> For the complete documentation index, see [llms.txt](https://docs.sonarsource.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sonarsource.com/sonarqube-cli/integrations/github-copilot-cli.md).

# GitHub Copilot CLI

Install secrets-detection hooks, the SonarQube MCP Server, and Vortex analysis and Vortex context features for GitHub Copilot CLI with the SonarQube CLI.

`sonar integrate copilot` configures the SonarQube CLI to work alongside GitHub Copilot CLI. For GitHub Copilot Chat in VS Code, see [GitHub Copilot Chat in VS Code](#github-copilot-chat-in-vs-code). In an interactive terminal, the command prompts you to install each component:

* [Secrets detection](/sonarqube-cli/analysis/secrets-detection.md) that runs before GitHub Copilot CLI reads or writes files and blocks any operation that would expose a secret. Because GitHub Copilot CLI does not currently support a prompt-time hook, the integration can also install custom instructions that tell the agent to refuse working with exposed tokens.
* [The SonarQube MCP Server](https://docs.sonarsource.com/sonarqube-mcp-server/), which lets GitHub Copilot CLI fetch projects, issues, and rules directly.
* Sonar Vortex (when your connection has a Vortex subscription: SonarQube Cloud Team or Enterprise plan, or SonarQube Server 2026.5 or newer Enterprise and Data Center editions): one prompt that installs Vortex analysis and Vortex context together. Accepting it adds:
  * [Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis.md) instructions that tell GitHub Copilot CLI to run `sonar analyze agentic` on your changes at end of turn
  * `sessionStart` and `subagentStart` hooks that inject [Vortex context](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-context.md) when a session starts, giving GitHub Copilot CLI access to project guidelines, architecture, semantic navigation, and dependency context

Pass `--non-interactive` to accept every offered component without prompts (see [Non-interactive install](#non-interactive-install)).

## Prerequisites

* [The SonarQube CLI is installed and authenticated](/sonarqube-cli/quickstart-guide.md).
* GitHub Copilot CLI is installed and available in your terminal.
* You're working inside a project directory, which lets the CLI auto-detect the SonarQube project for the preflight summary.

## Install

Install once for this machine:

```bash
sonar integrate copilot
```

The command writes hooks and config to `~/.copilot/` and applies to every GitHub Copilot CLI session on this machine. See [Project versus global scope](/sonarqube-cli/integrations/integrations.md#project-versus-global-scope).

### What the command does

The integrator runs in three phases:

1. Discovery and validation. It locates your project's config using the [project key auto-detection](/sonarqube-cli/integrations/integrations.md#project-key-auto-detection) chain and verifies the token.
2. Health check and repair. It calls SonarQube to confirm the token, organization, and project are valid. If the token is broken and you're running interactively, it offers to refresh it.
3. Installation. For each component (secrets hook, prompt-secrets instructions, MCP server, and Vortex when eligible), the CLI prompts you to install it, skips it with an explanation, or accepts it automatically in non-interactive mode. Before writing files, it shows a [What will be installed](/sonarqube-cli/integrations/integrations.md#install-confirmation) summary of accepted features. In interactive mode, press Enter to confirm. Then it installs accepted components into `~/.copilot/`.

   Common skip reasons include:

   * Your connection does not have a Vortex subscription (only available with SonarQube Cloud Team or Enterprise plan, or SonarQube Server 2026.5 or newer Enterprise and Data Center editions).

### Options

| Option              | Description                                                                                                                        |
| ------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
| `--non-interactive` | Non-interactive mode (no prompts).                                                                                                 |
| `--global`, `-g`    | Deprecated since 1.9.0. The install is already global; using the flag prints a warning and does not change the installation scope. |

### Where files are installed

| Location        | Hook and instructions location                                                              |
| --------------- | ------------------------------------------------------------------------------------------- |
| User home       | `~/.copilot/` (hooks, settings, instructions)                                               |
| Shared binaries | `~/.sonar/sonarqube-cli/bin/` (auxiliary binaries for secrets detection and Vortex context) |

State for installed integrations is recorded in `~/.sonar/sonarqube-cli/state.json`. See [State and storage](/sonarqube-cli/administration/state-and-storage.md).

## Restart GitHub Copilot CLI

GitHub Copilot CLI reads its hook and MCP configuration at startup. Restart GitHub Copilot CLI for the integration to take effect.

## Vortex analysis and Vortex context

When you run `sonar integrate copilot` against a SonarQube Cloud project, the command writes instructions that tell GitHub Copilot CLI to run one end-of-turn `sonar analyze agentic --depth DEEP` command covering every file it modified that turn (repeat `--file` for each path, or fall back to the git change set). Those instructions go in `~/.copilot/instructions/sonarqube.instructions.md`. The CLI auto-detects the project key: the instructions omit `--project`. If analysis reports that no project is configured, the instructions tell the agent to stay silent for the rest of the session instead of repeating a skip notice.

It also writes `sessionStart` and `subagentStart` hooks that inject Vortex context when a Copilot session starts. If a previous install wrote `.github/skills/sonar-context-augmentation/SKILL.md`, update to SonarQube CLI 1.8.0 or later, then re-run `sonar integrate copilot` to replace that leftover skill with the session-start hooks.

For overviews of these features, see [Vortex analysis](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis.md) and [Vortex context](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-context.md).

## Verify it works

### Test the secrets hook

1. Create a file in your project with a fake-looking but secret-shaped value:

   ```javascript
   // secrets.js
   const API_KEY = "sqp_1aa323ae0689cd4a1abd062a2ad0a224ae8a1d13";
   ```
2. Ask GitHub Copilot CLI to read it: *"Read secrets.js."*
3. GitHub Copilot CLI should block the read and explain that the file contains a secret.

Once you've confirmed the hook is active, delete the test file.

### Test the MCP server

Ask GitHub Copilot CLI to list your SonarQube projects via the MCP server. If the call fails, run `sonar auth status` to confirm the underlying token is healthy and restart GitHub Copilot CLI.

### Test Vortex analysis

In GitHub Copilot CLI, ask: *"Run `sonar analyze --staged` and summarize new issues."* GitHub Copilot CLI should invoke the SonarQube CLI and report findings. This requires a [Sonar Vortex](/agent-centric-development-cycle/inside-your-agent-the-agentic-loop/sonar-vortex-analysis.md) subscription.

## Non-interactive install

For provisioning scripts, dotfiles, and onboarding automation:

```bash
sonar integrate copilot --non-interactive
```

In non-interactive mode the CLI does not prompt for feature selection, install confirmation, token repair, or feature removal. Every component that's not explicitly skipped is installed automatically. When you authenticate with [environment variables](/sonarqube-cli/using-sonarqube-cli/environment-variables.md), integrate commands also run in non-interactive mode even without the flag. Run [`sonar auth status`](/sonarqube-cli/using-sonarqube-cli/commands.md#sonar-auth-status) afterward to confirm everything is configured correctly.

## Uninstall

Run `sonar integrate copilot` again in an interactive terminal. For each installed feature, the CLI asks **Keep?**: answer No, confirm **Proceed with removal?**, and the CLI removes hooks, instructions, and state for that feature. Vortex is removed as one unit (Vortex analysis instructions and session-start hooks). See [integrations/README.md](/sonarqube-cli/integrations/integrations.md#removing-installed-features) for the full flow.

For a manual cleanup or non-interactive environments:

1. Delete the hook files written under `~/.copilot/`.
2. Remove the SonarQube MCP server entry from your GitHub Copilot CLI configuration.
3. Remove the integration entry from `~/.sonar/sonarqube-cli/state.json` (under `integrations.installed`).

See the SonarQube CLI [Uninstalling](/sonarqube-cli/administration/uninstall.md) page for the full removal procedure.

## GitHub Copilot Chat in VS Code

If you use GitHub Copilot Chat in VS Code rather than GitHub Copilot CLI, `sonar integrate copilot` still generates useful instruction files. It writes an instructions file that Copilot Chat reads automatically, giving it guidance on secrets detection, issue querying, and SonarQube CLI commands.

One component works differently in Copilot Chat: the [pre-tool secrets detection hook](/sonarqube-cli/analysis/secrets-detection.md) does not fire. It's wired for the Copilot CLI terminal agent only. The instruction file still tells Copilot Chat to check for secrets, but the check runs as a model instruction rather than an enforced hook.

Copilot Chat in VS Code can also access native SonarQube for VS Code tools available without any CLI setup (`#sonarqube_analyzeFile`, `#sonarqube_getPotentialSecurityIssues`, and others). See [AI agents](/sonarqube-for-vs-code/ai-capabilities/integrations.md) in SonarQube for VS Code for details.

For the full SonarQube MCP Server integration with Copilot in Agent mode, see [VS Code with GitHub Copilot](/sonarqube-mcp-server/setup/quickstart-guides/vs-code.md) in the MCP server docs.

## Related pages <a href="#related-pages" id="related-pages"></a>

* [Secrets detection](/sonarqube-cli/analysis/secrets-detection.md)
* [Analyzing local changes](/sonarqube-cli/analysis/analyzing-local-changes.md)
* [State and storage](/sonarqube-cli/administration/state-and-storage.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.sonarsource.com/sonarqube-cli/integrations/github-copilot-cli.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
