Files
TylerLeonhardtandCopilot 2f84f5b382 authentication: Add GitHub session issuer provenance (#337846)
* authentication: Add GitHub session issuer provenance

Expose optional session authorizationServer metadata through authIssuers and authentication RPCs, populate it for GitHub sessions, and route in-repository consumers from the selected session. Keep existing single-host configuration and account-selection behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* authentication: Preserve public static-token MCP sessions

Keep issuer validation on the enterprise MCP path and preserve the fixed public endpoint for static-token authentication. Cover definition creation and resolution using StaticGitHubAuthenticationService.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* i18n: Register workbench GitHub service translations

Register the service's new localized authentication error with the workbench translation project so the CI translation-reminder rule passes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-09-25 01:56:10 +00:00
..

GitHub Authentication for Visual Studio Code

Notice: This extension is bundled with Visual Studio Code. It can be disabled but not uninstalled.

Features

This extension provides support for authenticating to GitHub. It registers the github Authentication Provider that can be leveraged by other extensions. This also provides the GitHub authentication used by Settings Sync.

GitHub Enterprise

The github-enterprise provider authenticates to the GHE.com or GitHub Enterprise Server instance configured by github-enterprise.uri:

{
	"github-enterprise.uri": "https://github.example.com"
}

GitHub.com accounts use the github provider and do not need this setting. Account and session IDs, labels, token storage, and Microsoft account links retain their existing behavior.

Session provenance

The proposed authIssuers API exposes optional AuthenticationSession.authorizationServer provenance. This built-in extension supplies it on every returned session and every added, changed, or removed session event, including sessions restored from saved tokens or brokered through Microsoft:

  • github: https://github.com/login/oauth
  • github-enterprise: the configured instance's existing /login/oauth server

New sessions take their issuer from the token result and retain it in storage. Sessions without it, including older saved sessions and sessions supplied by Codespaces, are populated using the provider's fallback base URI before being returned to clients, without requiring a new sign-in.

The value identifies the OAuth authorization server, not a REST API endpoint, resource audience, or Copilot endpoint. Its presence does not imply an enterprise account: GitHub.com sessions also include it. Consumers should use the provider ID and the returned issuer rather than infer the instance from an account label.

Extensions using this proposed property must enable authIssuers. The existing issuer filter can select the configured provider:

const session = await vscode.authentication.getSession('github-enterprise', ['repo'], {
	createIfNone: true,
	authorizationServer: vscode.Uri.parse('https://github.example.com/login/oauth')
});

Adoption by external extensions, including the separately released GitHub Pull Requests extension, is a separate change.