GitHub Enterprise Server
Connect a self-hosted GitHub Enterprise Server instance so your team gets cloud sessions, Code Review and internal plugin marketplaces on GHES repositories.
If your code lives on a self-managed GitHub Enterprise Server (GHES) instance rather than github.com, an Owner can connect that instance to your Claude organisation once. After that, developers use cloud sessions, Code Review and the rest exactly as they would on github.com, with no per-repository setup. Internal plugin marketplaces hosted on GHES work too, though how credentials flow depends on where you add them.
Note: GHES support is for Team and Enterprise plans.
Feature support
| Feature | On GHES | Notes |
|---|---|---|
| Cloud sessions | Yes | claude --cloud and claude.ai/code work once the instance is connected |
| Code Review | Yes | Same reviews as github.com |
| Claude Security (managed) | Yes | Public beta on Enterprise |
| Teleport | Yes | --teleport between cloud and terminal |
| Plugin marketplaces | Yes | Credentials differ per surface; see below |
| Contribution metrics | Yes | Delivered via webhooks to analytics |
| GitHub Actions | Yes | Manual workflow setup; /install-github-app is github.com only |
| GitHub MCP server | No | Use gh pointed at your GHES host instead |
Connecting the instance (Owners)
You need the Owner or Primary Owner role in Claude and permission to create GitHub Apps on the GHES instance. The guided flow builds a GitHub App manifest and bounces you to GHES to create the app in one click.
- On claude.ai, open Organization settings > Git providers and find GitHub Enterprise.
- Click Connect (or Add instance if one is already connected) and choose Set up automatically.
- Enter a display name (20 characters max) and the hostname, e.g.
git.northwind.internal. If the instance uses a private or self-signed CA, paste the CA certificate into the optional field. - Click Continue to GitHub Enterprise, review the pre-filled manifest on GHES and click Create GitHub App. You are sent back to Claude with the credentials stored.
- From the app's page on GHES, install it on the organisations or repositories Claude should reach. Start small if you like.
- In the Claude Code admin settings, enable Code Review and contribution metrics for GHES repositories, configured the same way as for github.com.
Permissions the app asks for
| Permission | Access | Why |
|---|---|---|
| Contents | Read and write | Clone and push branches |
| Pull requests | Read and write | Open PRs, post review comments |
| Issues | Read and write | Respond to issue mentions |
| Checks | Read and write | Post Code Review check runs |
| Actions | Read | CI status for auto-fix |
| Commit statuses | Read | CI status from tools that use statuses rather than checks |
| Repository hooks | Read and write | Create a webhook on a marketplace repo when Sync automatically is on in Organization settings > Plugins & skills |
| Metadata | Read | Required for every GitHub App |
| Organization members | Read | Parity with the github.com app, which checks a user's org role when linking an installation |
Webhook events: pull_request, issue_comment, pull_request_review_comment, pull_request_review, check_run, status.
GitHub only applies a manifest when the app is created. An app made from an older manifest keeps its original permissions and events, so if anything above is missing, add it in the app's settings on GHES. Installation owners then have to approve the new permissions, and old ones stay in force until they do.
When the redirect is blocked
Choose Add manually instead. Create a GitHub App on GHES yourself with the permissions and events above, then fill in the form:
- display name;
- hostname and optional port;
- app ID, client ID, client secret, webhook secret and private key;
- optional custom CA certificate and read replica hostnames.
Click Add configuration. Claude generates the webhook URL on save: open the connection's More options menu, choose Copy webhook URL, and paste it into the app's webhook settings on GHES with the same webhook secret.
Network reachability
For Anthropic-hosted sessions and reviews, Anthropic's infrastructure must be able to reach your GHES instance to clone and comment. Behind a firewall, allowlist Anthropic's published outbound IP ranges.
Sessions in a self-hosted environment clone from inside your own network, unless the runner opts into the Anthropic git proxy, which fetches from Anthropic's side and needs the same reachability. Hosted pre-session flows such as the repository picker always run on Anthropic's side, and the SCM connector is not available for them, so they cannot reach a GHES host that is only routable internally. See self-hosted environment deployment.
For developers
Nothing to configure. Claude Code reads the GHES hostname from your git remote and routes to the connected instance:
git clone https://git.northwind.internal/payments/ledger.git
cd ledger
claude --cloud "Make the nightly reconciliation job idempotent and add a regression test"
The session clones from GHES and pushes a branch back. Follow it at claude.ai/code. Pull it into your terminal with claude --teleport, which checks you are in a checkout of the same GHES repository first; see teleporting.
Plugin marketplaces on GHES
The marketplace format is the same as on github.com (see creating a marketplace). What differs is who fetches it and with whose credentials:
| Where it is added | Who fetches it | What each user needs |
|---|---|---|
| CLI or desktop app | The user's machine, with its own git credentials | Git access to GHES from that machine |
Managed settings (extraKnownMarketplaces) | The user's machine, with its own git credentials | Git access to GHES from that machine |
| claude.ai organisation plugin settings | Anthropic's backend, via the GHES GitHub App | Nothing. The Owner adding it must have their own GHES account connected, and the app must be installed on the marketplace repo |
| claude.ai user settings | Anthropic's backend, via that user's GHES connection | Their own GHES account connected to Claude |
| Inside a cloud session | The session sandbox | Unreliable: only reachable if the session's repo is on the same instance, and credentials are scoped to the session's repos. Use another route |
Warning: Connecting the GHES instance to the organisation does not connect individual people's accounts. Anyone adding a GHES marketplace from their own settings must first connect their own GitHub Enterprise account; nobody else's connection, including the Owner's, counts for them. Marketplaces added by an Owner at organisation level avoid this.
Adding one from the CLI
The owner/repo shorthand always means github.com, so use a full URL. HTTPS is the safer choice:
/plugin marketplace add https://git.northwind.internal/devex/claude-plugins.git
SSH works if the machine already trusts the host:
/plugin marketplace add git@git.northwind.internal:devex/claude-plugins.git
Claude Code runs git non-interactively and refuses SSH hosts missing from known_hosts. HTTPS with a credential helper sidesteps that.
Pre-registering for everyone
extraKnownMarketplaces registers a marketplace automatically. It works in any settings file, including a repository's .claude/settings.json; via managed settings it reaches the whole organisation:
{
"extraKnownMarketplaces": {
"northwind-devex": {
"source": {
"source": "git",
"url": "https://git.northwind.internal/devex/claude-plugins.git"
}
}
}
}
This installs locally with the machine's git credentials, not through claude.ai, so no per-user GHES connection is needed. To make the rollout stick:
- use a full git URL;
- prefer HTTPS with your standard credential helper;
- check every machine can clone from GHES (if not, the marketplace registers but never installs, and its plugins show as not found rather than prompting);
- check the settings file actually reaches each machine via your device management. See managed settings.
Allowing GHES under a marketplace allowlist
If you lock down marketplace sources with strictKnownMarketplaces, allow your whole instance with a hostPattern entry rather than listing every repo:
{
"strictKnownMarketplaces": [
{ "source": "hostPattern", "hostPattern": "^git\\.northwind\\.internal$" }
]
}
Put it in managed-settings.json or the equivalent MDM policy. Both keys are documented in the settings reference.
Workarounds for the gaps
-
No
/install-github-app: use the admin setup above. For Actions workflows on GHES, adapt the action repository'sexamples/claude.ymlby hand. -
No GitHub MCP server: authenticate the GitHub CLI against your host and let Claude use
gh:gh auth login --hostname git.northwind.internal
Troubleshooting
claude --cloud cannot clone. Check an Owner finished setup, the app is installed on this repository, and the hostname registered in Claude exactly matches the one in your git remote.
/plugin marketplace add hits a policy error. Your organisation restricts marketplace sources. Ask an admin to add a hostPattern for your GHES host.
"Marketplace couldn't be added" from your claude.ai user settings. Almost always your own GitHub Enterprise account is not connected, even though the instance is. The dialog does not say so, and the Connect to GitHub option on the Browse tab signs into github.com, which does not help. Connect via the repository picker at claude.ai/code (it offers a connect option per GHES instance) or, if you are an Owner, in Organization settings > Git providers under GitHub: click Connect (or Add organization), pick the hostname under GitHub instance, and connect. Or ask an Owner to add the marketplace at organisation level. A "Repository not found. If it's private, GitHub access is required" error elsewhere on claude.ai usually means the same thing.
Reviews or hosted sessions time out. Anthropic cannot reach your instance; check the firewall allows Anthropic's outbound IPs. For self-hosted environment sessions, check the runner's own network path instead.
Unable to get organization UUID at session start. Your credentials have no claude.ai organisation. /login with an account in your Team or Enterprise organisation. See Claude Code on the web troubleshooting.