MCP for Copilot
Provides an OpenAI-compatible chat completions gateway and LLM provider adapter, enabling OpenAI SDK clients to use the server and routing tool-augmented conversations to GPT-6 family models.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP for CopilotList the files in the current directory and summarize what this project does."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
๐ฐ๏ธ MCP for Copilot
Give Copilot hands.
A production-ready Model Context Protocol gateway. Use it as a Python library or deploy it as an OpenAI-compatible FastAPI service.
Quick Start ยท Installation ยท Examples ยท Architecture ยท Docs ยท Contributing
๐ฏ What is this?
Copilot is a strong reasoning assistant, but on its own it cannot read your files, query your database, or run your tools. MCP for Copilot connects it to any MCP server and puts three safety gates in front of every tool call: an allowlist, an approval layer, and argument validation.
It speaks two protocols at once โ MCP on the tool side, OpenAI on the client side โ so any OpenAI SDK client can use it as a drop-in replacement, and any MCP server can be its tool provider.
Related MCP server: LangGraph FastAPI MCP Server
โจ Features
๐ Three MCP transports โ
stdio,http(streamable), andsse๐ง GPT-6 family aware โ Sol, Luna, Astra, and GPT-5.6 Sol/Luna with correct context windows, output caps, and pricing metadata
๐ก๏ธ Three-gate tool safety โ allowlist โ approval โ dispatch, and it fails closed at every gate
โ Argument validation โ JSON-schema subset validation before dispatch, so a malformed call never reaches your server
๐ฆ Risky-tool detection โ 40+ mutating verbs (
write,delete,exec, โฆ) are flagged automatically; unknown tools are treated as risky๐ Secret redaction โ 11 regex rules scrub keys, tokens, and JWTs from every log line and error message
๐งฏ Prompt-injection guard โ tool output is wrapped and labelled as untrusted data before it re-enters the model context
๐ Streaming โ OpenAI-compatible SSE with the exact chunk format clients expect
๐ณ Multi-stage Docker โ one image, both modes, non-root user, healthcheck
๐งฉ Zero-config library mode โ
pip installand go; no server required๐งช Typed and tested โ full type hints,
mypy --strict, 3-layer test suite
๐ Quick Start
Option A โ Use as a library
pip install "mcp-for-copilot[library]"import asyncio
from mcp_for_copilot import Gateway
async def main():
async with Gateway() as gateway:
result = await gateway.chat([
{"role": "user", "content": "List the files in the current directory."}
])
print(result.content)
print("tools used:", result.used_tools)
asyncio.run(main())Option B โ Deploy as a server
pip install "mcp-for-copilot[server]"
export LLM_API_KEY=sk-...
mcp-for-copilot servecurl http://localhost:8000/v1/chat/completions \
-H "Content-Type: application/json" \
-d '{"model": "gpt-6-sol", "messages": [{"role": "user", "content": "Hello!"}]}'That is the whole setup. Any OpenAI SDK client works against it unchanged.
๐ฆ Installation
pip
# Library only โ talk to an MCP server from your own code
pip install "mcp-for-copilot[library]"
# Server โ FastAPI gateway + stdio MCP server
pip install "mcp-for-copilot[server]"
# Everything
pip install "mcp-for-copilot[all]"Docker
docker run --rm -p 8000:8000 \
-e LLM_API_KEY=sk-... \
ghcr.io/rwamyth-blip/mcp-for-copilot:latestFrom source
git clone https://github.com/rwamyth-blip/mcp-for-copilot.git
cd mcp-for-copilot
pip install -e ".[all,dev]"
cp .env.example .env # then edit .env๐ก Usage Examples
1. Library โ chat with tools, with an audit trail
import asyncio
from mcp_for_copilot import Gateway
async def main():
async with Gateway() as gateway:
result = await gateway.chat(
[{"role": "user", "content": "How many documents are in the users collection?"}],
system="You are a helpful data assistant.",
)
print(result.content)
for call in result.invocations:
status = "ok" if call["executed"] and not call["is_error"] else "blocked"
print(f" [{status}] {call['tool']} โ {call['reason']}")
asyncio.run(main())2. Server โ OpenAI SDK, unchanged
from openai import OpenAI
client = OpenAI(base_url="http://localhost:8000/v1", api_key="not-needed-locally")
response = client.chat.completions.create(
model="sol", # alias for gpt-6-sol
messages=[{"role": "user", "content": "Summarise README.md"}],
)
print(response.choices[0].message.content)3. Custom approval policy โ approve only what you trust
import asyncio
from mcp_for_copilot import Gateway, static_approver
async def main():
approver = static_approver(allow=["write_file"], deny=["delete_file"])
async with Gateway(approver=approver) as gateway:
result = await gateway.chat([
{"role": "user", "content": "Write 'hello' to notes.txt"}
])
print(result.content)
asyncio.run(main())4. CLI โ one-shot prompt
mcp-for-copilot chat "What models do you support?" --json
mcp-for-copilot models
mcp-for-copilot status๐๏ธ Architecture
flowchart LR
subgraph Client["Client side"]
A["OpenAI SDK<br/>/ any HTTP client"]
B["Your Python code"]
end
subgraph Gateway["mcp-for-copilot"]
C["FastAPI app<br/>/v1/chat/completions"]
D["Gateway facade"]
E["Orchestrator<br/>model โ tool โ model"]
F["ToolRouter<br/>allowlist + schema"]
G["ApprovalLayer<br/>fail closed"]
H["LLMProvider<br/>OpenAI adapter"]
I["MCPClient<br/>stdio / http / sse"]
end
subgraph Tools["Tool side"]
J["MCP server"]
K["Files, DB, APIs"]
end
L["GPT-6 Sol"]
A --> C --> D --> E
B --> D
E --> H --> L
E --> F --> G --> I --> J --> K
J -. "tool schemas" .-> FThe three gates
Every tool call the model requests must pass all three, in order:
Gate | Component | Behaviour on failure |
1. Allowlist |
| Denied โ reported to the model as an error result |
2. Approval |
| Denied โ fails closed when no approver is configured |
3. Dispatch |
| Error captured and returned; the turn continues |
A denied tool never aborts the turn. The model is told why it was denied and can explain the outcome or try a different approach.
Why reasoning_effort is forced to none with tools
The GPT-6 family rejects function tools combined with reasoning_effort on
/v1/chat/completions:
Function tools with reasoning_effort are not supported for gpt-6-luna in /v1/chat/completions. To use function tools, use /v1/responses or set reasoning_effort to 'none'.
The field must be present and set to "none" โ omitting it is also
rejected. Since tool calling is the entire point of this package, the provider
adapter sends "none" whenever tools are present, and forwards your configured
effort unchanged when they are not.
โ๏ธ Configuration
All configuration is environment-driven. See .env.example for
the annotated list.
Variable | Default | Description |
| (empty) | Required. Provider API key. |
|
| Model id or alias. |
|
| OpenAI-compatible base URL. |
| (empty) |
|
| (empty) | Command (stdio) or URL (http/sse). |
|
|
|
|
| Require approval for risky tools. |
| (empty) | Comma-separated allowlist; empty = read-only defaults. |
|
| Cap on model โ tool โ model rounds. |
| (empty) | When set, |
|
| Bind port. |
Supported models
Model | Tier | Context | Max output | Input / Output per Mtok |
| flagship | 1.05M | 128K | $10 / $50 |
| balanced | 1.05M | 128K | $2 / $10 |
| efficient | 1.05M | 128K | $0.10 / $0.50 |
| flagship | 1.05M | 128K | $4 / $20 |
| efficient | 1.05M | 128K | $0.20 / $1.20 |
Aliases: gpt-6, gpt6, sol โ gpt-6-sol ยท luna โ gpt-6-luna ยท
astra โ gpt-6-astra ยท gpt-5.6 โ gpt-5.6-sol
๐ณ Docker
# Gateway mode (default)
docker compose up gateway
# stdio MCP server mode
docker compose up mcp
# Both
docker compose upThe image is multi-stage: dependencies are built in a builder stage, and the
runtime stage runs as a non-root user with a HEALTHCHECK on /health.
๐งช Testing
make test # pytest with coverage
make lint # ruff check + format check
make typecheck # mypy --strict
make check # all of the aboveTests are split into three layers:
Layer | Path | What it covers |
Unit |
|
|
Integration |
|
|
End-to-end |
| Full model โ tool โ model loop with a fake MCP server |
No test touches the network: httpx transports and the MCP client are injected.
๐ Documentation
Full documentation lives at rwamyth-blip.github.io/mcp-for-copilot.
๐ค Contributing
Contributions are welcome. Please read CONTRIBUTING.md and CODE_OF_CONDUCT.md first.
git clone https://github.com/rwamyth-blip/mcp-for-copilot.git
cd mcp-for-copilot
pip install -e ".[all,dev]"
pre-commit install
make checkGood first issues are labelled
good first issue.
๐ Security
Please do not open a public issue for a vulnerability. See SECURITY.md for the private disclosure process.
This package never logs a credential: every log line and error message passes
through mcp_for_copilot.logging_utils.redact().
๐ License
MIT ยฉ VihokAI
โญ Star History
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-setup MCP gateway securely connecting AI to your tools with authentication and workflows
Find, vet, and run MCP tools through a secure audited gateway with prompt-injection risk scoring
The OpenRouter for tools. One MCP connection gives any AI agent 254 hosted tools, pay per call.
Connect any AI agent to 1,000+ apps and 27,000+ actions through one remote MCP server (OAuth).
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to discover and execute tools via a secure MCP server with JWT authentication, RBAC, rate limiting, and audit logging.1MIT
- FlicenseNot gradedqualityDmaintenanceEnables LLM-powered agents to securely communicate with and orchestrate downstream microservices via FastAPI endpoints exposed as MCP tools.-
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to access a unified catalog of tools from various APIs (OpenAPI, GraphQL, MCP, Google Discovery) through the MCP protocol.173 npmMIT
- FlicenseNot gradedqualityCmaintenanceEnables an LLM to dynamically discover and call tools across multiple MCP servers (file, GitHub, SQL, Python execution) with authentication, rate limiting, and observability, supporting parallel execution and secure deployment.-