npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@alvin0/ai-agent-sdk-provider-copilot

v0.1.4

Published

Universal GitHub Copilot adapter, OAuth device flow, token exchange, and provider plugin for ai-agent-sdk

Readme

@alvin0/ai-agent-sdk-provider-copilot

Runtime: Universal (Edge/Worker, browser, Deno, Bun, and Node with an injected credential store).

pnpm add @alvin0/ai-agent-sdk-core @alvin0/ai-agent-sdk-provider-copilot

Universal GitHub Copilot adapter: OAuth device flow, the two-tier credential contract, Copilot token exchange, model-driven endpoint routing across /responses and /chat/completions, catalog discovery, and a transactional provider plugin. A CopilotCredentialStore must be injected; filesystem and environment defaults belong to the Node auth package.

Use defineCredentialStore<CopilotAuthFile>({ id, label, read, commit }) to persist GitHub credentials in your database. getCopilotToken(store, { tokenCache }) acquires a short-lived API token; forceRefresh: true invalidates its cached entry. Share tokenCache with copilotPlugin, or implement its acquire/invalidate methods to own database caching and exchange. exchangeCopilotToken remains available for standalone exchange. The GitHub credential does not rotate. See the working database example.

import { ModelRegistry } from '@alvin0/ai-agent-sdk-core'
import { copilotPlugin, memoryCopilotCredentialStore } from '@alvin0/ai-agent-sdk-provider-copilot'

const registry = new ModelRegistry()
registry.install(copilotPlugin({ authStore: memoryCopilotCredentialStore(tokens) }))

Use copilotAdapter() for manual route registration. The store contract is Universal; a browser, Worker, secret manager, or Node package owns persistence.

Composition: runtime.providers. Lifecycle: inert-runtime-owned-registration; the runtime owns registration while the injected credential store remains caller-owned.

Client identity

Three exported constants decide which client this SDK presents itself as:

| Constant | Module | Override | | --- | --- | --- | | COPILOT_OAUTH_CLIENT_ID | src/oauth.ts | clientId option | | COPILOT_EDITOR_VERSION | src/adapter.ts | editorHeaders.editorVersion | | COPILOT_EDITOR_PLUGIN_VERSION | src/adapter.ts | editorHeaders.editorPluginVersion |

Their defaults make this SDK identify itself as an editor client. That is required for the surface to answer: copilot_internal/v2/token only accepts a token minted by an OAuth App on GitHub's allowlist, and the Copilot endpoints answer HTTP 400 when either editor header is missing.

They are exported and overridable rather than hidden precisely because presenting as another client is a decision you should be able to read off the source and change. Use your own account, and prefer a provider's official first-party surface for production workloads.

Two of the three default values are confirmed against a live Copilot account; one is not. A live run on 2026-09-10 sent both editor headers on the token exchange, GET /models, a streaming /chat/completions call and POST /embeddings, and none answered HTTP 400 — so COPILOT_EDITOR_VERSION and COPILOT_EDITOR_PLUGIN_VERSION are confirmed as of that date. COPILOT_OAUTH_CLIENT_ID is still unconfirmed: that run used an existing user token rather than the device flow, so this client id never reached GitHub's allowlist check. The source carries a copilot-identity comment naming what must be confirmed and how.

License

MIT