Skip to main content

Get Started with Microsoft Agent Framework GitHub Copilot

Please install this package via pip:

pip install agent-framework-github-copilot

GitHub Copilot Agent

The GitHub Copilot agent enables integration with GitHub Copilot, allowing you to interact with Copilot's agentic capabilities through the Agent Framework.

Tool approval (approval_mode="always_require")

The GitHub Copilot SDK owns the tool-calling loop for this provider, so approval for custom function tools is enforced through the SDK's native pre-execution hook rather than the standard Agent Framework approval round-trip.

When you register a FunctionTool declared with approval_mode="always_require" and you do not supply your own on_pre_tool_use hook, GitHubCopilotAgent installs a default on_pre_tool_use hook that returns "ask" for that tool and defers (None) for all other tools. The "ask" decision routes to your on_permission_request handler, where you approve or deny the call:

from agent_framework import tool
from agent_framework.github import GitHubCopilotAgent, GitHubCopilotOptions
from copilot.session import PermissionHandler


@tool(approval_mode="always_require")
def delete_file(path: str) -> str:
    """Delete a file."""
    ...


agent = GitHubCopilotAgent(
    tools=[delete_file],
    # The "ask" decision is routed here; approve or deny the call.
    default_options=GitHubCopilotOptions(on_permission_request=PermissionHandler.approve_all),
)

⚠️ If you provide your own on_pre_tool_use hook, it takes precedence and the agent does not install its default approval hook. In that case you are fully responsible for enforcing approval — including for any approval_mode="always_require" tool (e.g. by returning a "deny" or "ask" decision). The agent logs a warning naming any approval-required tool that your hook must handle.

Note: with the default (deny-all) permission handler, an always_require tool is denied unless you wire an approving on_permission_request.

Approving for the rest of the session

PermissionDecisionApproveForSession scopes its approval with either an approval (tool prompts) or a domain (URL prompts). Both are optional, so a bare PermissionDecisionApproveForSession() carries no scope at all and the Copilot CLI cannot interpret it.

GitHubCopilotAgent therefore scopes such a decision automatically, using the request that triggered it — a shell prompt becomes an approval for that prompt's command identifiers, an MCP prompt an approval for that server and tool, a URL prompt an approval for that URL's domain, and so on:

from copilot.generated.rpc import PermissionDecisionApproveForSession


def on_permission_request(request, invocation):
    # Scoped to `request` automatically; approves that kind of call for the whole session.
    return PermissionDecisionApproveForSession()

The decision is only ever narrowed, never widened. When the prompt reports that it cannot offer session-scoped approval (can_offer_session_approval=False), or the request kind has no session-scoped approval at all (such as a hook prompt), the decision is downgraded to a single-use approval and a warning is logged. Pass an explicit approval= or domain= when you want to approve something other than the request being handled — decisions that already specify a scope are forwarded unchanged.

Deprecated: on_function_approval

The on_function_approval callback is deprecated. It still works (and is still enforced inside the tool handler for backward compatibility), but it emits a DeprecationWarning and will be removed in a future version. Migrate to the on_pre_tool_use + on_permission_request model described above. When on_function_approval is set, it gates always_require tools and the default ask-hook is not installed. It is mutually exclusive with on_pre_tool_use — setting both (whether at construction or per run) raises ValueError.

Metadata

Release files for agent-framework-github-copilot 1.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agent-framework-github-copilot 1.0.3
File Size Uploaded
agent_framework_github_copilot-1.0.3.tar.gz 22.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agent-framework-github-copilot 1.0.3
File Interpreter ABI Platform
agent_framework_github_copilot-1.0.3-py3-none-any.whl Python 3 none any Details

Total release size: 44.4 kB

Release files / agent_framework_github_copilot-1.0.3.tar.gz

Download URL agent_framework_github_copilot-1.0.3.tar.gz
Size 22.5 kB
Tags Source
SHA-256 checksum
How to use checksums
54c7796577529b5e385a9414b707929abe496361cd7c0f4ff2bfc17deaf3e912
BLAKE2b-256 checksum
How to use checksums
c7c89fdf2e52a56b6055e0f94725debf45b56d0c5c3e8b2835aa9b80e0ea486e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.32 {"installer":{"name":"uv","version":"0.11.32","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / agent_framework_github_copilot-1.0.3-py3-none-any.whl

Download URL agent_framework_github_copilot-1.0.3-py3-none-any.whl
Size 21.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
69ee2f7780c00c59afde4ed8858e716597e9e029bd23ae2b6ec102aa27b45cb6
BLAKE2b-256 checksum
How to use checksums
5246738b85dd22e64abe3d7be2897b04b4c08618603bace440154f58fdd90268
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.32 {"installer":{"name":"uv","version":"0.11.32","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

2.0.1

2 release files

2.0.0

2 release files

This release

1.0.3 This release

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page