Copilot CLI no longer needs a personal access token in GitHub Actions
GitHub Copilot CLI now works with the built-in GITHUB_TOKEN in GitHub Actions, eliminating the need to create and manage personal access tokens for CI/CD workflows.
You can now run GitHub Copilot CLI in GitHub Actions using the built-in GITHUB_TOKEN.
This means that you no longer need to create and store a personal access token (PAT), eliminating the operational and security risks of managing long-lived PATs for automations at scale.
When you run Copilot CLI with the Actions token in an organization-owned repository, AI credits consumed by the CLI are billed directly to the organization.
Configuring organization billing for Copilot CLI in GitHub Actions
In order to use this feature, you must enable the “Allow use of Copilot CLI billed to the organization” Copilot policy. This is enabled by default if you have the existing “Copilot CLI” policy enabled.
Once enabled, workflows just need the copilot-requests: write permission and can authenticate with the workflow’s built-in GITHUB_TOKEN. No additional secrets are required.
To learn more, see “Using Copilot CLI in GitHub Actions with GITHUB_TOKEN” in the GitHub Docs.
Note: You must be on a recent version of Copilot CLI. Update with
copilot update, or reinstall the latest version withnpm install -g @github/copilot.
Controlling cost while billing to your organization
User-level budgets are not considered when billing directly to the organization because the cost is not attributed to a user. There are multiple ways to manage spend when using this billing method:
- Configure cost centers for the relevant organizations. Cost centers allow cost attribution to groups of organizations, and budgets can be applied to cost centers.
- Monitor Copilot usage from your organization’s billing and usage dashboards to track consumption over time.
- Set a session limit to configure a maximum amount of AI credits that will be used by a workflow.
The post Copilot CLI no longer needs a personal access token in GitHub Actions appeared first on The GitHub Blog.
Source: original entry ↗
More from GitHub
Follow GitHub to get its new changes in your feed and email digest.
Claude Haiku 5.5 now available in GitHub Copilot
Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.
Purpose-built model for leaked secret detection
GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.
Local sandboxing for GitHub Copilot now generally available
GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.