Skip to main content
This Workflow automatically sets up developers with access to GitHub Copilot. In this example, approval from a specific team is required. Depending on your organization’s requirements, you may want to configure a User input block instead, effectively allowing users to self-serve access to GitHub Copilot without needing approval from a specific team.

Prerequisites

Before getting started:
  • Before calling the GitHub API endpoint in the Async HTTP request block, your organization must already be on Copilot Business or Enterprise and have seat management policies configured.
  • You must create a secret in Cortex.
    • In this example, the secret in Cortex must be named GITHUB_COPILOT_TOKEN.

Step 1: Start creating the Workflow

Follow the steps in the documentation to create a Workflow and configure its basic settings. Note that Cortex has a pre-built template for this Workflow that contains the Async HTTP request block. The example on this page includes an additional Manual approval block that allows you to designate an approving team. Also in this example, the payload of the Async HTTP block includes approver": "{{actions.manual-approval.outputs.actor}}, which references the output of the Manual approval block. This reference is not included in the pre-built Workflow template.

Step 2: Add blocks to the Workflow

The instructions on this page describe how to create this Workflow in the Cortex UI, but it is also possible to copy the Workflow YAML and add it to your workspace via the Cortex CLI. This allows you to quickly set up the example configuration then iterate on it for your own use case. Expand the tile below to learn more.
To upload the Workflow example YAML into your workspace:
  1. Save the Workflow example YAML file below:
  1. Use the Cortex CLI to run this command, using the path to your Workflow YAML file:
    cortex workflows create -f <path-to-your-workflow.yaml>
Expand the tiles below to learn about each block in this Workflow and how to configure them in the Cortex UI:
In this block, you select which team has to give approval for the user to access GitHub Copilot.
  1. Click + in the center of the page. In the block library modal, choose Manual approval.
  2. In the block configuration side panel, enter a name and unique slug for this block.
    • In this example, we use the name Manual approval and the slug manual-approval.
  3. Under Teams allowed to approve, select the teams authorized to approve access to GitHub Copilot.
  4. Save the block.
This block looks at the initiating user’s identity mapping in Cortex for GitHub, then calls the GitHub API to grant access to Copilot for that user.
  1. Click + in the center of the page. In the block library modal, choose Async HTTP request.
  2. In the block configuration side panel, enter a name and unique slug for this block.
    • In this example, we use the name Grant access to Copilot and the slug copilot-access.
  3. Configure the block:
    • HTTP method: POST
    • URL: Enter a URL for the request.
      • In this example, we call the GitHub endpoint that adds users to your org’s Copilot subscription: https://api.github.com/orgs/<your-org>/copilot/billing/selected_users
    • Headers: Authorization: Bearer {{ context.secrets.GITHUB_COPILOT_TOKEN }}
    • Payload:
  1. Save the block.

Step 3: Run the Workflow

When you run the Workflow, the following events happen:
  • The Workflow pauses to collect a response from a member of one of the teams specified during the Manual approval block.
  • After a user gives their approval, the Async HTTP request block runs. It uses the initiator of the Workflow as the GitHub user, then makes a call to the GitHub API to provision access to Copilot for that user.
Last modified on September 28, 2026