PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
You can connect an AI agent to GitHub through Nango’s hosted Model Context Protocol (MCP) server without putting GitHub’s OAuth token in the model’s conversation. OAuth authorization still happens, and your application still needs a credential to authenticate with Nango. The distinction is that Nango manages the provider credential while the agent calls the GitHub tools you make available.
This walkthrough follows Nango’s GitHub guide published June 17, 2026. It uses a GitHub App OAuth integration, a user-specific Nango connection, and typed tools served from https://api.nango.dev/mcp.
What “without touching an OAuth token” means
It means the model does not receive or handle the GitHub access token. A user still authorizes your application through OAuth, and your backend still authenticates with Nango using a Nango secret key or, in a separately configured session-based design, a session token. Nango’s authentication documentation says it manages provider credentials and refreshes; those are Nango’s product claims, not an independent security audit. See Nango’s authentication overview.
Instead of asking an agent to construct raw GitHub API requests or pass a provider token as a tool argument, you expose selected actions as typed MCP tools. Nango’s June 17 guide describes this as calling tools such as create-issue or add-issue-comment with typed inputs. Read the GitHub integration guide and the MCP documentation for the implementation details.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Set up the GitHub integration in Nango
-
Create a GitHub App OAuth integration in Nango. The guide uses the integration ID
github-app-oauthand the callback URLhttps://api.nango.dev/oauth/callback. Use the callback shown for your own integration if Nango’s current setup differs. -
Configure the GitHub App’s permissions and OAuth settings for the actions your agent needs. The guide’s test connection is authorized against a GitHub account with repository issues and pull requests.
-
Add a test connection in Nango, authorize it with a GitHub account, then build and test your integration against that connection. Nango’s GitHub catalog includes templates for commits, pull requests, and repositories; you can also build actions, syncs, or triggers for the connection. See the GitHub integration catalog.
Recommended: Update Every Outdated Driver on Your PC in One Scan - Free →Recommended: Fix Windows Errors and Clear Junk Files in Minutes - Free Scan →Recommended: Crashes or Glitches? A Free Driver Scan Usually Finds the Culprit →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
-
If you use GitHub webhooks, configure the GitHub App’s webhook URL with the URL shown in your Nango integration settings. Webhooks are a separate part of the setup from the hosted MCP connection.
Choose what the agent can do
Actions, syncs, and webhooks solve different problems. Select only the capabilities the application needs; adding every available tool expands what the agent can attempt.
| Capability | Purpose | Example from the GitHub guide |
|---|---|---|
| Actions | Let the agent perform an operation in GitHub through a tool call. | Create an issue or comment on a pull request. |
| Syncs | Import provider data so your application can work with a local, refreshed copy. | Sync issues and pull requests. |
| Webhooks | Deliver GitHub events to your integration when they occur. | Route configured GitHub webhook events into the integration. |
For an agent that only needs to perform user-requested operations, start with the necessary actions. Add syncs when your application needs a maintained local view of GitHub data, and webhooks when it needs event-driven updates.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Connect an MCP client to the right user connection
The hosted endpoint in Nango’s guide is https://api.nango.dev/mcp. The MCP request needs three pieces of information: a Nango credential, the provider config key, and the connection ID for the logged-in user. The guide uses the Nango secret key as a bearer credential and the provider config key github-app-oauth.
Recommended Free Tools
| Request value | Example or source | Keep it where? |
|---|---|---|
| MCP endpoint | https://api.nango.dev/mcp |
MCP client configuration. |
| Nango authentication | Nango secret key sent as a bearer credential in the guide’s request. | Backend or trusted client configuration; do not put the secret in model input. |
| Provider config key | github-app-oauth |
Connection configuration. |
| Connection ID | The Nango connection associated with the current application user. | Resolve it server-side after authenticating the user. |
The guide’s Codex example reads NANGO_SECRET_KEY from an environment variable and supplies the connection ID and provider config as HTTP headers. Follow the same security boundary in other MCP clients: keep the Nango credential out of prompts and model-visible tool arguments, and do not commit it to source control.
Resolve a connection per authenticated user
Do not hardcode the test connection ID in a multi-user application. Nango’s guide explicitly calls for fetching the connection for each logged-in user so each agent operates on that user’s repositories.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
-
Authenticate the person to your application.
-
On the backend, look up the Nango GitHub connection that belongs to that application user.
-
Verify the connection’s ownership before using its ID to configure or create the MCP client request.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Expose only the integration and tools required for the current task. Nango’s MCP documentation describes selecting which connections, integrations, and tools a session can access.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
This ownership check is essential: an MCP connection ID is not a substitute for your application’s user authorization. If your backend selects a connection without confirming its owner, an agent could act on the wrong GitHub account.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Keep provider credentials out of the model
Nango’s authentication page says credentials are encrypted at rest and in transit, with tenant isolation, and do not pass through the backend or agent. These are statements from Nango about its service. Your application still has to protect the Nango credential it uses to call the service, authenticate users before selecting their connections, and restrict available tools to the work the agent should perform.
- Provider token: Let Nango manage the GitHub OAuth credential and refresh flow; do not pass it as an MCP tool argument or include it in model context.
- Nango credential: Keep the secret key in trusted server-side configuration, such as an environment variable, rather than in prompts or user-visible output.
- Connection access: Select a connection only after authenticating the application user and verifying that connection belongs to them.
- Tool access: Allow only the actions and data access required for the task.
A separate Nango Agent Sessions tutorial dated September 18, 2026 demonstrates a pattern using a short-lived session restricted to a selected connection and read-only action; its example uses Gmail, not the GitHub configuration described here. It is a design reference, not a step in the GitHub guide. The tutorial’s author, Emmanuel Oyibo, Dev Relations at Nango, explains the concern this way: “Passing an OAuth token as a tool argument or result puts the credential in the model conversation.” See the Agent Sessions tutorial.
Troubleshoot authorization and tool failures
- Authentication fails: Check that the connection ID belongs to the user, the correct provider config key is supplied, and the Nango credential is valid. Nango’s GitHub guide identifies revoked installations and invalid refresh credentials as reasons a user may need to reconnect.
- A tool is unavailable: Confirm that the action was built, deployed, and enabled for the MCP access configuration, and that the request uses the intended integration and connection.
- Webhook events do not arrive: Check the GitHub App webhook URL against the URL shown in Nango’s integration settings, then inspect the relevant Nango logs.
- Inspect execution details: Use the action and sync logs in the Nango dashboard to investigate calls and data flows.
What the setup does—and does not—remove
This design removes the need for the model to handle GitHub’s OAuth token; it does not remove OAuth authorization, all credentials, or the need to secure your backend. The MCP client still needs to authenticate with Nango, and the application must choose the correct user connection and tool scope.
Nango’s 2026 authentication and MCP pages present a catalog of 1,000+ APIs; its MCP page presents 7,000+ ready-made tools. Its authentication page also advertises 99.9% uptime. These are Nango-published figures and a platform claim as presented in 2026, not independently verified measurements. The cited material does not establish a neutral performance comparison with other platforms.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

