[docs] auth: GHEC Copilot auth header prefix corrected to token - #7120
Conversation
PR #6991 fixed the GHEC data-residency Copilot target (copilot-api.<subdomain>.ghe.com) to require the 'token' Authorization prefix instead of 'Bearer', matching the enterprise and business targets' behavior. The auth matrix documentation still described GHEC as using 'Bearer', which is now stale. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Aligns Copilot authentication documentation with GHEC behavior introduced in #6991.
Changes:
- Documents
token <value>for derived GHEC targets. - Updates authentication-prefix tables and explanatory notes.
Show a summary per file
| File | Description |
|---|---|
docs/auth-matrix.md |
Corrects GHEC Copilot authorization-prefix guidance. |
Review details
Tip
Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Suppressed comments (1)
docs/auth-matrix.md:383
- “Standard prefix” is not defined here, and the preceding note describes both
Bearerandtokenas generally accepted formats. Keep the exactBearerprefix stated by the table so this summary cannot be interpreted as target-dependent.
The `token` prefix is used for GitHub OAuth tokens on the derived GHEC data-residency, enterprise, and business Copilot targets, or when GHES is otherwise detected (see `copilotTargetRequiresGitHubTokenPrefix()` in `copilot-auth.js`). BYOK and OIDC always use the standard prefix. As noted above, this is AWF-implementation-specific behavior driven by observed `400` errors from those targets — not a general GitHub REST API requirement.
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Balanced
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
|
✅ Copilot review passed with no inline comments. @github-actions[bot] Add the |
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
✅ Build Test Suite completed successfully!
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 5 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed12.pkgs.visualstudio.com"
- "msfeed17.pkgs.visualstudio.com"
- "msfeed2.pkgs.visualstudio.com"
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
|
✅ Smoke Gemini completed. All facets verified. 💎 Gemini Smoke Test PASS: MCP(✅), Connectivity(✅), File(✅), Bash(✅)
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤
|
|
🚀 Security Guard has started processing this pull request |
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
✅ Contribution Check completed successfully! Contribution check complete: the PR updates documentation only and matches CONTRIBUTING.md requirements; no missing tests, docs, or file-organization issues found.
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
✅ Smoke Claude passed
|
|
✅ Smoke Gemini completed. All facets verified. 💎 Smoke test completed with FAIL status due to connectivity issues.
|
|
📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 5 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed12.pkgs.visualstudio.com"
- "msfeed17.pkgs.visualstudio.com"
- "msfeed2.pkgs.visualstudio.com"
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
✅ Contribution Check completed successfully! PR #7120 follows CONTRIBUTING.md: the change is documentation-only with a small test expectation update, the description is clear and references related PRs/issues, and files are in the correct docs/tests locations. No missing guideline items found.
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Smoke Claude passed
|
|
✅ Build Test Suite completed successfully!
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
🚀 Security Guard has started processing this pull request |
Smoke Test: Copilot BYOK (Direct) ModeMCP PRs: #7146 Upgrade gh-aw extension to latest pre-release and recompile workflows; #7124 Update Runner Doctor with C9 and B20 failure modes
Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY) via api-proxy → api.githubcopilot.com Overall: PASS cc
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain (github.com) reachable: Overall: PASS cc Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
Smoke Test: Copilot Engine —
Overall: PASS
|
|
Smoke Test Results:
Overall: FAIL —
|
Smoke Test: API Proxy OTel Tracing
Overall: All 5 scenarios pass.
|
Gemini Engine Smoke Test Results
Overall Status: FAIL
|
Chroot Version Comparison Results
Overall: FAILED — Node.js version mismatch between host and chroot environment.
|
Smoke Test
Warning Firewall blocked 5 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed12.pkgs.visualstudio.com"
- "msfeed17.pkgs.visualstudio.com"
- "msfeed2.pkgs.visualstudio.com"
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS Notes:
|
|
Smoke Test: Docker Sbx Validation
Pre-fetched PRs: #7146 (by Overall: PASS ✅ cc
|
Summary
copilot-auth.js,excluded-vars.ts,api-proxy-env-config.ts), and merged PRs fix(api-proxy): correct auth prefix for derived GHEC Copilot targets #6991, fix(api-proxy): stop alias fallback picking arbitrary models #6996, fix: isolate Actions OIDC from agent container #6894, plus gh-aw#50053.copilot-api.<subdomain>.ghe.com).docs/authentication-architecture.md; no changes needed there.Documentation Changes
*.ghe.com) row in the "GitHub OAuth Token (Standard)" table, the "Auth Header Prefix Rules" table, and the accompanying prose notes to state the auth header uses thetoken <value>prefix (notBearer) for the derived GHEC data-residency Copilot targetcopilot-api.<subdomain>.ghe.com. This matches the fix merged in PR fix(api-proxy): correct auth prefix for derived GHEC Copilot targets #6991 (fix(api-proxy): correct auth prefix for derived GHEC Copilot targets), which found the enterprise/business-style400 Bad Requestbehavior also applies to GHEC targets and addedisGhecCopilotApiTarget()tocopilotTargetRequiresGitHubTokenPrefix()incontainers/api-proxy/providers/copilot-auth.js.Validation
containers/api-proxy/providers/copilot-auth.js(copilotTargetRequiresGitHubTokenPrefix,isGhecCopilotApiTarget),copilot-adapter-enterprise.test.js,copilot-auth.test.js,server.auth-matrix.test.js— all confirm thetokenprefix is now used forcopilot-api.*.ghe.comtargets onmain.docs/authentication-architecture.mdfor GHEC/OIDC claims — no stale text found there.Sources