github / github/copilot-cli

Copilot App: Adding internal Github hosted marketplace opens GitHub device page without displaying authentication code

Open
#4,876 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

triage
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

Describe the bug

Adding an internal GitHub plugin marketplace through the Copilot App's Customize > Manage marketplaces UI starts GitHub device authentication and opens https://github.com/login/device, but the Copilot App never displays the device code. The GitHub page therefore asks for a code that the user has no way to obtain, and the marketplace cannot be added.

The user already has access to the internal repository. Authenticated GitHub CLI access to the repository succeeds, while anonymous access returns 404 as expected for an internal repository.

Affected version

GitHub Copilot App / bundled Copilot CLI 1.0.84-5

Steps to reproduce the behavior
  1. On macOS, open the GitHub Copilot App.
  2. Open Customize.
  3. Open Manage marketplaces.
  4. Enter the URL of an internal GitHub repository containing a valid .claude-plugin/marketplace.json, for example https://github.com/<organization>/<repository>.
  5. Click Add.
  6. When prompted, start GitHub authentication.
  7. Observe that the browser opens GitHub's device activation page and asks for a code, but no device code is displayed anywhere in the Copilot App UI.
Expected behavior

The Copilot App should prominently display the one-time GitHub device code before or while opening the device activation page, and keep it visible until authentication completes or is cancelled.

Alternatively, marketplace access should reuse an existing authenticated Git credential or GitHub CLI session when available.

Actual behavior

GitHub's device activation page opens and waits for a code, but the Copilot App does not show the code. The flow cannot be completed.

Additional context
  • Operating system: macOS
  • Repository visibility: internal
  • The repository is accessible to the current user and contains a valid marketplace manifest.
  • gh repo view <organization>/<repository> succeeds for the same user.
  • APM can resolve the same marketplace through the authenticated command-line path.
  • This appears related to, but is distinct from, #4103: the App now initiates an authentication flow, but its Customize UI does not surface the required device code.
  • Screenshots show the marketplace URL entered in Manage marketplaces followed by GitHub's Enter code page with no corresponding code visible in the Copilot App.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file or test is named. Start at the Customize > Manage marketplaces authentication flow and trace how the GitHub device page is launched, using related issue #4103 for context. Done means the one-time device code is visible in the Copilot App through authentication completion or cancellation, and the internal marketplace can be added.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, macos
Domain
authentication, cli
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.