인증 방법
| Method | 사용 사례 | Copilot 구독 필요 |
|---|---|---|
| GitHub 로그인한 사용자 | 사용자가 GitHub 사용하여 로그인하는 대화형 앱 | Yes |
| GitHub OAuth 앱 | OAuth를 통해 사용자를 대신하여 작동하는 앱 | Yes |
| 환경 변수 | CI/CD, 자동화, 서버-서버 | Yes |
| 서버-서버 인증 | 조직 귀속 자동화 및 조직 직접 청구 | 사용자 구독 없음; 조직 정책 필요 |
| BYOK(사용자 고유의 키 가져오기) | 사용자 고유의 API 키 사용(Microsoft Foundry, OpenAI 등) | No |
GitHub 로그인 사용자
Copilot CLI를 대화형으로 실행할 때 기본 인증 방법입니다. 사용자는 GitHub OAuth 디바이스 흐름을 통해 인증하고 SDK는 저장된 자격 증명을 사용합니다.
작동 방식:
- 사용자는
copilotCLI를 실행하고 GitHub OAuth를 통해 로그인합니다. - 자격 증명은 시스템 키 집합에 안전하게 저장됩니다.
- SDK는 저장된 자격 증명을 자동으로 사용합니다.
SDK 구성:
using GitHub.Copilot;
// Default: uses logged-in user credentials
await using CopilotClient client = new();
import copilot "github.com/github/copilot-sdk/go"
// Default: uses logged-in user credentials
client := copilot.NewClient(nil)
import com.github.copilot.CopilotClient;
// Default: uses logged-in user credentials
var client = new CopilotClient();
client.start().get();
from copilot import CopilotClient
# Default: uses logged-in user credentials
client = CopilotClient()
await client.start()
use github_copilot_sdk::{Client, ClientOptions};
// Default: uses logged-in user credentials
let client = Client::start(ClientOptions::default()).await?;
import { CopilotClient } from "@github/copilot-sdk";
// Default: uses logged-in user credentials
const client = new CopilotClient();
사용 시기:
- 사용자가 직접 상호 작용하는 데스크톱 애플리케이션
- 개발 및 테스팅 환경
- 사용자가 대화형으로 로그인할 수 있는 모든 시나리오
GitHub OAuth 앱
OAuth GitHub 앱을 사용하여 애플리케이션을 통해 사용자를 인증하고 해당 자격 증명을 SDK에 전달합니다. 이를 통해 애플리케이션은 앱에 권한을 부여한 사용자를 대신해 Copilot API 요청을 보낼 수 있습니다.
작동 방식:
- 사용자가 OAuth GitHub 앱에 권한을 부여합니다.
- 앱이 사용자 액세스 토큰(
gho_또는ghu_접두사)을 받습니다. - 클라이언트 구성을 통해 SDK에 토큰 전달
SDK 구성:
using GitHub.Copilot;
await using var client = new CopilotClient(new CopilotClientOptions
{
GitHubToken = userAccessToken, // Token from OAuth flow
UseLoggedInUser = false, // Don't use stored CLI credentials
});
import copilot "github.com/github/copilot-sdk/go"
client := copilot.NewClient(&copilot.ClientOptions{
GitHubToken: userAccessToken, // Token from OAuth flow
UseLoggedInUser: copilot.Bool(false), // Don't use stored CLI credentials
})
import com.github.copilot.CopilotClient;
import com.github.copilot.rpc.*;
var client = new CopilotClient(new CopilotClientOptions()
.setGitHubToken(userAccessToken) // Token from OAuth flow
.setUseLoggedInUser(false) // Don't use stored CLI credentials
);
client.start().get();
from copilot import CopilotClient
client = CopilotClient({
"github_token": user_access_token, # Token from OAuth flow
"use_logged_in_user": False, # Don't use stored CLI credentials
})
await client.start()
use github_copilot_sdk::{Client, ClientOptions};
let client = Client::start(
ClientOptions::default()
.with_github_token(user_access_token)
.with_use_logged_in_user(false),
).await?;
import { CopilotClient } from "@github/copilot-sdk";
const client = new CopilotClient({
gitHubToken: userAccessToken, // Token from OAuth flow
useLoggedInUser: false, // Don't use stored CLI credentials
});
지원되는 토큰 유형:
gho_- OAuth 사용자 액세스 토큰ghu_- 앱 사용자 액세스 토큰 GitHubgithub_pat_- 세분화된 개인용 액세스 토큰
지원되지 않음:
ghp_- 클래식 개인용 액세스 토큰(사용되지 않음)
사용 시기:
- 사용자가 GitHub 통해 로그인하는 웹 애플리케이션
- Copilot 위에 빌드되는 SaaS 애플리케이션
- 다른 사용자를 대신하여 요청을 수행해야 하는 모든 다중 사용자 애플리케이션
자세한 내용은 GitHub OAuth 설정을(를) 참조하세요.
세션 범위의 GitHub 토큰 순환
다중 사용자 서비스 및 통합의 경우 수명이 긴 토큰을 저장하는 대신 각 세션에서 토큰 공급자를 설정합니다. 런타임은 실제로 적용되는 GitHub 호스트를 확인하기 위해 공급자를 호출하고 요청을 initial 또는 refresh로 식별합니다. 클라우드 세션이 아직 ID를 받지 못한 경우에만 세션 ID가 없습니다.
태그가 지정된 토큰 결과 또는 명시적 취소를 반환합니다. 모든 토큰 결과에는 콜백이 완료될 때 남은 양수(초)가 포함되어 expiresIn야 합니다. 프로덕션 GitHub 토큰은 일반적으로 8시간 동안 지속되므로 8 * 60 * 60 일반적인 값입니다. 세션별 정적 토큰과 공급자를 모두 설정하지 마세요.
const session = await client.createSession({
gitHubTokenProvider: async ({ host, sessionId, reason }) => {
const token = await acquireGitHubToken({ host, sessionId, reason });
return {
kind: "token",
accessToken: token.value,
expiresIn: token.secondsRemaining,
};
},
});
async def provide_github_token(args):
token = await acquire_github_token(
host=args["host"],
session_id=args["session_id"],
reason=args["reason"],
)
return {
"kind": "token",
"accessToken": token.value,
"expiresIn": token.seconds_remaining,
}
session = await client.create_session(github_token_provider=provide_github_token)
session, err := client.CreateSession(ctx, &copilot.SessionConfig{
GitHubTokenProvider: func(args copilot.GitHubTokenProviderArgs) (*copilot.GitHubTokenProviderResult, error) {
token, secondsRemaining, err := acquireGitHubToken(args.Host, args.SessionID, args.Reason)
if err != nil {
return nil, err
}
return copilot.GitHubTokenResult(&copilot.GitHubToken{
AccessToken: token,
ExpiresIn: secondsRemaining,
}), nil
},
})
await using var session = await client.CreateSessionAsync(new SessionConfig
{
GitHubTokenProvider = async args =>
{
var token = await AcquireGitHubTokenAsync(args.Host, args.SessionId, args.Reason);
return GitHubTokenProviderResult.FromToken(new GitHubToken
{
AccessToken = token.Value,
ExpiresIn = token.SecondsRemaining,
});
},
});
var session = client.createSession(new SessionConfig()
.setGitHubTokenProvider(args ->
acquireGitHubToken(args.host(), args.sessionId(), args.reason())
.thenApply(token -> GitHubTokenProviderResult.token(
token.value(), token.secondsRemaining())))
.setOnPermissionRequest(PermissionHandler.APPROVE_ALL)
).get();
let provider = Arc::new(|args: GitHubTokenProviderArgs| async move {
let token = acquire_github_token(&args.host, args.session_id.as_ref(), args.reason).await?;
Ok(GitHubTokenProviderResult::Token(GitHubToken::new(
token.value,
token.seconds_remaining,
)))
});
let session = client
.create_session(SessionConfig::default().with_github_token_provider(provider))
.await?;
런타임은 세션 생성 또는 재개 과정의 일부로 initial 획득을 수행합니다. 안정적인 계정 ID가 없는 취소된 취득, 공급자 오류, 잘못된 응답 또는 토큰은 만들기 또는 다시 시작 작업을 거부합니다. 런타임은 앰비언트 인증으로 대체되지 않습니다.
세션이 설정되면 런타임은 각 자격 증명 사용 작업 전에 비동기 프리플라이트를 수행합니다. 현재 토큰에 1 refresh 시간 이하의 남은 시간이 있는 경우를 요청합니다. 유휴 세션은 다음 자격 증명 사용 작업까지 새로 고쳐지지 않습니다. 런타임은 이 콜백에 백그라운드 타이머, 거부 시 재시도, 401/403 챌린지 전파 또는 범위 확장을 사용하지 않습니다.
환경 변수
자동화, CI/CD 파이프라인 및 서버-서버 시나리오의 경우 환경 변수를 사용하여 인증할 수 있습니다.
사용자의 개인 액세스 토큰을 사용하지 않아야 하는 조직 특성 자동화는 서버-서버 인증을 참조하세요.
지원되는 환경 변수(우선 순위):
COPILOT_GITHUB_TOKEN- 명시적 Copilot 사용에 권장됨GH_TOKEN- GitHub CLI 호환GITHUB_TOKEN- GitHub Actions 호환
작동 방식:
- 유효한 토큰으로 지원되는 환경 변수 중 하나를 설정합니다.
- SDK는 토큰을 자동으로 검색하고 사용합니다.
SDK 구성:
코드 변경이 필요하지 않습니다. SDK는 환경 변수를 자동으로 검색합니다.
using GitHub.Copilot;
// Token is read from environment variable automatically
await using CopilotClient client = new();
import copilot "github.com/github/copilot-sdk/go"
// Token is read from environment variable automatically
client := copilot.NewClient(nil)
import com.github.copilot.CopilotClient;
// Token is read from environment variable automatically
var client = new CopilotClient();
client.start().get();
from copilot import CopilotClient
# Token is read from environment variable automatically
client = CopilotClient()
await client.start()
use github_copilot_sdk::{Client, ClientOptions};
// Token is read from environment variable automatically
let client = Client::start(ClientOptions::default()).await?;
import { CopilotClient } from "@github/copilot-sdk";
// Token is read from environment variable automatically
const client = new CopilotClient();
사용 시기:
- CI/CD 파이프라인(GitHub Actions, Jenkins 등)
- 자동화된 테스트
- 서비스 계정이 있는 서버 쪽 애플리케이션
- 대화형 로그인을 사용하지 않으려는 경우 개발
BYOK(사용자 고유의 키 가져오기)
BYOK를 사용하면 Microsoft Foundry, OpenAI 또는 Anthropic 같은 모델 공급자의 고유한 API 키를 사용할 수 있습니다. 이렇게 하면 GitHub Copilot 인증이 완전히 무시됩니다.
주요 이점:
- GitHub Copilot 구독 필요 없음
- 엔터프라이즈 모델 배포 사용
- 모델 공급자를 사용하여 직접 청구
- Microsoft Foundry, OpenAI, Anthropic 및 OpenAI 호환 엔드포인트 지원
다음을 비롯한 자세한 내용은 BYOK(사용자 고유의 키 가져오기) 을 참조하세요.
- Microsoft Foundry 설정
- 공급자 구성 옵션
- 제한 사항 및 고려 사항
- 전체 코드 예제
인증 우선 순위
여러 인증 방법을 사용할 수 있는 경우 SDK는 이 우선 순위 순서로 사용합니다.
- 명시적
gitHubToken- SDK 클라이언트 또는 세션 구성에 직접 전달되는 토큰 - 직접 API 토큰 -
GITHUB_COPILOT_API_TOKEN포함COPILOT_API_URL - 환경 변수 토큰 -
COPILOT_GITHUB_TOKEN``GH_TOKEN→ →GITHUB_TOKEN - 저장된 OAuth 자격 증명 - 이전
copilotCLI 로그인에서 - GitHub CLI -
gh auth자격 증명
다중 사용자 서버 모드의 경우 각 세션이 올바른 GitHub ID로 실행되도록 세션별 gitHubToken 전달합니다. 다중 테넌트 및 서버 배포 참조하세요.
자동 로그인 사용 안 림
SDK가 저장된 자격 증명 또는 gh CLI 인증을 자동으로 사용하지 않도록 하려면 로그인한 사용자 대체를 사용하지 않도록 구성합니다.
await using var client = new CopilotClient(new CopilotClientOptions
{
UseLoggedInUser = false, // Only use explicit tokens
});
client := copilot.NewClient(&copilot.ClientOptions{
UseLoggedInUser: copilot.Bool(false), // Only use explicit tokens
})
import com.github.copilot.CopilotClient;
import com.github.copilot.rpc.*;
var client = new CopilotClient(new CopilotClientOptions()
.setUseLoggedInUser(false) // Only use explicit tokens
);
client.start().get();
client = CopilotClient({
"use_logged_in_user": False, # Only use explicit tokens
})
use github_copilot_sdk::{Client, ClientOptions};
let client = Client::start(
ClientOptions::default().with_use_logged_in_user(false),
).await?;
const client = new CopilotClient({
useLoggedInUser: false, // Only use explicit tokens
});
다음 단계
- BYOK(사용자 고유의 키 가져오기) - 사용자 고유의 API 키를 사용하는 방법 알아보기
- Build your first Copilot-powered app - 첫 번째 Copilot 지원 앱 빌드
- GitHub Copilot SDK에서 MCP 서버 사용 - 외부 도구에 연결