Summary
On macOS 26, every process launched by GitHub Copilot.app (Copilot CLI, stdio MCP servers, agent shell commands) is silently denied access to hosts on the local subnet. Connections fail immediately with no route to host / Couldn't connect to server.
The app does not declare NSLocalNetworkUsageDescription in its Info.plist. As a result, macOS never shows the Local Network permission prompt, and the app never appears under System Settings → Privacy & Security → Local Network, so the user has no way to grant access.
Environment
- GitHub Copilot.app 1.1.27 (
com.github.githubapp)
- Copilot CLI 1.0.93-1 (
~/Library/Caches/github-copilot-sdk/cli/1.0.93-1/copilot --server --stdio)
- macOS 26.5.2
- Machine on a corporate LAN (192.168.80.0/20); target host on the same subnet (192.168.90.13)
Steps to reproduce
- Connect the Mac to a LAN that contains an internal HTTPS server on the same subnet.
- Configure a stdio MCP server (or simply use the agent's shell tool) that requests that server.
- Make the request from a Copilot session in the app.
Expected
macOS prompts once for Local Network access, or the app shows up in the Local Network settings list so access can be granted, and the request succeeds.
Actual
- MCP server request:
dial tcp 192.168.90.13:443: connect: no route to host
- Agent shell:
curl: (7) Failed to connect to live.topix.de port 443 after 2 ms: Couldn't connect to server
- The host is up:
arp -n 192.168.90.13 resolves its MAC address.
- The same request works from Terminal.app, and works from the Copilot app when the connection goes through a VPN tunnel (non-local route).
- Restarting the app and rebooting the Mac do not help.
plutil -p "/Applications/GitHub Copilot.app/Contents/Info.plist" shows no NSLocalNetworkUsageDescription key.
- The unified log shows
LocalNetwork: found bundle id com.github.githubapp by PID for each attempt, and no prompt is ever shown.
Suggested fix
Add NSLocalNetworkUsageDescription (and NSBonjourServices if needed) to the app's Info.plist, so that macOS can ask for, and remember, Local Network access for the app and the processes it launches.
Workaround
Run the Copilot CLI from Terminal.app instead of the desktop app while on the local network.
Summary
On macOS 26, every process launched by GitHub Copilot.app (Copilot CLI, stdio MCP servers, agent shell commands) is silently denied access to hosts on the local subnet. Connections fail immediately with
no route to host/Couldn't connect to server.The app does not declare
NSLocalNetworkUsageDescriptionin itsInfo.plist. As a result, macOS never shows the Local Network permission prompt, and the app never appears under System Settings → Privacy & Security → Local Network, so the user has no way to grant access.Environment
com.github.githubapp)~/Library/Caches/github-copilot-sdk/cli/1.0.93-1/copilot --server --stdio)Steps to reproduce
Expected
macOS prompts once for Local Network access, or the app shows up in the Local Network settings list so access can be granted, and the request succeeds.
Actual
dial tcp 192.168.90.13:443: connect: no route to hostcurl: (7) Failed to connect to live.topix.de port 443 after 2 ms: Couldn't connect to serverarp -n 192.168.90.13resolves its MAC address.plutil -p "/Applications/GitHub Copilot.app/Contents/Info.plist"shows noNSLocalNetworkUsageDescriptionkey.LocalNetwork: found bundle id com.github.githubapp by PIDfor each attempt, and no prompt is ever shown.Suggested fix
Add
NSLocalNetworkUsageDescription(andNSBonjourServicesif needed) to the app'sInfo.plist, so that macOS can ask for, and remember, Local Network access for the app and the processes it launches.Workaround
Run the Copilot CLI from Terminal.app instead of the desktop app while on the local network.