Skip to main content
GitHub Copilot is GitHub’s AI pair programmer that suggests code completions, explains code, and runs agentic workflows across your editor and terminal. It works in the VS Code extension and the copilot CLI.

Prerequisites

Before setting up the integration, ensure you have:

Setup with Unbound CLI

This installs the Unbound hooks for Copilot. Both the VS Code extension and the copilot CLI pick up the same hooks. Restart your terminal (and reload the VS Code window) after setup. To remove the Unbound configuration:

Telemetry export

Copilot Chat reports each turn’s model and token counts over OpenTelemetry, and pointing that exporter at Unbound is what makes Copilot’s cost and usage numbers right. Copilot reads the setting from a root-owned, organization-managed file, so only the device-wide install configures it — run setup with sudo (see Deploy AI Tools via MDM). A plain unbound setup copilot installs the hooks for you alone and leaves telemetry alone. The device-wide install adds a telemetry block to Copilot’s managed settings file: The block points Copilot’s exporter at your gateway, with your API key as an x-api-key header and captureContent off. Anything else in that file is an administrator’s and is preserved. Reload editors afterwards — the exporter is read when the extension activates. If an earlier setup left github.copilot.chat.otel.* keys in your own VS Code settings, setup removes them. --clear removes the telemetry block, and the file too when nothing else is left in it.
Telemetry export needs an HTTPS gateway. Where the gateway URL is plain HTTP, setup reports Gateway URL is not https (…); skipping Copilot telemetry export and configures everything else as normal, because the API key travels as a header on every turn. A symlinked managed settings file is skipped the same way, since Copilot rejects one outright.captureContent is false, so the spans carry the shape of each turn rather than its text.

Copilot rows with no prompt

Some Copilot turns arrive in Logs about 18 hours late, carrying model, tokens and cost but no prompt and no policy decision. Nothing is missing and nothing is counted twice — each of those turns appears exactly once. A run of them means the prompt and policy side of Copilot isn’t reaching Unbound. Re-run unbound setup copilot, reload the VS Code window, and confirm with unbound doctor that Copilot comes back Healthy.

Usage

Basic Usage

After configuration, every tool call Copilot makes — shell commands, file reads, file writes, edits — is intercepted by the Unbound hooks. Policies are checked before the tool runs, and matching actions (block, warn, audit, Slack approval) are enforced inline.

Security Benefits

Using GitHub Copilot with Unbound Security AI Gateway provides:
  • Request Monitoring: All Copilot tool calls are logged and monitored
  • Analytics: See which files and commands Copilot touches across your org
  • Compliance: Ensure AI interactions meet your organization’s standards
  • Audit Trail: Complete visibility into AI usage patterns

Unbound CLI

Install the CLI to set up and manage tools

Tool Policies

Configure security guardrails for AI tools