github / github/app

Custom model provider: support Bearer token auth for Google Gemini-compatible endpoints

Open
#3,269 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
2.1k
Forks
153
PR merge metrics
No merged PRs in 30d

Description

## Problem

When configuring a custom model provider using the **Google Gemini** format, the Copilot app appears to send the API key as a `?key=` query parameter (Google's standard auth). However, enterprise Gemini-compatible proxies (e.g. SAP Hyperspace LLM Proxy) require the API key to be sent as an `Authorization: Bearer` header — not as a query param.

This makes it impossible to use Gemini-native endpoints from corporate proxies with custom model providers.

## Reproduction

1. Add a custom model provider with base URL pointing to a Gemini-compatible proxy (e.g. `http://localhost:6655/gemini`)
2. Set the API key to the proxy's bearer token
3. Attempt to use the model → fails with auth error on the proxy side (`Missing Authorization header`)

The proxy endpoint works correctly when called with `Authorization: Bearer `:
```
curl -X POST http://localhost:6655/gemini/v1beta/models/gemini-3.5-flash:generateContent \
-H "Authorization: Bearer " \
-H "Content-Type: application/json" \
-d '{"contents":[{"role":"user","parts":[{"text":"hi"}]}]}'
```

## Expected behavior

The custom Gemini model provider should send the API key as `Authorization: Bearer ` (in addition to or instead of `?key=`), to support enterprise proxies that follow this pattern.

## Workaround attempted

Using the OpenAI-compatible endpoint (`/litellm/v1`) works but **prompt caching does not function** through that path (related: #1975).

## Environment

| Field | Value |
|---|---|
| App version | 1.0.80 |
| OS | macOS |
| Path | /settings → Custom model provider |

Contributor guide

Open the contributing guide

Research direction

Start at Settings → Custom model provider and reproduce the request against the Gemini-compatible endpoint shown in the issue. Trace how the configured API key is applied for the Google Gemini format, then verify that the completed request includes the required Authorization: Bearer header and succeeds against the proxy without breaking the existing Gemini request behavior.

Written by the indexing model from the issue text.

Assessment

Domain
api, authentication
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
58/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.