System proxy
Any HTTPS rewriting proxy works. Proxyman is recommended.
Routes policy requests from VS Code, Copilot CLI, and SDK clients to this server.
Checking…
Waiting for the automatic connection check.
-
1
Configure the system proxy
Configure an HTTPS rewrite from the managed settings URL to this local server. In Proxyman, create a Map Remote rule using these values.
Proxyman tips
- Keep the source and destination paths identical.
- If HTTPS requests do not appear, install and trust Proxyman's certificate.
Required for VS Code: add this property inside the client's settings.json.
VS Code settings.json property
-
2
Request fresh policy in VS Code
Run > Developer: Sync Account Policy. For Local Agent Host, also run > Developer: Restart Local Agent Host.
If no request appears under Live Requests on the Policies page, open Troubleshooting in the right sidebar, clear the SDK policy cache for your platform, and then run the commands again.
-
3
Filter responses in your proxy Optional
Use this display filter to show only real policy requests:
^(?!.*mockPolicySetupProbe).*managed_settings.*
Keep probes in the Map Remote rule; filter only the displayed traffic.
File-based settings
Deploy managed-settings.json directly to a local client. It loads from disk without a proxy or server request.
Not detectable from here. Deploy the file, restart the client, then verify inside the client.
-
1
Write the policy file
On the Policies page, edit the Managed Settings response body, then copy the command for the client platform from File Deployment and run it in a terminal.
File locations
- macOS:
/Library/Application Support/GitHubCopilot/managed-settings.json
- Windows:
%ProgramFiles%\GitHubCopilot/managed-settings.json
- Linux:
/etc/github-copilot/managed-settings.json
On macOS and Linux, Copilot CLI requires a regular file owned by root that is not group- or world-writable, so the copied command uses sudo.
-
2
Reload the client
Restart the client so it loads the file, or in VS Code run > Developer: Sync Account Policy. File-based settings persist across accounts and don't expire like the SDK policy cache.
Use this to avoid proxying entirely, or deploy it alongside a server-managed response to test precedence. Deploying file-based settings