# GitHub Copilot CLI

> Run GitHub Copilot CLI on Tokens models with its bring-your-own-key environment variables: base URL, key, model, token limits, and what to check when it fails.

GitHub Copilot CLI is GitHub's terminal coding agent, started with the `copilot` command. Its bring-your-own-key (BYOK) mode replaces GitHub-hosted models with a provider you choose. With Tokens it uses the default `openai` provider type, which sends OpenAI Chat Completions requests to `https://tokens.bd/v1`.

This page is about the terminal agent. For Copilot Chat inside VS Code, see [GitHub Copilot in VS Code](/docs/github-copilot). The two are configured differently:

| | Copilot CLI (this page) | Copilot in VS Code |
| --- | --- | --- |
| Where you configure it | Environment variables read by `copilot` | `chatLanguageModels.json` in VS Code |
| Model choice | `COPILOT_MODEL` or `--model` | The model picker in Copilot Chat |
| Scope | The whole CLI session | Chat and utility tasks only; inline suggestions stay on GitHub |

:::note[Checked against the documentation]
Based on GitHub's [BYOK reference for Copilot CLI](https://docs.github.com/en/copilot/how-tos/copilot-cli/customize-copilot/use-byok-models), checked October 2026. That page does not name a Copilot CLI version; GitHub announced BYOK in a changelog entry dated 7 April 2026. We have not run Copilot CLI against Tokens end to end. Run `copilot help providers` in your installed version to compare it with this page.
:::

## What you need

- A Tokens key. Create one for Copilot CLI alone, with a monthly spend cap ([API keys](/docs/api-keys)).
- The model id from [/models](/models). The examples use `deepseek/deepseek-v4.1-flash`.
- Copilot CLI installed. GitHub's documented options are `npm install -g @github/copilot` (Node.js 22 or newer), `winget install GitHub.Copilot` on Windows, `brew install --cask copilot-cli`, or `curl -fsSL https://gh.io/copilot-install | bash` on macOS and Linux. On Windows, GitHub requires PowerShell 6 or newer.
- A model that supports tool calling and streaming. Copilot CLI returns an error if either is missing. GitHub recommends a context window of 128K tokens or more.

## Set it up

Copilot CLI turns BYOK on when `COPILOT_PROVIDER_BASE_URL` is set. Set the base URL, your key and the model, then start `copilot`:

:::code-tabs

```bash title="macOS / Linux"
export TOKENS_API_KEY="tok_live_your_key"
export COPILOT_PROVIDER_BASE_URL="https://tokens.bd/v1"
export COPILOT_PROVIDER_API_KEY="$TOKENS_API_KEY"
export COPILOT_MODEL="deepseek/deepseek-v4.1-flash"
copilot
```

```powershell title="Windows PowerShell"
$env:TOKENS_API_KEY = "tok_live_your_key"
$env:COPILOT_PROVIDER_BASE_URL = "https://tokens.bd/v1"
$env:COPILOT_PROVIDER_API_KEY = $env:TOKENS_API_KEY
$env:COPILOT_MODEL = "deepseek/deepseek-v4.1-flash"
copilot
```

:::

The PowerShell lines last for the current window. Keep the key in your shell profile or a secrets manager, not in a file inside a repository.

| Variable | Value for Tokens |
| --- | --- |
| `COPILOT_PROVIDER_BASE_URL` | `https://tokens.bd/v1`. Required. It ends in `/v1`, like the OpenAI example on GitHub's page. |
| `COPILOT_PROVIDER_TYPE` | Leave unset. The default is `openai`. Do not use `azure` or `anthropic` for Tokens. |
| `COPILOT_PROVIDER_API_KEY` | Your Tokens key. |
| `COPILOT_MODEL` | The Tokens model id, or pass `--model <id>` to `copilot`. Required. |

The key is the only credential Tokens needs. If you would rather use `COPILOT_PROVIDER_BEARER_TOKEN`, Tokens also accepts `Authorization: Bearer`, but the API key variable is the simpler choice.

### Token limits

Copilot CLI looks up context limits from a well-known model name. Tokens ids are not well-known names to it, so set the limits yourself:

```bash
export COPILOT_PROVIDER_MAX_PROMPT_TOKENS=120000
export COPILOT_PROVIDER_MAX_OUTPUT_TOKENS=8192
```

The numbers are placeholders. Copy the real context window and maximum output from the model's page in [/models](/models), and leave room for the output inside the context window. `COPILOT_PROVIDER_MODEL_ID` and `COPILOT_PROVIDER_WIRE_MODEL` exist for cases where the name the CLI should look up differs from the name sent to the provider. You do not need either with Tokens, because the id you set in `COPILOT_MODEL` is the id Tokens expects.

### The wire API setting

GitHub's page also lists `COPILOT_PROVIDER_WIRE_API`, but it does not say which values are accepted. Leave it unset. Tokens supports both [Chat Completions](/docs/chat-completions) and the [Responses API](/docs/responses), so the default works. Other guides set it to `responses` for specific models; if you try that, test with the check below first.

## Check that it works

Test the key and model outside Copilot CLI first:

```bash
curl https://tokens.bd/v1/chat/completions \
  -H "Authorization: Bearer $TOKENS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model": "deepseek/deepseek-v4.1-flash", "max_tokens": 16, "messages": [{"role": "user", "content": "Reply with OK"}]}'
```

Then run Copilot CLI with one prompt:

```bash
copilot -p "Reply with OK"
```

You should get a short answer, and the request should appear in usage analytics on your dashboard. To check tool calling, start `copilot` in a project and ask it to read a file. If the model answers but never touches your files, it probably does not support tool calling well; see [Tool calling](/docs/tool-calling).

## Choosing a model

Pick a model with reliable tool calling and a long context. [Choosing a model](/docs/choosing-a-model) compares them, and the `/models` catalog shows context and output limits for each. Switch for a session with `copilot --model <id>` or by changing `COPILOT_MODEL`. Only one provider configuration is active at a time.

## Limits and what to know

- **Spend.** An agent loops: one prompt can become many requests, each carrying the growing conversation. Use a key with a monthly spend cap ([API keys](/docs/api-keys)) and watch usage on the dashboard.
- **GitHub sign-in.** GitHub's announcement says signing in to GitHub is optional in BYOK mode, and that signing in adds GitHub features such as `/delegate`, GitHub code search and the GitHub MCP server. GitHub's install page lists an active Copilot subscription as a prerequisite. The BYOK page does not say which plans support BYOK. Ask whoever manages your Copilot plan if you are unsure.
- **Organization policy.** If your organization or enterprise has disabled Copilot CLI, you cannot use it, with or without BYOK.
- **What still goes to GitHub.** GitHub's page does not list it. It does say `COPILOT_OFFLINE=true` stops Copilot CLI contacting GitHub's servers. That setting does not make Tokens local: prompts and code context still go to `https://tokens.bd/v1`.
- **Model ids with a slash.** Tokens ids look like `provider/model`. GitHub's page does not discuss ids with a slash. If `COPILOT_MODEL` is rejected, test the id with the `curl` above first.
- **Sessions.** Start `copilot` in a shell where the variables are set. A session started elsewhere does not see them.

## Troubleshooting

**Copilot CLI still uses GitHub models.** `COPILOT_PROVIDER_BASE_URL` is not set in the shell that started `copilot`. Run `echo $COPILOT_PROVIDER_BASE_URL` (or `$env:COPILOT_PROVIDER_BASE_URL` in PowerShell).

**401 `missing_api_key` or `invalid_api_key`.** `COPILOT_PROVIDER_API_KEY` is empty, or it holds another provider's key. A Tokens key starts with `tok_live_`. See [Errors](/docs/errors).

**404 `model_not_found`.** `COPILOT_MODEL` is not an exact Tokens id. Copy it from [/models](/models) or `GET https://tokens.bd/v1/models`.

**404 `unsupported_endpoint`.** The base URL is missing `/v1`, or has an extra path. Use `https://tokens.bd/v1` exactly.

**An error about tool calling or streaming.** The model does not support one of them. Pick a model that does ([Streaming](/docs/streaming), [Tool calling](/docs/tool-calling)).

**403 `monthly_spend_cap_exceeded` or 402 `insufficient_credits`.** The key's cap or your balance is used up. Raise the cap or top up in [billing](/dashboard/billing).

**429 `rate_limited` or `concurrency_limit`.** The agent sent requests faster than your limits allow. Wait for `Retry-After`; see [Rate limits](/docs/rate-limits).

For the full list of codes, see [Errors](/docs/errors). Other problems: [Troubleshooting](/docs/troubleshooting).

---
Page: https://tokens.bd/docs/github-copilot-cli
