Skip to content

Cannot search enterprise MCP registry, shows only public catalog results #4999

Description

@rpstester

Describe the bug

Copilot CLI does not show servers from our configured enterprise MCP registry in /mcp search. From a non-Git working directory, the Online tab loads public MCP results, but searching for example-mcp-server does not return our internal server. /mcp search example likewise does not show it.

A few releases ago, I was able to query the enterprise registry via the CLI. After some time of not trying it, I noticed it stopped working.

The enterprise registry policy is fetched successfully and identifies our registry with registry_access: allow_all. The registry responds to GET https://mcp-registry.example.com/v0.1/servers?limit=30 with HTTP 200 and 23 servers, including an active, latest example-mcp-server. VS Code can read the same registry.

GitHub's MCP private registry enforcement documentation lists Registry display as supported in Copilot CLI. A maintainer also described /mcp search <query> as showing servers available in the configured registry in #3436. Is the CLI expected to include enterprise-registry results when the policy is allow_all? If not, how should users browse their configured registry without changing the enterprise-wide access policy?

Affected version

GitHub Copilot CLI 1.0.89 on Windows 11

Steps to reproduce the behavior

  1. Configure an enterprise MCP Registry URL pointing to a working v0.1 registry.
  2. In GitHub policy, set Restrict MCP access to registry servers to Allow all.
  3. Start a fresh Copilot CLI process outside any Git repository, for example, from $HOME.
  4. Run /mcp, select Online tab, and search for an internal-only server like example-mcp-server.
  5. Also try /mcp search example.

Current behavior: The Online view shows public MCP catalog results but not example-mcp-server. /mcp search example also does not find the server (that is on the internal registry).

Expected behavior

From the Copilot CLI, the internal example-mcp-server appears in search results and can be inspected or installed from the configured enterprise registry. Public results may also appear if Allow all is intended to include both sources.

Additional context

  • GET https://api.github.com/copilot/mcp_registry returns HTTP 200 and the expected registry URL with registry_access: allow_all. CLI startup logs independently report that the registry “permits all servers (allow_all).”
  • In a local TLS pass-through test recording destination hostnames only, the search connected to api.mcp.github.com; no connection to mcp-registry.example.com was observed through the proxy. This does not rule out a GitHub backend fetching the registry or a request bypassing the proxy.
  • This is separate from /mcp search fails with 400 Bad Request in every repo with a non-GitHub (Azure DevOps) git remote #4374: starting CLI inside our Azure DevOps Git repositories causes a 400 while loading registry policy. Starting outside a directory with Git avoids that error but does not make internal servers appear in search.
  • Our enterprise also uses server-managed allowedMcpServers (allowedMcpServers entries using serverName never match #4989). This report concerns discovery/search, not whether an installed server is permitted to start.
  • We have not changed the policy to Registry only as a test because that changes server-use permissions enterprise-wide, not just the search view.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions