azure-hosted-copilot-sdk
microsoft/azure-skills
Build, deploy, and modify GitHub Copilot SDK apps on Azure with SDK-aware scaffolding and BYOM support
What is azure-hosted-copilot-sdk?
azure-hosted-copilot-sdk is a skill for coding agents that handles the full lifecycle of GitHub Copilot SDK applications on Azure. It auto-detects Copilot SDK codebases via package.json markers or source file patterns, then orchestrates scaffolding, infrastructure setup, model configuration, and deployment. It acts as the mandatory entry point when @github/copilot-sdk or CopilotClient is present, coordinating azure-prepare and azure-deploy as sub-skills. Not for Copilot Extensions, Foundry agents, or general web apps.
- Detects Copilot SDK codebases by scanning package.json and source files for @github/copilot-sdk, CopilotClient, or createSession markers
- Scaffolds new Copilot SDK apps using the azure-samples/copilot-sdk-service template (Express/TS API, React/Vite UI, Bicep infra, Dockerfiles)
- Adds a Copilot SDK service alongside an existing repo, adapting azure.yaml to include both
- Adds Azure infra to an existing working Copilot SDK app for deployment
- Configures model selection: GitHub default, GitHub-specific model, or Azure BYOM with DefaultAzureCredential/ManagedIdentityCredential
- Orchestrates azure-prepare → azure-validate → azure-deploy in sequence after scaffolding
How to install azure-hosted-copilot-sdk
npx skills add https://github.com/microsoft/azure-skills --skill azure-hosted-copilot-sdk- Docker installed and running (docker info must succeed)
- Node.js and npx available for azd init and skill installation
- Azure Developer CLI (azd) installed
- Azure subscription for deployment
- AGENTS.md reviewed in the target repo if present
How to use azure-hosted-copilot-sdk
- 1.Install the skill: npx skills add https://github.com/microsoft/azure-skills --skill azure-hosted-copilot-sdk
- 2.For existing codebases, the skill auto-detects @github/copilot-sdk, CopilotClient, or createSession in package.json or source files
- 3.Choose your route: scaffold new app (Step 2A), add SDK service to existing repo (Step 2B), or add infra to existing SDK app (Step 2C)
- 4.For new apps, run: azd init --template azure-samples/copilot-sdk-service
- 5.Configure your model: use GitHub default, specify a model name via listModels(), or set up Azure BYOM with DefaultAzureCredential
- 6.For BYOM, authenticate using DefaultAzureCredential (local dev) or ManagedIdentityCredential (production) via bearerToken only
- 7.Deploy by invoking azure-prepare → azure-validate → azure-deploy in order
- 8.For deploy-only scenarios where .azure/deployment-plan.md already exists, use azure-deploy instead
Use cases
- Building a new Copilot-powered app from scratch on Azure
- Adding a Copilot SDK service to an existing repository
- Preparing an existing Copilot SDK app for Azure deployment
- Configuring Bring Your Own Model (BYOM) with an Azure-hosted model
- Modifying or adding features to an app that uses @github/copilot-sdk
- Developers building GitHub Copilot SDK-powered applications
- Teams deploying Copilot-integrated services to Azure
- Engineers integrating BYOM (Bring Your Own Model) with Azure credentials
- Developers using coding agents like Claude Code or Cursor on Copilot SDK projects
azure-hosted-copilot-sdk FAQ
Use this skill whenever your codebase contains @github/copilot-sdk in package.json or CopilotClient/createSession in source files. It takes priority over azure-prepare and orchestrates it as a sub-skill.
No. If the codebase already has .azure/deployment-plan.md and you only want to deploy, use azure-deploy instead. This skill handles preparation and scaffolding.
Only bearerToken via DefaultAzureCredential (local dev) or ManagedIdentityCredential (production) is supported. No other auth pattern is allowed.
No. Use microsoft-foundry for Foundry agents. This skill is specifically for apps using the @github/copilot-sdk package.
The azure-samples/copilot-sdk-service template includes an Express/TypeScript API, React/Vite web UI, Bicep infrastructure, Dockerfiles, and token scripts. You should not recreate these manually.
Full instructions (SKILL.md)
Source of truth, from microsoft/azure-skills.
name: azure-hosted-copilot-sdk description: "Build, deploy, and modify GitHub Copilot SDK apps on Azure. MANDATORY when codebase contains @github/copilot-sdk or CopilotClient in package.json. PREFER OVER azure-prepare when copilot-sdk markers detected. WHEN: copilot SDK, @github/copilot-sdk, copilot-powered app, build copilot app, prepare copilot app, add feature to copilot app, modify copilot app, BYOM, bring your own model, CopilotClient, createSession, sendAndWait, azd init copilot. DO NOT USE FOR: deploying already-prepared copilot-sdk apps (use azure-deploy), general web apps without copilot SDK (use azure-prepare), Copilot Extensions, Foundry agents (use microsoft-foundry)." license: MIT metadata: author: Microsoft version: "1.1.3"
GitHub Copilot SDK on Azure
Codebase Detection — MANDATORY FIRST CHECK
⚠️ CRITICAL: This check MUST run before ANY other skill (azure-prepare, azure-deploy, etc.) when an existing codebase is present.
Detection procedure (run IMMEDIATELY for any build/modify/add-feature/prepare prompt):
- Read
package.jsonin the workspace root (and any*/package.jsonone level deep) - Check if
@github/copilot-sdkorcopilot-sdkappears inname,dependencies, ordevDependencies - If NOT found in package.json, scan
.tsand.jsfiles forCopilotClientorcreateSession - If ANY marker is found → invoke this skill as the entry point. Do not route directly to azure-prepare or azure-deploy — this skill orchestrates them as sub-skills.
| Marker | Where to check |
|---|---|
@github/copilot-sdk | package.json dependencies or devDependencies |
copilot-sdk | package.json name or dependencies |
CopilotClient | Source files (.ts, .js) |
createSession + sendAndWait | Source files (.ts, .js) |
Generic prompts that MUST trigger this skill when markers are detected:
| Prompt pattern (no "copilot" keyword) | Why this skill |
|---|---|
| "Build this app" / "Prepare this app for Azure" | Codebase contains @github/copilot-sdk - needs SDK-aware scaffolding |
| "Add a new feature to this app" | Requires SDK-aware implementation patterns |
| "Update this app" / "Modify this app" | Must preserve SDK integration patterns |
⚠️ Warning: ANY build, modify, add-feature, or prepare prompt targeting an existing codebase MUST route to this skill when codebase contains
@github/copilot-sdk, even if the prompt does not mention "copilot". This skill then orchestrates azure-prepare and azure-deploy as sub-skills.
⚠️ Yield to azure-deploy: When the codebase already has
.azure/deployment-plan.mdand the user wants to deploy (not modify or add features), route to azure-deploy instead. This skill handles preparation; azure-deploy handles execution.
Step 1: Route
| User wants | Action |
|---|---|
| Build new (empty project) | Step 2A (scaffold) |
| Add new SDK service to existing repo | Step 2B (scaffold alongside) |
| Deploy existing SDK app to Azure | Step 2C (add infra to existing SDK app) |
| Modify/add features to existing SDK app | Use codebase context + SDK references to implement |
| Add SDK to existing app code | Integrate SDK |
| Use Azure/own model | Step 3 (BYOM config) |
Step 2A: Scaffold New (Greenfield)
azd init --template azure-samples/copilot-sdk-service
Template includes API (Express/TS) + Web UI (React/Vite) + infra (Bicep) + Dockerfiles + token scripts — do NOT recreate. See SDK ref.
Step 2B: Add SDK Service to Existing Repo
User has existing code and wants a new Copilot SDK service alongside it. Scaffold template to a temp dir, copy the API service + infra into the user's repo, adapt azure.yaml to include both existing and new services. See deploy existing ref.
Step 2C: Deploy Existing SDK App
User already has a working Copilot SDK app and needs Azure infra. See deploy existing ref.
Step 3: Model Configuration
Three model paths (layers on top of 2A/2B):
| Path | Config |
|---|---|
| GitHub default | No model param — SDK picks default |
| GitHub specific | model: "<name>" — use listModels() to discover |
| Azure BYOM | model + provider with bearerToken via DefaultAzureCredential |
⚠️ BYOM Auth — MANDATORY: Azure BYOM configurations MUST use
DefaultAzureCredential(local dev) orManagedIdentityCredential(production) to obtain abearerToken. The ONLY supported auth pattern isbearerTokenin the provider config. See auth-best-practices.md for the credential pattern and model config ref for the full BYOM code example.
See model config ref.
Step 4: Deploy
Invoke azure-prepare (skip its Step 0 routing — scaffolding is done) → azure-validate → azure-deploy in order.
Rules
- Read
AGENTS.mdin user's repo before changes - Docker required (
docker info) - BYOM auth: ONLY
bearerTokenviaDefaultAzureCredentialorManagedIdentityCredential— no other auth pattern is supported
Related skills
More from microsoft/azure-skills and the wider catalog.
finetuning
Fine-tune models on Azure AI Foundry with SFT, DPO, or RFT training methods.
azure-ai
Azure AI services skill for Search, Speech, OpenAI, and Document Intelligence in coding agents
azure-deploy
Execute Azure deployments for prepared applications with built-in error recovery and validation.
azure-diagnostics
Debug Azure production issues using AppLens, Azure Monitor, resource health, and systematic triage.
azure-prepare
Generate Azure deployment infrastructure (Bicep/Terraform, azure.yaml, Dockerfiles) for new or existing apps
azure-storage
Azure Storage skill: Blob, File Shares, Queue, Table, and Data Lake with access tier guidance and lifecycle management