copilot CLI.
Prerequisites
Before setting up the integration, ensure you have:- Unbound CLI: Installed and logged in — see the CLI guide
- GitHub Copilot: VS Code extension or Copilot CLI
Setup with Unbound CLI
copilot CLI pick up the same hooks. Restart your terminal (and reload the VS Code window) after setup.
To remove the Unbound configuration:
Telemetry export
Copilot Chat reports each turn’s model and token counts over OpenTelemetry, and pointing that exporter at Unbound is what makes Copilot’s cost and usage numbers right. Copilot reads the setting from a root-owned, organization-managed file, so only the device-wide install configures it — run setup withsudo (see Deploy AI Tools via MDM). A plain unbound setup copilot installs the hooks for you alone and leaves telemetry alone.
The device-wide install adds a telemetry block to Copilot’s managed settings file:
The block points Copilot’s exporter at your gateway, with your API key as an
x-api-key header and captureContent off. Anything else in that file is an administrator’s and is preserved. Reload editors afterwards — the exporter is read when the extension activates.
If an earlier setup left github.copilot.chat.otel.* keys in your own VS Code settings, setup removes them. --clear removes the telemetry block, and the file too when nothing else is left in it.
Telemetry export needs an HTTPS gateway. Where the gateway URL is plain HTTP, setup reports Gateway URL is not https (…); skipping Copilot telemetry export and configures everything else as normal, because the API key travels as a header on every turn. A symlinked managed settings file is skipped the same way, since Copilot rejects one outright.
captureContent is false, so the spans carry the shape of each turn rather than its text.Copilot rows with no prompt
Some Copilot turns arrive in Logs about 18 hours late, carrying model, tokens and cost but no prompt and no policy decision. Nothing is missing and nothing is counted twice — each of those turns appears exactly once. A run of them means the prompt and policy side of Copilot isn’t reaching Unbound. Re-rununbound setup copilot, reload the VS Code window, and confirm with unbound doctor that Copilot comes back Healthy.
Usage
Basic Usage
After configuration, every tool call Copilot makes — shell commands, file reads, file writes, edits — is intercepted by the Unbound hooks. Policies are checked before the tool runs, and matching actions (block, warn, audit, Slack approval) are enforced inline.Security Benefits
Using GitHub Copilot with Unbound Security AI Gateway provides:- Request Monitoring: All Copilot tool calls are logged and monitored
- Analytics: See which files and commands Copilot touches across your org
- Compliance: Ensure AI interactions meet your organization’s standards
- Audit Trail: Complete visibility into AI usage patterns
Unbound CLI
Install the CLI to set up and manage tools
Tool Policies
Configure security guardrails for AI tools

