Skip to content

docs: use organization Copilot Requests permission for server-to-server tokens - #2832

Draft
gfarb wants to merge 1 commit into
mainfrom
gfarb-s2s-token-docs-update
Draft

gfarb wants to merge 1 commit into
mainfrom
gfarb-s2s-token-docs-update

Conversation

@gfarb

@gfarb gfarb commented Oct 9, 2026

Copy link
Copy Markdown

Part of github/copilot#31519 (Document organization App setup, billing and token renewal)
Epic: github/copilot#30409

Summary

Updates the server-to-server guide to use the organization Copilot Requests permission (organization_copilot_requests, read-only, registered in github/github#456098 and enforced by CAPI via authzd in github/copilot-api#38896) instead of the repository permission.

  • Setup: the App requests the organization Copilot Requests permission set to Read-only. An All repositories installation and repository_ids are no longer required.
  • Billing: usage is billed to the organization that owns the installation. Installations on personal accounts are rejected for custom Apps, so the user-account billing clause is removed.
  • Troubleshooting: replaces the repository_ids and All repositories rows with a single organization permission row. Fixes the 401 row, since CAPI returns 403 when GitHub App installation tokens are not enabled.

SDK runtime code samples and the COPILOT_GITHUB_TOKEN path are unchanged because gitHubToken support for installation tokens is still being verified in github/copilot#30423.

Validation

Run 2026-10-08 against prod https://api.githubcopilot.com/models (no inference):

  • Default installation token (no request body), selected-repositories install: 200
  • Token scoped to permissions: {organization_copilot_requests: read} only: 200
  • Token scoped to repository_ids only: 200
  • Token missing the org permission, and App without it: 403 the GitHub App installation access token does not have the organization "Copilot Requests" read permission

Not yet validated: SDK code samples and createSession, inference, and the 401 and "not enabled" troubleshooting rows.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant