github / github/copilot-cli

Improve workflow for minimal auth scope vs gh auth login (via /login)

Open
#1,460 0 comments 4 reactions 0 assignees View on GitHub
area:authentication area:enterprise
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

### Describe the feature or problem you'd like to solve

There is no easy way to authenticate Copilot CLI with minimal, scoped permissions in isolated environments. The `gh auth login` device code flow only adds to existing scopes and does not support per-repo granularity. A `/login` command or similar mechanism that supports scoped auth would reduce the need for workarounds.

This is especially important when running Copilot CLI in isolated environments with YOLO mode.

### Proposed solution

**Current workaround:** Create a Fine-grained Personal Access Token with `User: Copilot` and `Repository: Contents (read/write)` permissions, then authenticate with `gh auth login --with-token` or pass in `GH_TOKEN` env var.

### Example prompts or workflows

_No response_

### Additional context

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.