Skip to content

GitHub Copilot as a coding agent: cloud agent, app, CLI and billing

GitHub Copilot is a full coding-agent platform, not only an autocomplete: a cloud agent that researches, plans and changes code on a branch in GitHub Actions and opens a pull request, a desktop Copilot app and Copilot CLI for local work, Agent Skills, hooks and MCP, and third-party Claude and Codex agents. Since 1 June 2026 its agent and chat usage bills in usage-based GitHub AI Credits.

Your company already pays for Copilot Business. A developer wants Claude Code, a tech lead wants to hand backlog issues to an agent, and finance asks why the June invoice changed. Before you buy another seat, learn what Copilot’s agents do, what a task costs, and which controls to set before the first agent pull request.

What this GitHub Copilot reference gives you

Section titled “What this GitHub Copilot reference gives you”
  • A map of the five Copilot agent surfaces and the job each one fits.
  • A working copilot-setup-steps.yml, a preToolUse hook, and three copy-paste prompts for the cloud agent and the CLI.
  • How AI-credit billing works and which knobs cap spend.
  • An admin checklist for Business and Enterprise, including policy gaps the settings pages do not flag.
  • A decision table for when Copilot is enough and when to add Claude Code, Codex or Cursor.

JetBrains’ August 2026 research (secondary, search extracts) places Copilot among the top AI coding tools used at work, behind Claude Code. For many teams it is the first agent; the question is how far it goes.

Which GitHub Copilot surface fits which job?

Section titled “Which GitHub Copilot surface fits which job?”

The five surfaces share one account, one AI-credit allowance and most customisation files. They differ in where the agent runs and who watches it.

SurfaceWhere the agent runsHow you start itFits
Copilot cloud agentAn ephemeral GitHub Actions environmentAssign an issue to Copilot, the Agents tab, @copilot on a pull request, Slack or Teams, or an automationWell-specified backlog issues, test gaps, dependency and documentation chores
GitHub Copilot appYour desktop (macOS, Linux, Windows), one git worktree and branch per session; cloud or local sandboxPick an issue or start a blank workspace, choose Interactive, Plan or AutopilotSeveral parallel tasks you steer and review from one window
Copilot CLI (@github/copilot 1.0.88)Your terminal, or headless with -pcopilot, copilot --plan, copilot -p "…"Terminal-first work and scripted jobs in CI
Agent mode in VS Code and JetBrainsYour editor, editing local filesThe chat view’s agent pickerInteractive changes where you watch each edit
Third-party agents (public preview)The same GitHub-hosted environment as the cloud agentAssign an issue to the Claude or Codex agent, or mention it on a pull requestComparing agents on the same issue without separate subscriptions

GitHub’s plans page states that “All plans include Copilot CLI and GitHub Copilot app”. The cloud agent needs a paid plan: it is on by default for Pro, Pro+ and Max, and off by default for Business and Enterprise until an administrator enables it.

How do you delegate an issue to the Copilot cloud agent?

Section titled “How do you delegate an issue to the Copilot cloud agent?”

The cloud agent works best when the environment is deterministic and “done” is written down. Do these in order.

  1. Enable the agent. On Business or Enterprise, an organization owner enables the cloud agent policy (see the admin checklist below). Repository owners can opt individual repositories out.

  2. Give it instructions it will read. The cloud agent reads .github/copilot-instructions.md, path-specific .github/instructions/**/*.instructions.md, organization instructions, and agent files: AGENTS.md, CLAUDE.md or GEMINI.md. An existing AGENTS.md or CLAUDE.md works as is; keep build, test and “definition of done” commands there. See making a codebase agent-ready.

  3. Pre-install the toolchain with copilot-setup-steps.yml. Without it, the agent finds dependencies by trial and error and fails on private packages. The file must live at .github/workflows/copilot-setup-steps.yml, contain a single job named copilot-setup-steps, and be on the default branch before it takes effect:

    .github/workflows/copilot-setup-steps.yml
    name: "Copilot Setup Steps"
    on:
    workflow_dispatch:
    push:
    paths:
    - .github/workflows/copilot-setup-steps.yml
    jobs:
    copilot-setup-steps: # the job name is mandatory
    runs-on: ubuntu-latest
    timeout-minutes: 40 # hard ceiling is 59
    permissions:
    contents: read # Copilot gets its own token for its work
    steps:
    - uses: actions/checkout@v4
    with:
    persist-credentials: false # Copilot uses its own token; do not leave the job token in .git/config
    - uses: actions/setup-node@v4
    with:
    node-version-file: .node-version
    cache: npm
    - run: npm ci
    - run: npx playwright install --with-deps chromium

    Only steps, permissions, runs-on, services, snapshot and timeout-minutes are honoured; other job settings are ignored. Run the workflow once from the Actions tab to prove it is green.

    Credentials for a private registry go in Settings → Secrets and variables → Agents, at repository or organization level. Secrets once kept in the copilot Actions environment were migrated there automatically, and the agent cannot read Actions, Codespaces or Dependabot secrets. Agents secrets reach the setup steps and the agent itself as environment variables, so store only read-only, narrowly scoped tokens there. Only names prefixed COPILOT_MCP_ are hidden from the agent and passed to MCP servers alone.

  4. Write the issue as a spec. Put the acceptance criteria, the files in scope and the command that proves the work into the issue body, as in the prompt below. See writing acceptance criteria an agent can check.

  5. Assign the issue to Copilot, or ask it in the Agents tab to plan first. Planning before a pull request works only on github.com (preview in Slack and Teams); Jira, Linear and Azure Boards go straight to a pull request.

  6. Review and iterate with @copilot comments on the pull request. It pushes new commits to the same pull request.

The cloud agent has four hard limits (checked 2026-09-26): one repository per task, one branch and at most one pull request per task, a maximum session time of 59 minutes that cannot be extended, and repositories hosted on GitHub only. If an issue cannot finish in under an hour, split it by acceptance criterion before you assign it.

How do you run Claude and Codex agents inside Copilot?

Section titled “How do you run Claude and Codex agents inside Copilot?”

GitHub runs two third-party agents in public preview: Anthropic Claude (built on the Claude Agent SDK) and OpenAI Codex. They share the cloud agent’s entry points, protections and limits, and draw on your AI credits and Actions minutes. Only the code author and the model list differ.

Assign the issue to Copilot, or mention @copilot on a pull request. It uses the full Copilot model list for your plan (on Pro+, Max, Business and Enterprise that includes Claude Opus 5.5, GPT-6 Astra and GPT-6 Sol), plus custom agents, hooks, skills and repository MCP settings. Pick it by default: it has the most customisation.

Auto in the third-party agents picks one of that agent’s listed models; it is not Copilot’s auto model selection and does not earn its 10% discount. Use the preview agents to compare harnesses on one issue. If your team standardises on Claude Code or Codex, run them natively; the head-to-head page compares the two paths.

Work locally with Copilot CLI and the Copilot app

Section titled “Work locally with Copilot CLI and the Copilot app”

Install the CLI with any of the documented methods (npm needs Node.js; check the install page for the minimum version):

Terminal
npm install -g @github/copilot # all platforms
brew install --cask copilot-cli # macOS and Linux
winget install GitHub.Copilot # Windows
copilot --version # GitHub Copilot CLI 1.0.88 on 2026-09-26

The flags that matter for agent work, all present in copilot --help 1.0.88:

Flag or commandWhat it does
--plan, --mode plan|interactive|autopilot, --autopilotStart in plan mode or fully autonomous mode; Shift+Tab cycles modes in a session
--max-autopilot-continues <count>Caps automatic continuations in Autopilot (default 5)
--max-ai-credits <credits>, /limits set max-ai-credits NSoft AI-credit cap per session (minimum 30; public preview per GitHub’s “Set an AI Credit limit” how-to)
--allow-tool, --deny-tool, --allow-all-toolsTool permissions; a deny rule always wins, even over --allow-all-tools
--allow-all / --yoloTools, paths and URLs all allowed; use only inside a sandbox
/sandbox enableOS-level sandbox for shell commands (experimental: start with --experimental or run /settings experimental on first; Linux needs bwrap)
-p, -s, --output-format json, --usage-output-fileHeadless runs for scripts and CI, with JSONL output and a usage report
--model, --reasoning-effortModel and effort (none through max) for the session
--fleetRuns the prompt with parallel subagent orchestration
copilot appOpens the GitHub Copilot app

The GitHub Copilot app is built on the CLI. Each session gets its own git worktree and branch, runs in a cloud or local sandbox, and uses one of three modes: Interactive, Plan (you approve the plan) or Autopilot. GitHub advises switching to Autopilot only when the task is well defined. The app also runs scheduled Automations and reads the same instructions, MCP servers and skills as the CLI.

Most of these files are shared with other agents, which matters if your team runs more than one tool.

Agent Skills. Copilot follows the open Agent Skills standard on every surface. It loads project skills from .github/skills, .claude/skills or .agents/skills, and personal skills from ~/.copilot/skills or ~/.agents/skills. A Claude Code skill in .claude/skills works unchanged. Install shared skills with gh skill (GitHub CLI 2.90.0 or later; preview), and read each skill first, because GitHub does not verify them:

Terminal
gh skill search "release notes"
gh skill preview github/awesome-copilot documentation-writer # renders SKILL.md, installs nothing
gh skill install github/awesome-copilot documentation-writer --pin v1.2.0

Hooks. Hooks run shell commands at session, prompt and tool events for the cloud agent and the CLI. Repository hooks live in .github/hooks/*.json; the CLI also reads personal hooks from ~/.copilot/hooks/. A preToolUse hook can deny a tool call, which makes it the one place to enforce a rule the agent cannot talk its way around:

.github/hooks/guard.json
{
"version": 1,
"hooks": {
"preToolUse": [
{ "type": "command", "bash": "./.github/hooks/deny-risky.sh", "timeoutSec": 5 }
]
}
}
.github/hooks/deny-risky.sh
#!/usr/bin/env bash
payload="$(cat)"
if printf '%s' "$payload" | grep -Eq 'git push --force|rm -rf /|DROP TABLE|terraform apply'; then
echo '{"permissionDecision":"deny","permissionDecisionReason":"Blocked by repository policy in .github/hooks/deny-risky.sh"}'
fi

A crash or non-zero exit in a preToolUse command hook denies the call, but a timeout lets the call through. Keep the script fast and set timeoutSec well above its real run time. Under the cloud agent, a decision of ask counts as deny, because nobody is there to answer.

MCP. The cloud agent starts with two MCP servers on: GitHub’s, using a token scoped read-only to the current repository, and Playwright, limited to localhost. Repository administrators add more as JSON in the repository’s Copilot settings; they apply to the cloud agent and Copilot code review. The agent uses configured tools without asking, so list only the tools it needs. Locally, the CLI reads ~/.copilot/mcp-config.json and a workspace .mcp.json or .github/mcp.json, and ships the GitHub MCP server by default:

Terminal
copilot mcp add playwright -- npx @playwright/mcp@latest
copilot mcp list

How does Copilot’s AI-credit billing work?

Section titled “How does Copilot’s AI-credit billing work?”

Since 1 June 2026 Copilot bills by model and tokens, not by request. Every interaction’s input, output and cached tokens are priced at the chosen model’s rate and converted to GitHub AI Credits at 1 credit = $0.01. Premium requests and model multipliers survive only on legacy annual Pro and Pro+ plans until they end.

PlanPriceBase credits per monthFlex allotment on top
Free · Student$0a smaller allowance, Auto model selection only (Free: 2,000 completions per month)—
Pro$10/month1,000+500
Pro+$39/month3,900+3,100
Max$100/month10,000+10,000
Business$19/user/month1,900 per usernot listed per plan
Enterprise$39/user/month3,900 per usernot listed per plan

Base credits match the subscription price. GitHub calls flex “a variable part of your included usage”, so budget on base credits only. Allowances reset at 00:00 UTC on the first of each month and do not roll over. Code completions and next edit suggestions are not billed in credits on paid plans. The cloud agent and third-party agents also consume GitHub Actions minutes, which is the line item teams forget.

To estimate one task, multiply its tokens by the model’s per-million-token rates on the models hub and multiply the dollar result by 100 to get credits. Four levers cut spend without cutting quality, all from GitHub’s own guidance:

  • Pick the model per task, then keep it. Switching model, effort, context size or MCP tools mid-session invalidates the cache and rebills the whole context.
  • Use Auto model selection as the default. Paid plans get a 10% discount on model costs with it in Chat, the CLI, the app and the cloud agent.
  • Cap sessions. Use --max-ai-credits in the CLI, and user or cost-centre budgets for the monthly total (cost governance covers the budget design).
  • Plan with a strong model, implement with a cheaper one. Subagents do not inherit the main conversation, so a lighter model there does not break its cache.

Set org policy before the first agent pull request

Section titled “Set org policy before the first agent pull request”

Copy this checklist into your rollout ticket.

For the cross-vendor version of this policy (Claude Code managed settings, Codex requirements.toml, Cursor and Copilot on one page), see one policy for every coding agent.

How do you verify what Copilot’s agents produce?

Section titled “How do you verify what Copilot’s agents produce?”

An agent pull request is a claim, not a result. Make it checkable before anyone reads the diff.

  • The agent runs your gates. copilot-setup-steps.yml installs the toolchain so the agent runs tests, lint and type checks inside its session, and your normal required status checks run on its pull request. Actions workflows on an agent pull request wait until someone with write access approves them. Approve the run before judging the checks, and put any secrets the setup steps need in Settings → Secrets and variables → Agents. Treat a red check exactly as you would for a human.
  • GitHub scans agent code. For the cloud agent and the third-party agents, GitHub documents automatic security validation before the pull request is finalized: CodeQL code scanning, secret scanning, and a check of new dependencies against the GitHub Advisory Database, with no GitHub Advanced Security licence required.
  • Hooks enforce what prompts cannot. A preToolUse deny is deterministic; an instruction in AGENTS.md is a request.
  • The pull request carries evidence. Ask the agent to map each acceptance criterion to a test and paste the command output. That is the evidence bundle reviewers check instead of reading every line.
  • A named human signs off. The agent requests your review when it finishes; branch protection and CODEOWNERS decide who merges. Keep that decision with the engineer who owns the acceptance criteria.
  • Measure outcomes, not activity. The Copilot usage metrics APIs report pull requests created and merged (including cloud-agent ones) and median time to merge. Track merge rate and rework per agent next to your delivery metrics.

What breaks with Copilot’s agents, and how do you recover?

Section titled “What breaks with Copilot’s agents, and how do you recover?”
  • The agent never starts, or cannot push. A ruleset restricting commit authors blocks it. Check the session log, then add Copilot as a bypass actor or relax the rule for agent branches.
  • Setup steps fail silently. If a step exits non-zero, Copilot skips the rest, starts in a half-built environment and burns credits reinstalling. Run the workflow from the Actions tab until green, and keep it on the default branch.
  • Credits run out mid-month. On an individual plan, upgrade (you pay the difference), set a budget for extra usage, or wait for the monthly reset; on Business and Enterprise the budget is the lever. Put --max-ai-credits on every scripted run and review /usage per session.
  • A model disappears. Claude Opus 4.7, Kimi K2.7 Code, Gemini 3.5 Flash and Gemini 3.6 Flash leave Copilot on 2026-10-02. Automations and scripts pinned to them need a new --model; check the models hub before you pin one.
  • A timed-out hook lets a blocked command through. See the timeout note under hooks.
  • An installed skill carries a prompt injection. Run gh skill preview before every install and pin versions with --pin.
  • --allow-all-tools or --yolo on a workstation. The agent gets your full file and shell access. Run such sessions in a sandbox, a container or CI with a scoped token; see permissions and sandboxing.

When is Copilot enough, and when do you add Claude Code or Codex?

Section titled “When is Copilot enough, and when do you add Claude Code or Codex?”
Your situationRecommendation
Code lives on GitHub, work arrives as issues, and you want pull requests from the backlogStart with the Copilot cloud agent; you already pay for it
Engineers want a terminal agent with a deep hook, subagent and plugin ecosystemAdd Claude Code for those engineers, and keep Copilot for issue-driven work
You need OpenAI’s current default model in its own harness, or multi-surface cloud tasksAdd Codex; the Codex agent inside Copilot offers older models
Code is not on GitHubThe cloud agent does not apply; compare the other coding agents
You must keep one bill and one admin consoleStay on Copilot and use its model picker, including Claude Opus 5.5 and GPT-6 Astra on Pro+, Max, Business and Enterprise (not Pro)

Frequently asked questions

Is GitHub Copilot still only an autocomplete tool?

No. As of 26 September 2026 GitHub Copilot includes a cloud agent that works in an ephemeral GitHub Actions environment and opens pull requests, a desktop Copilot app with Interactive, Plan and Autopilot modes, the Copilot CLI, Agent Skills, hooks and MCP, and it can run Anthropic Claude and OpenAI Codex as third-party agents (public preview).

How is GitHub Copilot billed since June 2026?

Since 1 June 2026 Copilot bills by model and tokens in GitHub AI Credits, where one credit is $0.01. Each paid plan includes base credits plus a variable flex allotment; code completions and next edit suggestions are not billed in credits on paid plans. The cloud agent and third-party agents also consume GitHub Actions minutes.

Can I run Claude or Codex inside GitHub Copilot?

Yes, in public preview. Once the policy is enabled you can assign an issue to the Anthropic Claude or OpenAI Codex agent, start one from the Agents tab, or mention it on a pull request. Sessions consume AI credits and Actions minutes from your Copilot plan, and the model list for these agents is shorter than the main Copilot model picker.

What limits does the Copilot cloud agent have?

A cloud agent session works in one repository, on one branch, opens at most one pull request per task, and stops after a hard limit of 59 minutes. Rulesets that restrict commit authors can block it, and it only works on repositories hosted on GitHub.