Copilot App: Adding internal Github hosted marketplace opens GitHub device page without displaying authentication code
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 11.2k
- Forks
- 1.9k
- Avg merge
- 14h 16m
- Merged PRs (30d)
- 6
Description
Describe the bug
Adding an internal GitHub plugin marketplace through the Copilot App's Customize > Manage marketplaces UI starts GitHub device authentication and opens https://github.com/login/device, but the Copilot App never displays the device code. The GitHub page therefore asks for a code that the user has no way to obtain, and the marketplace cannot be added.
The user already has access to the internal repository. Authenticated GitHub CLI access to the repository succeeds, while anonymous access returns 404 as expected for an internal repository.
Affected version
GitHub Copilot App / bundled Copilot CLI 1.0.84-5
Steps to reproduce the behavior
- On macOS, open the GitHub Copilot App.
- Open Customize.
- Open Manage marketplaces.
- Enter the URL of an internal GitHub repository containing a valid
.claude-plugin/marketplace.json, for examplehttps://github.com/<organization>/<repository>. - Click Add.
- When prompted, start GitHub authentication.
- Observe that the browser opens GitHub's device activation page and asks for a code, but no device code is displayed anywhere in the Copilot App UI.
Expected behavior
The Copilot App should prominently display the one-time GitHub device code before or while opening the device activation page, and keep it visible until authentication completes or is cancelled.
Alternatively, marketplace access should reuse an existing authenticated Git credential or GitHub CLI session when available.
Actual behavior
GitHub's device activation page opens and waits for a code, but the Copilot App does not show the code. The flow cannot be completed.
Additional context
- Operating system: macOS
- Repository visibility: internal
- The repository is accessible to the current user and contains a valid marketplace manifest.
gh repo view <organization>/<repository>succeeds for the same user.- APM can resolve the same marketplace through the authenticated command-line path.
- This appears related to, but is distinct from, #4103: the App now initiates an authentication flow, but its Customize UI does not surface the required device code.
- Screenshots show the marketplace URL entered in Manage marketplaces followed by GitHub's Enter code page with no corresponding code visible in the Copilot App.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No source file or test is named. Start at the Customize > Manage marketplaces authentication flow and trace how the GitHub device page is launched, using related issue #4103 for context. Done means the one-time device code is visible in the Copilot App through authentication completion or cancellation, and the internal marketplace can be added.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, macos
- Domain
- authentication, cli
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100