# GitHub Copilot

<Callout type="info" title="Note">
  AI Gateway is part of [AI Governance](/beta-docs/ai-coder/ai-governance/), which is
  included with a Premium license.
</Callout>

[GitHub Copilot](https://github.com/features/copilot) is an AI coding assistant that doesn't support custom base URLs but does respect proxy configurations.
This makes it compatible with [AI Gateway Proxy](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/), which integrates with [AI Gateway](/beta-docs/ai-coder/ai-gateway/) for full access to auditing and governance features.
To use Copilot with AI Gateway, make sure AI Gateway Proxy is properly configured, see [AI Gateway Proxy Setup](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/) for instructions.

Copilot uses **per-user tokens** tied to GitHub accounts rather than a shared API key.
Users must still authenticate with GitHub to use Copilot.

For general information about GitHub Copilot, see the [GitHub Copilot documentation](https://docs.github.com/en/copilot).

For general client configuration requirements, see [AI Gateway Proxy Client Configuration](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#client-configuration).
The sections below cover Copilot-specific setup for each client.

For provider configuration (admin), see [GitHub Copilot provider setup](/beta-docs/ai-coder/ai-gateway/providers/#github-copilot).

## Copilot CLI [#copilot-cli]

For installation instructions, see [GitHub Copilot CLI documentation](https://docs.github.com/en/copilot/how-tos/copilot-cli/install-copilot-cli).

### Proxy configuration [#proxy-configuration]

Set the `HTTPS_PROXY` environment variable:

```sh
export HTTPS_PROXY="https://coder:${CODER_API_TOKEN}@<proxy-host>:8888"
```

Replace `<proxy-host>` with your AI Gateway Proxy hostname.

Note: if [TLS is not enabled](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#proxy-tls-configuration) on the proxy, replace `https://` with `http://` in the proxy URL.

### CA certificate trust [#ca-certificate-trust]

Copilot CLI is built on Node.js and uses the `NODE_EXTRA_CA_CERTS` environment variable for custom certificates:

```sh
export NODE_EXTRA_CA_CERTS="/path/to/coder-ai-gateway-proxy-ca.pem"
```

Refer to [Client Configuration CA certificate trust](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#trust-the-ca-certificate) for details on how to obtain the certificate file.

When [TLS is enabled](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#proxy-tls-configuration) on the proxy, combine the MITM CA certificate and the TLS certificate into a single file:

```sh
cat coder-ai-gateway-proxy-ca.pem listener.crt > combined-ca.pem
export NODE_EXTRA_CA_CERTS="/path/to/combined-ca.pem"
```

Copilot CLI may start MCP server processes that use runtimes other than Node.js (e.g. Go).
These processes inherit environment variables like `HTTPS_PROXY` but may not respect `NODE_EXTRA_CA_CERTS`.
Adding the TLS certificate to the [system trust store](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#system-trust-store) ensures all processes trust it.

## VS Code Copilot Extension [#vs-code-copilot-extension]

For installation instructions, see [Installing the GitHub Copilot extension in VS Code](https://docs.github.com/en/copilot/how-tos/set-up/install-copilot-extension?tool=vscode).

### Proxy configuration [#proxy-configuration-1]

You can configure the proxy using environment variables or VS Code settings.
For environment variables, visit [AI Gateway Proxy client configuration](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#configure-the-proxy).

Alternatively, you can configure the proxy directly in VS Code settings:

1. Open Settings (`Ctrl+,` for Windows or `Cmd+,` for macOS)
2. Search for `HTTP: Proxy`
3. Set the proxy URL using the format `https://coder:<CODER_API_TOKEN>@<proxy-host>:8888`

Or add directly to your `settings.json`:

```json
{
    "http.proxy": "https://coder:<CODER_API_TOKEN>@<proxy-host>:8888"
}
```

Note: if [TLS is not enabled](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#proxy-tls-configuration) on the proxy, replace `https://` with `http://` in the proxy URL.

The `http.proxy` setting is used for both HTTP and HTTPS requests.
Replace `<proxy-host>` with your AI Gateway Proxy hostname and `<CODER_API_TOKEN>` with your Coder API token.

Restart VS Code for changes to take effect.

For more details, see [Configuring proxy settings for Copilot](https://docs.github.com/en/copilot/how-tos/configure-personal-settings/configure-network-settings?tool=vscode) in the GitHub documentation.

### CA certificate trust [#ca-certificate-trust-1]

Add the AI Gateway Proxy CA certificate to your operating system's trust store.
By default, VS Code loads system certificates, controlled by the `http.systemCertificates` setting.

Check out [Client Configuration CA certificate trust](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#trust-the-ca-certificate) for details on how to obtain the certificate file.

When [TLS is enabled](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#proxy-tls-configuration) on the proxy, add the TLS certificate to the system trust store as well.

### Coder Remote extension [#coder-remote-extension]

When connecting to a Coder workspace with the [Coder extension](https://marketplace.visualstudio.com/items?itemName=coder.coder-remote), the Copilot extension runs inside the Coder workspace and not on your local machine.
This means proxy and certificate configuration must be done in the Coder workspace environment.

When [TLS is enabled](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#proxy-tls-configuration) on the proxy, add the TLS certificate to the workspace's system trust store as well.

#### Proxy configuration [#proxy-configuration-2]

Configure the proxy in VS Code's remote settings:

1. [Connect to your Coder workspace](/beta-docs/user-guides/workspace-access/vscode/)
2. Open Settings (`Ctrl+,` for Windows or `Cmd+,` for macOS)
3. Select the **Remote** tab
4. Search for `HTTP: Proxy`
5. Set the proxy URL using the format `https://coder:<CODER_API_TOKEN>@<proxy-host>:8888`

Note: if [TLS is not enabled](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#proxy-tls-configuration) on the proxy, replace `https://` with `http://` in the proxy URL.

Replace `<proxy-host>` with your AI Gateway Proxy hostname and `<CODER_API_TOKEN>` with your Coder API token.

#### CA certificate trust [#ca-certificate-trust-2]

Since the Copilot extension runs inside the Coder workspace, add the [AI Gateway Proxy CA certificate](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#trust-the-ca-certificate) to the Coder workspace's system trust store.
See [System trust store](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#system-trust-store) for instructions on how to do this on Linux.

Restart VS Code for changes to take effect.

## JetBrains IDEs [#jetbrains-ides]

For installation instructions, see [Installing the GitHub Copilot extension in JetBrains IDE](https://docs.github.com/en/copilot/how-tos/set-up/install-copilot-extension?tool=jetbrains).

### Proxy configuration [#proxy-configuration-3]

Configure the proxy directly in JetBrains IDE settings:

1. Open Settings (`Ctrl+Alt+S` for Windows or `Cmd+,` for macOS)
2. Navigate to `Appearance & Behavior` > `System Settings` > `HTTP Proxy`
3. Select `Manual proxy configuration` and `HTTP`
4. Enter the proxy hostname and port (default: 8888)
5. Select `Proxy authentication` and enter:
   1. Login: `coder` (this value is ignored)
   2. Password: Your Coder API token
   3. Check `Remember` to save the password
6. Restart the IDE for changes to take effect

For more details, see [Configuring proxy settings for Copilot](https://docs.github.com/en/copilot/how-tos/configure-personal-settings/configure-network-settings?tool=jetbrains) in the GitHub documentation.

### CA certificate trust [#ca-certificate-trust-3]

Add the AI Gateway Proxy CA certificate to your operating system's trust store.
If the certificate is in the system trust store, no additional IDE configuration is needed.

When [TLS is enabled](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#proxy-tls-configuration) on the proxy, add the TLS certificate to the system trust store as well, or add it under `Accepted certificates` in the IDE settings below.

Alternatively, you can configure the IDE to accept the certificate:

1. Open Settings (`Ctrl+Alt+S` for Windows or `Cmd+,` for macOS)
2. Navigate to `Appearance & Behavior` > `System Settings` > `Server Certificates`
3. Under `Accepted certificates`, click `+` and select the CA certificate file
4. Check `Accept non-trusted certificates automatically`
5. Restart the IDE for changes to take effect

For more details, see [Trusted root certificates](https://www.jetbrains.com/help/idea/ssl-certificates.html) in the JetBrains documentation.

See [Client Configuration CA certificate trust](/beta-docs/ai-coder/ai-gateway/ai-gateway-proxy/setup/#trust-the-ca-certificate) for details on how to obtain the certificate file.
