Visual Studio Code ↗︎ supports custom endpoint models for chat. Point a custom endpoint at an AI Gateway custom domain protected by Cloudflare Access. Visual Studio Code authenticates with an Access service token stored in its secret storage.
This integration uses static credentials. Visual Studio Code cannot use cloudflared to generate short-lived Access tokens.
Before you start, you need:
- An AI Gateway with a custom domain.
- Cloudflare Access enabled on the custom domain.
- An Access service token allowed by a Service Auth policy.
- The Access application configured to authenticate service tokens with the
Authorizationheader. - Unified Billing credits or a stored provider key for each model.
- Visual Studio Code installed and updated to the latest version.
-
In Visual Studio Code, open the Command Palette and run Chat: Manage Language Models.
-
Select Add Models > Custom Endpoint.
-
Enter a group name, such as
AI Gateway. -
Enter a display name and API key. For the API key, use the following single-header service token value. Replace
<CLIENT_ID>and<CLIENT_SECRET>with your Access service token values.{"cf-access-client-id":"<CLIENT_ID>","cf-access-client-secret":"<CLIENT_SECRET>"} -
Select Chat Completions as the API type.
-
In the
chatLanguageModels.jsonfile that opens, configure your models. Replaceai.example.comwith your AI Gateway custom domain. Replace the model IDs and token limits with values supported by your models.chatLanguageModels.jsonjson [ { "name": "AI Gateway", "vendor": "customendpoint", "apiKey": "${input:cloudflareAccessServiceToken}", "apiType": "chat-completions", "models": [ { "id": "openai/gpt-4.1-mini", "name": "GPT-4.1 mini", "url": "https://ai.example.com/compat/chat/completions", "toolCalling": true, "vision": true, "maxInputTokens": 1000000, "maxOutputTokens": 32768, "requestHeaders": { "Authorization": "${apiKey}" } } ] } ]Visual Studio Code replaces
${apiKey}with the service token value stored in secret storage. TheAuthorizationoverride prevents Visual Studio Code's default authentication behavior from adding aBearerprefix. -
Save the file, then select the model from the chat model picker.
-
Send a prompt. Requests now route through AI Gateway.
For more information about custom endpoint settings, refer to AI language models in Visual Studio Code ↗︎.
When you use an AI Gateway custom domain, WAF rule (Command Injection - Common Attack Commands) can block prompts that contain shell commands.
If the rule blocks Visual Studio Code requests, create a WAF exception that skips only this rule for your AI Gateway custom domain. Scope the exception as narrowly as possible.
To confirm traffic reaches AI Gateway, refer to Verify it works.