel="noopener noreferrer"&gt;https://github.com/sravya520/nango-github-mcp&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>mcp</category>
      <category>python</category>
      <category>tutorial</category>
    </item>
  </channel>
</rss>
