Problem
Copilot Chat BYOK execution in code-server can remain coupled to the browser/renderer lifecycle even when the conversation UI is backed by the server-side Agent Host. In practice, an active BYOK turn may stop when the tab becomes inactive, is hard-reloaded, or the browser is closed, and the user must send another message to resume work.
This is particularly surprising for remote code-server usage: the server is still alive, the Agent Host is still available, and long-running agent work is expected to continue independently of whether a browser happens to be attached.
Why this matters
Remote development sessions routinely outlive individual browser tabs. Users switch devices, lose mobile/network connectivity, reload the workbench, suspend a laptop, or intentionally close the browser while a long-running agent task is in progress. Tying BYOK model execution to the renderer means those otherwise normal client lifecycle events can terminate useful server-side work.
The goal is not to keep a browser renderer artificially alive. The goal is to move the ownership boundary to the component that already has the correct lifecycle for background work: the remote/server Agent Host.
Desired behavior
For BYOK providers whose semantics can be represented safely by the Copilot SDK/server Agent Host:
- an active turn continues while the tab is inactive;
- an active turn survives hard reload/reconnect;
- an active turn survives full browser/tab detach and can be observed after reconnect;
- no replacement user message is required merely to keep the existing turn alive.
Compatibility requirements
The server-side path must preserve provider semantics rather than force every BYOK configuration through a lossy abstraction.
The direct Agent Host path should therefore be used only when the configuration can be represented faithfully. Configurations that need renderer-only semantics should continue to use the existing renderer bridge, including cases such as:
- OpenAI ZDR-specific behavior;
- OpenRouter Anthropic Messages behavior;
- custom request headers;
- query-bearing/custom endpoints whose exact wire semantics matter;
- thinking/edit-tool or other advanced custom-endpoint overrides not representable safely by the server SDK surface.
Unsupported semantics should fall back to renderer ownership instead of being guessed or silently altered.
Security requirements
BYOK credential material must remain ephemeral:
- credentials must not be persisted into Agent Host state, replay/history, telemetry, or AHP JSONL logs;
- the renderer-to-Agent-Host credential-bearing DTO must be strictly validated and bounded;
- provider identities must not allow credentials/endpoints to cross provider groups;
- no user BYOK model/provider or credential material should be hard-coded.
Related Agent Host UI correctness
While validating browser-detached Agent Host sessions, folder-isolated sessions also exposed an adjacent scoping bug: the Changes pill could subscribe to branch-wide changes and report unrelated repository changes. Folder isolation should default to Session Changes; worktree isolation should retain Branch Changes.
Validation target
The proposed implementation has been exercised on code-server 4.140.0 / VS Code 1.140 with targeted Agent Host/BYOK tests, browser tests, full build/release verification, repository CI, and live browser-detach acceptance.
Problem
Copilot Chat BYOK execution in code-server can remain coupled to the browser/renderer lifecycle even when the conversation UI is backed by the server-side Agent Host. In practice, an active BYOK turn may stop when the tab becomes inactive, is hard-reloaded, or the browser is closed, and the user must send another message to resume work.
This is particularly surprising for remote code-server usage: the server is still alive, the Agent Host is still available, and long-running agent work is expected to continue independently of whether a browser happens to be attached.
Why this matters
Remote development sessions routinely outlive individual browser tabs. Users switch devices, lose mobile/network connectivity, reload the workbench, suspend a laptop, or intentionally close the browser while a long-running agent task is in progress. Tying BYOK model execution to the renderer means those otherwise normal client lifecycle events can terminate useful server-side work.
The goal is not to keep a browser renderer artificially alive. The goal is to move the ownership boundary to the component that already has the correct lifecycle for background work: the remote/server Agent Host.
Desired behavior
For BYOK providers whose semantics can be represented safely by the Copilot SDK/server Agent Host:
Compatibility requirements
The server-side path must preserve provider semantics rather than force every BYOK configuration through a lossy abstraction.
The direct Agent Host path should therefore be used only when the configuration can be represented faithfully. Configurations that need renderer-only semantics should continue to use the existing renderer bridge, including cases such as:
Unsupported semantics should fall back to renderer ownership instead of being guessed or silently altered.
Security requirements
BYOK credential material must remain ephemeral:
Related Agent Host UI correctness
While validating browser-detached Agent Host sessions, folder-isolated sessions also exposed an adjacent scoping bug: the Changes pill could subscribe to branch-wide changes and report unrelated repository changes. Folder isolation should default to Session Changes; worktree isolation should retain Branch Changes.
Validation target
The proposed implementation has been exercised on code-server 4.140.0 / VS Code 1.140 with targeted Agent Host/BYOK tests, browser tests, full build/release verification, repository CI, and live browser-detach acceptance.