Skip to content

Commit bfffc77

Browse files
committed
feat(copilot): add BYOK provider parity
1 parent e9720c2 commit bfffc77

27 files changed

Lines changed: 2798 additions & 143 deletions
Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,2 @@
1-
f7247b5bbfe3f96bffffd25a8be2f89b37999e36731f34a159ae21ded1cedd05 plugin-sdk-api-baseline.json
2-
ce88a53dadc194ceccc63f50146aee03a1a425f551117da826a21519d5bf80db plugin-sdk-api-baseline.jsonl
1+
267b152897f63cb73d1df4357887c1943fdb04ec5a26f780a3632e7661ab251d plugin-sdk-api-baseline.json
2+
6be9b74fdee8d8928fdb667515b2859c6db6aa7c13c524d7c86587a95477aa1c plugin-sdk-api-baseline.jsonl

docs/plugins/copilot.md

Lines changed: 70 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -103,8 +103,65 @@ The harness advertises support for the canonical `github-copilot` provider
103103

104104
- `github-copilot`
105105

106-
Anything outside that set falls through `selection.ts`'s `auto_pi` branch back
107-
to PI.
106+
It also supports custom `models.providers` entries when the selected model has
107+
a non-empty `baseUrl` and one of these API shapes:
108+
109+
- `openai-responses`
110+
- `openai-completions`
111+
- `ollama` (OpenAI-compatible completions)
112+
- `azure-openai-responses`
113+
- `anthropic-messages`
114+
115+
Native provider ids such as `openai`, `anthropic`, `google`, and `ollama` remain
116+
owned by their native runtimes. Use a distinct custom provider id when routing
117+
an endpoint through Copilot BYOK.
118+
119+
Copilot BYOK endpoints must be public-network HTTPS URLs. The harness gives the
120+
Copilot SDK a per-attempt loopback proxy URL, then forwards provider traffic
121+
through OpenClaw's guarded fetch path so DNS pinning and SSRF policy stay
122+
owned by OpenClaw. Use the native OpenClaw runtime for local Ollama, LM Studio,
123+
or LAN model servers.
124+
125+
## BYOK
126+
127+
Copilot BYOK uses the SDK's session-level custom provider contract. OpenClaw
128+
passes the resolved model endpoint, API key, bearer-token mode, headers, model
129+
id, and context/output limits without moving provider transport logic into
130+
core.
131+
132+
For example:
133+
134+
```json5
135+
{
136+
agents: {
137+
defaults: {
138+
model: "custom-proxy/llama-3.1-8b",
139+
models: {
140+
"custom-proxy/llama-3.1-8b": {
141+
agentRuntime: { id: "copilot" },
142+
},
143+
},
144+
},
145+
},
146+
models: {
147+
mode: "merge",
148+
providers: {
149+
"custom-proxy": {
150+
baseUrl: "https://api.example.com/v1",
151+
apiKey: "${CUSTOM_PROXY_API_KEY}",
152+
api: "openai-responses",
153+
authHeader: true,
154+
models: [{ id: "llama-3.1-8b", name: "Llama 3.1 8B" }],
155+
},
156+
},
157+
},
158+
}
159+
```
160+
161+
BYOK sessions are separately keyed from subscription sessions and from other
162+
endpoints or credential fingerprints. Rotating the key, headers, model, or
163+
endpoint creates a fresh Copilot SDK session instead of resuming incompatible
164+
state.
108165

109166
## Auth
110167

@@ -151,10 +208,11 @@ Override with `copilotHome: <path>` on the attempt input when you need a
151208
custom location (for example, a shared mount for migration).
152209

153210
Live harness tests use `OPENCLAW_COPILOT_AGENT_LIVE_TOKEN` when a direct token
154-
is needed. The shared live-test setup intentionally scrubs `COPILOT_GITHUB_TOKEN`,
155-
`GH_TOKEN`, and `GITHUB_TOKEN` after staging real auth profiles into the isolated
156-
test home, so passing a `gh auth token` value through the dedicated live-test
157-
variable avoids false skips without exposing the token to unrelated suites.
211+
is needed. The shared live-test setup intentionally scrubs
212+
`COPILOT_GITHUB_TOKEN`, `GH_TOKEN`, and `GITHUB_TOKEN` after staging real auth
213+
profiles into the isolated test home, so passing a `gh auth token` value
214+
through the dedicated live-test variable avoids false skips without exposing
215+
the token to unrelated suites.
158216

159217
## Configuration surface
160218

@@ -163,9 +221,9 @@ The harness reads its config from per-attempt input
163221
`extensions/copilot/src/`:
164222

165223
- `copilotHome` — per-agent CLI state directory (defaults documented above).
166-
- `model` — string or `{ provider, id, api? }`. When omitted, OpenClaw uses
167-
the agent's normal model selection and the harness verifies the resolved
168-
provider is in the supported set.
224+
- `model` — string or `{ provider, id, api?, baseUrl?, headers?, authHeader? }`.
225+
When omitted, OpenClaw uses the agent's normal model selection and the
226+
harness verifies the resolved provider is supported.
169227
- `reasoningEffort``"low" | "medium" | "high" | "xhigh"`. Maps from
170228
OpenClaw's `ThinkLevel` / `ReasoningLevel` resolution in
171229
`auto-reply/thinking.ts`.
@@ -252,9 +310,9 @@ under `describe("runSideQuestion")`.
252310

253311
## Limitations
254312

255-
- The harness only claims the canonical `github-copilot` provider at MVP.
256-
Additional providers (BYOK or otherwise) should land in follow-up PRs that
257-
ship the adapter alongside the wire-up.
313+
- The harness claims `github-copilot` plus unowned custom BYOK provider ids.
314+
Manifest-owned native provider ids stay on their owning runtime even when
315+
`agentRuntime.id` is forced to `copilot`.
258316
- The harness does not deliver TUI; PI's TUI is unaffected and remains the
259317
fallback for whatever runtimes do not have a peer surface.
260318
- PI session state is not migrated when an agent switches to `copilot`.

extensions/copilot/README.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,10 +10,11 @@ openclaw plugins install @openclaw/copilot
1010

1111
Restart the Gateway after installing or updating the plugin.
1212

13-
The harness claims the canonical subscription `github-copilot` provider and
14-
is opt-in only — selection requires explicit `agentRuntime.id: "copilot"`
15-
on a model or provider entry; `auto` never picks it. PI remains the default
16-
embedded runtime.
13+
The harness claims the canonical subscription `github-copilot` provider plus
14+
custom BYOK provider entries that the Copilot SDK can represent. Manifest-owned
15+
native provider ids stay with their owning runtimes. The harness is opt-in only:
16+
selection requires explicit `agentRuntime.id: "copilot"` on a model or provider
17+
entry; `auto` never picks it. PI remains the default embedded runtime.
1718

1819
See [GitHub Copilot agent runtime](../../docs/plugins/copilot.md) for
1920
configuration, the doctor contract, transcript mirroring, compaction, side

0 commit comments

Comments
 (0)