GitHub Copilot (VS Code)

Wire your Cocobox connections into GitHub Copilot Chat in VS Code via the Model Context Protocol.

Last updated

VS Code’s GitHub Copilot Chat supports the Model Context Protocol. Connecting it to Cocobox gives Copilot the ability to read your schema and run scoped queries — without ever seeing your database credentials.

Prerequisites

  • VS Code 1.95 or newer with GitHub Copilot Chat enabled.
  • A Cocobox sk-coco-* API key with toolsEnabled: true. See API keys.

1. Create the MCP config

Create or edit .vscode/mcp.json in your workspace:

{
  "servers": {
    "cocobox": {
      "type": "http",
      "url": "https://api.cocobox.io/v1/mcp",
      "headers": {
        "Authorization": "Bearer ${env:COCOBOX_API_KEY}"
      }
    }
  }
}

VS Code interpolates ${env:VAR} from your shell or the user-level mcp.json.

2. Reload VS Code

Run Developer: Reload Window (or restart VS Code). Open the MCP view in the sidebar — the cocobox server should be listed as Connected, with the tool catalog underneath.

3. Try it in Copilot Chat

Open Copilot Chat and ask, for example:

Using the cocobox MCP server, list my connections, then describe the orders table on the prod-readonly one.

Copilot will request permission to call each tool the first time. Approve, and the result streams back inline — including a code block of the SQL it executed and the rows returned. Every call is logged in the Cocobox audit log.

Workspace vs user config

FileScopeBest for
.vscode/mcp.jsonPer-workspaceSharing the wiring with teammates (commit this; let env vars carry the key).
~/.vscode/mcp.json (or settings.json mcp.servers)Per-userPersonal default that follows you across projects.

Workspace config wins when both exist.

Limiting what Copilot can do

Two layers of control:

  1. Cocobox key scope. Disable writes by leaving the key with read-only connection roles. Disable specific models by setting allowedModels.
  2. VS Code tool prompts. VS Code asks you to confirm each tool invocation by default. Approve once, always, or never per tool.

Troubleshooting

  • Authentication failed — verify $COCOBOX_API_KEY is exported in the shell that launched VS Code (Mac users: GUI launches don’t see your shell rc files; use https://github.com/sindresorhus/launch-agent or the Cocobox extension).
  • Tools list is empty after connect — check that tools_enabled is true on the key (GET /api-keys).
  • Mcp-Session-Id not retained — VS Code handles session ids automatically; if you see this complaint, update VS Code.