Surfil
// integration

Surfil detects Copilot and connects its MCP

Surfil recognises Copilot on your machine. Its completions are served through GitHub's own proxy and are not user-redirectable, so Surfil does not intercept that traffic. Where Copilot runs inside an MCP host, its MCP routes through Surfil, and full interception is on the roadmap via the on-device network layer.

surfil verify rcpt_8f2a
Signed savings receiptVALID
receiptrcpt_8f2a
typeprefix-cache + prune
saved48,200 tokens
measuredbefore / after
signatureed25519:… (epoch 7)
verifiedoffline · no account
Run surfil verify on any receipt - the signature is the proof.
Where it sits

One layer in your stack

Beside Copilot on your device: detected, with its MCP connected where a host exposes it. Its GitHub-proxied completions are not redirectable today.

youCopilot (GitHub-proxied completions)
surfilSurfil · detection + MCP where available
providerGitHub / model provider
One interception point, on your device. Surfil never chains a second proxy in front of Copilot, and passthrough to the provider is byte-exact.
What you get

What you get today

Recognised, not guessed

`surfil doctor` detects Copilot from a real on-device signal and shows exactly how it connects.

MCP where available

When Copilot runs in an MCP host, that host's MCP routes through Surfil's one governed endpoint.

Honest about reach

Copilot's completions stay on GitHub's proxy; Surfil never claims to intercept traffic it cannot see.

Setup

Add Surfil to Copilot

Three steps, no config rewrite, reversible byte-for-byte.

1Install Surfil; it detects Copilot and reports how it connects, with no config rewrite.
2Use Copilot as usual; its completions are unchanged, and any MCP host it runs in is governed.
3Full completion interception arrives with the on-device network layer, not a config edit.
What holds

Why it fits Copilot

Honest by default

Surfil detects Copilot and states plainly what it can and cannot intercept - never a fabricated claim.

MCP where it exists

If Copilot runs in an MCP host, that host's MCP servers route through Surfil's one endpoint.

Reversible byte-for-byte

Nothing about Copilot is rewritten; a clean uninstall leaves your setup exactly as it was.

Works with

Every agent, the same layer

One adapter per agent, all on the same on-device interception point.

Add Surfil to Copilot

Core installs beside the agents you already run, byte-exact, and the first signed receipt arrives after one normal week of traffic.