Repository navigation
Unable to publish under GitHub organisation namespace despite organisation ownership #1468
Description
Activity
@premnathm Can you check your role using this curl call to verify? Note: You need correct scope for the token for this to work.
curl -H "Authorization: Bearer $GH_TOKEN" \ -H "Accept: application/vnd.github+json" \ https://api.github.com/orgs/ORG_NAME/memberships/YOUR_USERNAMEHi Team! Premnathm is the owner of the qatouch GitHub organization, so this isn't a case of missing organization permissions or a private membership. Refer to the screenshot
I verified that the organization is owned by the same GitHub account (premnathm) that's being used to publish. If there's anything else you'd like me to check (such as the namespace registration or publisher configuration), let me know and I'm happy to provide additional details.
@premnathm Can you verify this using the token as given in previous comment, it may happen that token scope is not correct. This is the token that you are using to publish the server.
I verified the organization membership using the GitHub API.
The authenticated account is premnathm, and the membership lookup returns:state: active
role: admin
direct_membership: true
So the account is an active organization owner/admin of the qatouch GitHub organization.
Given that, it appears the 403 Forbidden during publishing is not due to GitHub organization membership or permissions. The registry still reports that the authenticated account is only authorized to publish under io.github.premnathm/* and not io.github.qatouch/*.
Could you please check whether the io.github.qatouch namespace has been registered or mapped to the qatouch GitHub organization on the registry side? If there's any additional setup required to authorize publishing under the organization namespace, please let me know.@premnathm registry internally doesn't have any mapping, I will debug this further and report back. Thank you for the details!
I'm experiencing the same issue. I tried with
1.7.9and1.8.0and I reproduce it with both.Hi @premnathm, sorry for the confusion. You were right. This is a bug on our side, not an issue with your organisation permissions.
Since v1.8.0, we check that only organisation Owners can publish under an organisation namespace. The problem is that
mcp-publisher login githubuses a GitHub App token, which cannot see your organisation role (which makes it to work only for your personal namespace).That is why
io.github.qatouch/qatouchworked before July 13 and stopped after. Nothing changed on your side.We are working on a proper fix. For now, you can publish with:
mcp-publisher login github --token <YOUR_PAT> mcp-publisher publish
Use either a classic PAT with
read:org, or a fine-grained PAT with Organization → Members → Read-only. GitHub Actions publishing also works.@kdinev, the same workaround should work for you. The CLI version is not the issue.
Thanks to all for chiming in! 🙏
Reacted by Konstantin DinevThanks for the clarification! The workaround worked perfectly for us.
We'll use a PAT for now. Please let us know once the actual fix is available so we can switch back to the standard login flow.
Thanks for the quick investigation and update!georgii-borovinskikh-sonarsource commented
on Aug 4, 2026 More actionsHi. The workaround doesn't work for me
- I have public org membership
- I've tried using the fine-grained PAT owned by the correct org and Members Read-only permission - login is successful, publish returns 403
- I've tried using the classic token with
read:orgpermission and authorized it for the correct org - same as above
PS C:\Users\georgii.borovinskikh\Documents\Repos\sonarqube-mcp-server> .\mcp-publisher login github --token <redacted> Logging in with github... ✓ Successfully logged in PS C:\Users\georgii.borovinskikh\Documents\Repos\sonarqube-mcp-server> .\mcp-publisher publish Publishing to https://registry.modelcontextprotocol.io... Error: publish failed: server returned status 403: {"title":"Forbidden","status":403,"detail":"You do not have permission to publish this server. You have permission to publish: io.github.georgii-borovinskikh-sonarsource/*. Attempting to publish: io.github.SonarSource/sonarqube-mcp-server. If you're trying to publish to a GitHub organization, you may need to make your organization membership public in your GitHub settings: https://docs.github.com/en/account-and-profile/how-tos/organization-membership/publicizing-or-hiding-organization-membership"}PS C:\Users\georgii.borovinskikh\Documents\Repos\sonarqube-mcp-server> .\mcp-publisher --version 2026/08/04 16:22:45 mcp-publisher 1.8.0 (commit: d813d2b80552006e61a9e7f9f0562518d76cc85c, built: 2026-07-13T08:44:13Z)Reacted by Nicolas QUINQUENEL- added a commit that references this issue
on Aug 14, 2026 Adding a data point for @georgii-borovinskikh-sonarsource, since the workaround failing is the only thing still open on this thread.
The workaround works for us on
mcp-publisher 1.8.1(commitf52dc85, built 2026-08-06). The failing run above is on1.8.0built 2026-07-13, which predates it — worth re-trying on 1.8.1 before concluding the organisation configuration is at fault.What worked, publishing
io.github.loncadev/baronas an active Owner ofloncadev:mcp-publisher login github --token "$(gh auth token)" # scopes: gist, read:org, repo, workflow mcp-publisher publishTwo things that cost an afternoon here and might save someone else theirs:
- Plain
mcp-publisher login githubsucceeds and reports nothing wrong. It simply yields the personal namespace only, with no signal at login time that the org namespace was never evaluated. @rdimitrov's explanation above is what made it findable at all — without it the failure looks like a permissions problem on your own side, which is exactly where three of us went looking. - The 403's hint about making organisation membership public is misleading now that the check uses
GET /user/memberships/orgs, which explicitly includes private memberships. I made mine public on the strength of that message and it changed nothing — a visible change to a personal profile, made for no reason. Dropping that sentence would probably save more time than anything else short of the fix itself.
- Plain
We can reproduce this with an existing organization-owned Registry server.
Environment
- mcp-publisher: 1.8.1
- GitHub user: mozakaria123
- GitHub organization: TrigGuard-AI
- organization membership: active
- organization role: admin/Owner
- public membership endpoint:
GET /orgs/TrigGuard-AI/public_members/mozakaria123→ HTTP 204
Server:
io.github.TrigGuard-AI/trigguardThe organization namespace has previously worked. The Registry currently contains
io.github.TrigGuard-AI/trigguard@1.2.0(published 2026-08-20T00:59:06Z).We are attempting to publish validated 1.3.1 metadata. The corresponding npm artifact is already public:
@trigguard/mcp@1.3.1mcpName=io.github.TrigGuard-AI/trigguard
mcp-publisher validate server.jsonpasses.After
mcp-publisher logoutandmcp-publisher login github, interactive GitHub authentication succeeds, but publication returns:403 Forbidden You do not have permission to publish this server. You have permission to publish: io.github.mozakaria123/* Attempting to publish: io.github.TrigGuard-AI/trigguardGitHub independently confirms the user is an active Owner/admin and a public organization member (HTTP 204).
Expected: authenticated organization Owner authorized for
io.github.TrigGuard-AI/*Actual: only
io.github.mozakaria123/*is authorized.The existing 1.2.0 Registry record is additional evidence that the same organization namespace was previously publishable via interactive GitHub authentication (~22 minutes after npm
@trigguard/mcp-server@1.2.0on 2026-08-20).Happy to provide additional non-sensitive diagnostics if useful.
Reproduction update (2026-08-25) — public org membership does NOT resolve
Environment: macOS,
mcp-publisherGitHub device login (interactive)GitHub org membership:
- User:
mozakaria123 - Org:
TrigGuard-AI - Role:
admin, state:active - Public org membership: verified (
GET /orgs/TrigGuard-AI/public_members/mozakaria123→ 200) - Only public member listed on org
Steps:
mcp-publisher logout && mcp-publisher login github→ ✅ Successfully authenticatedmcp-publisher validate server.json→ ✅ validmcp-publisher publish server.jsonforio.github.TrigGuard-AI/trigguard@ 1.3.1
Result:
HTTP 403:You do not have permission to publish this server. You have permission to publish: io.github.mozakaria123/*. Attempting to publish: io.github.TrigGuard-AI/trigguard.
npm (already live):
@trigguard/mcp@1.3.1,mcpName=io.github.TrigGuard-AI/trigguardRegistry still shows:
io.github.TrigGuard-AI/trigguard@1.2.0(@trigguard/mcp-server)Conclusion: Org OAuth scope regression persists despite public org membership. Request restore of
io.github.TrigGuard-AI/*publish authorization for verified org admins.- User:
- added a commit that references this issue
on Sep 6, 2026 - added a commit that references this issue
on Oct 2, 2026 Root cause identified + working workaround posted on #1649. Short version: the device-flow GitHub App (
MCP Registry Login (Prod)) does not requestread:orgscope, so the token cannot see org memberships — even public ones. Workaround: exchange aread:org-scoped token directly viaPOST /v0/auth/github-at.
GitHub username:
premnathm
Organization:
qatouch
Namespace:
io.github.qatouch/qatouch
Repository:
https://github.com/qatouch/qatouch-mcp-server
Environment:
mcp-publisher 1.7.9
Validation:
mcp-publisher validate -> passes
Publishing:
mcp-publisher publish -> 403
Error:
You have permission to publish:
io.github.premnathm/*
Attempting to publish:
io.github.qatouch/qatouch
Additional information: