Surfil detects Copilot and connects its MCP
Surfil recognises Copilot on your machine. Its completions are served through GitHub's own proxy and are not user-redirectable, so Surfil does not intercept that traffic. Where Copilot runs inside an MCP host, its MCP routes through Surfil, and full interception is on the roadmap via the on-device network layer.
surfil verify on any receipt - the signature is the proof.One layer in your stack
Beside Copilot on your device: detected, with its MCP connected where a host exposes it. Its GitHub-proxied completions are not redirectable today.
What you get today
Recognised, not guessed
`surfil doctor` detects Copilot from a real on-device signal and shows exactly how it connects.
MCP where available
When Copilot runs in an MCP host, that host's MCP routes through Surfil's one governed endpoint.
Honest about reach
Copilot's completions stay on GitHub's proxy; Surfil never claims to intercept traffic it cannot see.
Add Surfil to Copilot
Three steps, no config rewrite, reversible byte-for-byte.
Why it fits Copilot
Honest by default
Surfil detects Copilot and states plainly what it can and cannot intercept - never a fabricated claim.
MCP where it exists
If Copilot runs in an MCP host, that host's MCP servers route through Surfil's one endpoint.
Reversible byte-for-byte
Nothing about Copilot is rewritten; a clean uninstall leaves your setup exactly as it was.
Every agent, the same layer
One adapter per agent, all on the same on-device interception point.
Claude Code
Between Claude Code and your model provider, on your device - one interception point, never a second proxy stacked into the path.
See adapter →Cursor
At Cursor's MCP layer on your device: one endpoint for its MCP servers today, with full-traffic interception on the roadmap via the network layer.
See adapter →Codex
One adapter under Codex, on your device - the same interception point every other agent uses, never a stacked second layer.
See adapter →MCP agents
In front of your MCP servers on your device, collapsing many endpoints into one interception point you can meter and govern.
See adapter →Add Surfil to Copilot
Core installs beside the agents you already run, byte-exact, and the first signed receipt arrives after one normal week of traffic.